VLAN trunking на Cisco ASA

* VLAN Trunking (ASA 5510, ASAOS 7.2.1)

Hey! If you are trying to trunk VLAN 1, you are going to run into trouble (using the below config, I think you may have to configure Ethernet0/3 (NOT a sub-interface) to have an ip address. You will not be able to type in ‘vlan 1’, as it is assumed). You have been warned.

same-security-traffic permit inter-interface
same-security-traffic permit intra-interface

interface Ethernet0/3
no nameif
no security-level
no ip address
!
interface Ethernet0/3.1
description Development Network
vlan 50
nameif dev
security-level 40
ip address 192.168.50.1 255.255.255.0 standby 192.168.50.2
!
interface Ethernet0/3.2
description Test Network
vlan 88
nameif test
security-level 60
ip address 192.168.88.1 255.255.255.0 standby 192.168.88.2

QTECH QSW2900

Аналогичный коммутатору Zyxel ES2024 конфигурационный файл для QTECH QSW2900 (все данные, идентифицирующие нашу сеть были удалены):

QTECH-QSW2900#sh run
!LanSwitch BuildRun(QTECH Platform)
enable
configure terminal
![VLAN]
interface range ethernet 1/1 to ethernet 2/1
switchport mode trunk
exit
vlan 1
description VLAN1
interface ip 10.2.6.253 255.255.255.0 10.2.6.1
exit
vlan 2
description MULTICAST
switchport ethernet 1/1 to ethernet 2/1
exit
vlan 10
description MANAGED_VLAN10
switchport ethernet 1/1 to ethernet 2/1
interface ip 192.168.3.181 255.255.252.0 192.168.2.1
exit
![DEVICE]
interface ethernet 0/1
exit
interface ethernet 0/2
exit
interface ethernet 0/3
exit
interface ethernet 0/4
exit
interface ethernet 0/5
exit
interface ethernet 0/6
exit
interface ethernet 0/7
exit
interface ethernet 0/8
exit
interface ethernet 0/9
exit
interface ethernet 0/10
exit
interface ethernet 0/11
exit
interface ethernet 0/12
exit
interface ethernet 0/13
exit
interface ethernet 0/14
exit
interface ethernet 0/15
exit
interface ethernet 0/16
exit
interface ethernet 0/17
exit
interface ethernet 0/18
exit
interface ethernet 0/19
exit
interface ethernet 0/20
exit
interface ethernet 0/21
exit
interface ethernet 0/22
exit
interface ethernet 0/23
exit
interface ethernet 0/24
exit
interface ethernet 1/1
exit
interface ethernet 2/1
exit
![OAM]
ipaddress 10.2.6.253 255.255.255.0 10.2.6.1
hostname QTECH-QSW2900
![IGMP_SNOOPING]
igmp-snooping
![SNMP]
snmp-server contact noc@provider
snmp-server location Koe-gde-2
QTECH-QSW2900#

Информация о VLAN’ах:

QTECH-QSW2900#sh vlan
show VLAN information
VLAN name              : VLAN1
VLAN ID                : 1
VLAN status            : static
VLAN member            : e0/1-e2/1.
Static tagged ports    : e1/1-e2/1.
Static untagged Ports  : e0/1-e0/24.
Dynamic tagged ports   : 

show VLAN information
VLAN name              : MULTICAST
VLAN ID                : 2
VLAN status            : static
VLAN member            : e1/1-e2/1.
Static tagged ports    : e1/1-e2/1.
Static untagged Ports  :
Dynamic tagged ports   : 

show VLAN information
VLAN name              : MANAGED_VLAN10
VLAN ID                : 10
VLAN status            : static
VLAN member            : e1/1-e2/1.
Static tagged ports    : e1/1-e2/1.
Static untagged Ports  :

Конфигурация должна работать, если по аплинку приходит транк (а в нашем случае он не приходит, это жаль) )) Из-за этого Инет у людей работал на портах 1-24,  при этом он проходил по native VLAN 1, а вот 25-26 порты, которые в транке, не пинговались извне. До конца еще не разобрался — то ли надо просто отключить trunk, то ли руками прописать default native VLAN 1.

