Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations TouchToneTommy on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Configuration issues Cisco UC560 Connected to 3com 4500 switch and Sonicwall Firewall

Status
Not open for further replies.

Rickimaru

Technical User
Sep 10, 2010
9
US
I wanted to get input on this if this is configured right. One company says the other one is problem so on so forth when you talk to tech support. I am not at all familiar with the 3COM switch and this maybe where my problem lies in getting all three of these devices working properly with each other. The end result is to get the UC560 to talk thru a VPN tunnel (already established) from our two offices for our VOIP solution. Site 1 (HQ) houses the UC560, a 3com switch for phones and hopefully data. Also the SonicWall Firewall that serves as the WAN access. Site 2 houses Sonicwall Firewall and 3com Switch. The Cisco UC560 has a static address of 192.168.0.13/255.255.255.0 while the configuration for phones ip's are a stock config which is a 10.1.10.0/255.255.255.252 (which is vlan90) and 10.1.1.0/255.255.255.0 (which is vlan100) Here is the current configuration for the 3COM switch at HQ: #
sysname AE-Tech
#
password-control login-attempt 3 exceed lock-time 120
#
super password level 3 simple
#
local-server nas-ip 127.0.0.1 key 3com
#
lldp enable
lldp compliance cdp
#
udp-helper enable
#
radius scheme system
#
domain system
#
local-user
service-type telnet terminal
level 3
local-user
service-type lan-access
service-type telnet
level 3
local-user
service-type lan-access
service-type telnet
level 3
#
vlan 1
#
vlan 90
description Cisco-Voice2
#
vlan 100
description Cisco-Voice
#
interface Vlan-interface1
ip address 192.168.0.12 255.255.255.0
#
interface Vlan-interface90
ip address dhcp-alloc
#
interface Vlan-interface100
ip address dhcp-alloc
#
interface Aux1/0/0
#
interface Ethernet1/0/1
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 90 tagged
port hybrid vlan 1 untagged
broadcast-suppression pps 3000
undo jumboframe enable
voice vlan enable
#
interface Ethernet1/0/2
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 90 tagged
port hybrid vlan 1 untagged
broadcast-suppression pps 3000
undo jumboframe enable
voice vlan enable
#
interface Ethernet1/0/3
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 90 tagged
port hybrid vlan 1 untagged
broadcast-suppression pps 3000
undo jumboframe enable
voice vlan enable
#
interface Ethernet1/0/4
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 90 tagged
port hybrid vlan 1 untagged
broadcast-suppression pps 3000
undo jumboframe enable
voice vlan enable
#
interface Ethernet1/0/5
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 90 tagged
port hybrid vlan 1 untagged
broadcast-suppression pps 3000
undo jumboframe enable
voice vlan enable
#
interface Ethernet1/0/6
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 90 tagged
port hybrid vlan 1 untagged
broadcast-suppression pps 3000
undo jumboframe enable
voice vlan enable
#
interface Ethernet1/0/7
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 90 tagged
port hybrid vlan 1 untagged
broadcast-suppression pps 3000
undo jumboframe enable
voice vlan enable
#
interface Ethernet1/0/8
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 90 tagged
port hybrid vlan 1 untagged
broadcast-suppression pps 3000
undo jumboframe enable
voice vlan enable
#
interface Ethernet1/0/9
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 90 tagged
port hybrid vlan 1 untagged
broadcast-suppression pps 3000
undo jumboframe enable
voice vlan enable
#
interface Ethernet1/0/10
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 90 tagged
port hybrid vlan 1 untagged
broadcast-suppression pps 3000
undo jumboframe enable
voice vlan enable
#
interface Ethernet1/0/11
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/12
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/13
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/14
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/15
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/16
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/17
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/18
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/19
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/20
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/21
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/22
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/23
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/24
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/25
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/26
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/27
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/28
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/29
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/30
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/31
poe enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
#
interface Ethernet1/0/32
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/33
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/34
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/35
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/36
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/37
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/38
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/39
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/40
poe enable
stp edged-port enable
lldp compliance admin-status cdp txrx
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/41
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/42
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/43
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/44
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/45
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/46
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/47
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface Ethernet1/0/48
poe enable
stp edged-port enable
port link-type hybrid
port hybrid vlan 1 90 untagged
port hybrid pvid vlan 90
broadcast-suppression pps 3000
undo jumboframe enable
#
interface GigabitEthernet1/0/49
stp edged-port enable
port link-type trunk
port trunk permit vlan 1 90 100
broadcast-suppression pps 3000
undo jumboframe enable
#
interface GigabitEthernet1/0/50
stp edged-port enable
port link-type trunk
port trunk permit vlan 1
broadcast-suppression pps 3000
undo jumboframe enable
#
interface GigabitEthernet1/0/51
stp edged-port enable
port link-type trunk
port trunk permit vlan 1 90 100
broadcast-suppression pps 3000
shutdown
undo jumboframe enable
#
interface GigabitEthernet1/0/52
stp edged-port enable
port link-type trunk
port trunk permit vlan 1
broadcast-suppression pps 3000
shutdown
undo jumboframe enable
#
undo xrn-fabric authentication-mode
#
interface NULL0
#
undo voice vlan security enable
voice vlan 100 enable
#
ip route-static 0.0.0.0 0.0.0.0 192.168.0.1 preference 60
#
snmp-agent
snmp-agent local-engineid 8000002B20FDF16040806877
snmp-agent sys-info location AE-NORFOLK-SW1
snmp-agent sys-info version v3
snmp-agent group v3 admin read-view admin write-view admin
snmp-agent mib-view included admin iso
snmp-agent usm-user v3 admin admin
#
undo cluster enable
#
user-interface aux 0
authentication-mode scheme
user-interface aux 1 7
user-interface vty 0 4
authentication-mode scheme
#
return

This is what Cisco support said to do which caused my phones to drop calls, phone resets and what seemed to be voice packet loss. So I set back to what I originally had it configured to with no problems with VOIP.
Recommend the following Network configuration changes based on the information Given:

1. disconnect the Wan port from the sonic wall firewall
2. Change the WAN interface to dhcp for ip address.
3. Change VLAN 1 on the UC to have IP address 192.168.0.13
4. Connect one of the Expansion ports of the UC560 to the sonic wall
5. For the 3com switch connected to the UC560 set all ports the phones are
connected to for VLAN 100. Set the phones to DHCP vs. Static. They should then draw an IP
from the UC560 in the 10.1.1.x/24 network. On the 3com set its uplink port for trunking Vlan 1,90, 100.

6. On the sonic wall create a static route for 10.1.10.0/255.255.255.252 and
10.1.1.0/255.255.255.0 networks to use gateway 192.168.0.13 (VLAN 1 interface of the UC560).

7. This puts your configuration in line with best practices for a voip solution.

8. On the remote site you will need to be able to route across the VPN tunnel to
the 10.1.1.0 and 10.1.10.0 networks. You will need to set the tftp server option 150 on the
remote dhcp server to 10.1.1.1 or static the alternate tftp server selection on the phones for 10.1.1.1.

So the above static routes are placed in my Sonicwall on HQ side. Is there anyone out there that can help me with this? Thanks for the help in advance. Hopefully I have given enough information.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top