Вот аналогичный конфиг который отлично работает на другом доме:

QTECH#sh run
!LanSwitch BuildRun(QTECH Platform)
enable
configure terminal
![DEVICE]
interface ethernet 0/1
exit
interface ethernet 0/2
exit
interface ethernet 0/3
exit
interface ethernet 0/4
exit
interface ethernet 0/5
exit
interface ethernet 0/6
exit
interface ethernet 0/7
exit
interface ethernet 0/8
exit
interface ethernet 0/9
exit
interface ethernet 0/10
exit
interface ethernet 0/11
exit
interface ethernet 0/12
exit
interface ethernet 0/13
exit
interface ethernet 0/14
exit
interface ethernet 0/15
exit
interface ethernet 0/16
exit
interface ethernet 0/17
exit
interface ethernet 0/18
exit
interface ethernet 0/19
exit
interface ethernet 0/20
exit
interface ethernet 0/21
exit
interface ethernet 0/22
exit
interface ethernet 0/23
exit
interface ethernet 0/24
exit
interface ethernet 1/1
description UPLINK
exit
interface ethernet 2/1
exit
![OAM]
ipaddress 10.2.5.252 255.255.255.0 10.2.5.1
hostname Koe-gde-3
QTECH#sh vlan
show VLAN information
VLAN ID                : 1
VLAN status            : static
VLAN member            : e0/1-e2/1.
Static tagged ports    :
Static untagged Ports  : e0/1-e2/1.
Dynamic tagged ports   :

Total entries: 1 vlan.

Т.е. не настроено НИЧЕГО!

Алгоритм быстрой настройки свитча:

1. Подключаемся по COM-порту и вводим логин/пароль.
2. enable
3. clear startup-config
4. reboot
5. Вводим default логин/пароль: admin/123456
6. enable
7. conf t
8. username admin privilege 15 password 7 P@$$W0RD
9. hostname KOE-GDE
10. ipaddress 10.2.6.253
11. exit
12. reboot

Вот и всё. Быстрая настройка коммутатора по вышеописанному конфигу готова.

Zyxel ES2024

Типичный конфигурационный файл коммутатора, установленного на одном из узлов нашей сети (все данные, идентифицирующие нашу сеть были удалены ))):

ES-2024A# show running-config
  Building configuration...

  Current configuration:

vlan 1
  name 1
  normal ""
  fixed 1-26
  forbidden ""
  untagged 1-26
  ip address default-management 10.1.1.253 255.255.255.0
  ip address default-gateway 10.1.1.1
exit
vlan 10
  name managed
  normal ""
  fixed 25-26
  forbidden 1-24
  untagged 1-24
  ip address 192.168.4.60 255.255.252.0
  ip address default-gateway 192.168.2.1
exit
igmp-snooping
igmp-snooping unknown-multicast-frame drop
ip name-server 10.2.0.1
snmp-server contact noc@provider location Koe-gde
remote-management 2
remote-management 3
remote-management 1 start-addr 10.2.2.0 end-addr 10.2.2.254 service telnet ftp http icmp snmp ssh https
remote-management 2 start-addr 10.2.0.0 end-addr 10.2.0.254 service telnet ftp http icmp snmp ssh https
remote-management 3 start-addr 192.168.2.1 end-addr 192.168.4.255 service telnet ftp http icmp snmp ssh https
mvr 2
  source-port 25
  receiver-port 1-24,26
  name IPTV
  tagged 25-26
  group DEF_GROUP start-address 224.0.0.1 end-address 224.0.0.254
  group IPTV_ALT start-address 224.0.42.1 end-address 224.0.42.254
  group IPTV_NEW start-address 234.5.2.1 end-address 234.5.2.254
  group SAP_GROUP start-address 239.255.255.250 end-address 239.255.255.250
exit

VLAN 1 политически используется на всех портах ))

VLAN 10 — управляющий VLAN, только для админов.

VLAN 2 — мультикаст и IPTV.