Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

HP 2650 VLAN configuration

Status
Not open for further replies.

wontwork

Technical User
Mar 15, 2004
181
GB
Hi All,

Wondering if someone can help me at all.

We have a HP 2650 in house and we currently have 3 VLANs setup.

VLAN 1 - 10.0.0.0
VLAN 2 - 10.0.1.0
VLAN 3 - 192.168.143.0

We require VLAN 1 to be able to talk to both VLAN 2 and 3 but we do not want VLAN 2 and 3 to be able to talk to each other.

I thought that this was just a case of 'tagging' all ports in VLAN 1 and then 'untagging' the specific port depending on what VLAN it needs to be in and then setting the other VLAN to 'no'.

We have tried this but we are still able to send traffic across all three VLANs!!

IP Routing is enabled on this switch and it is the default gateway for all devices depending on what VLAN they are in.

There is also a 'forbid' option within the VLAN configuration, would i need to use this at all??

Any help would be appriciated.

Thanks in advance

 
No. Mucking around with the VLAN configuration options only helps get Layer-2 connectivity between devices on the same subnet.

The thing you are missing is that the switch is routing packets between hosts on different VLANs.
To prevent any communication with VLAN 2 (for example), you would remove the 10.0.1.n IP address fropm the VLAN 2 interface on the switch.
However, you require routing between VLANs 1 & 2, therefore you will need that IP address on that interface. What you need is to create a relevant access list and apply it to the relevant VLAN interfaces.

I can't remember the 2650 very well, I didn't think it even did IP routing, but if it does that, then hopefully it supports basic filtering with access lists as well.
 
Thanks for the response.

I did not think that the HP switches did access lists?!?

Would you be able to provide me some examples or even point me to a decent document to download as i have gone to the HP support website but cannot seem to find anything relevant and a good old Google search came back with nothing.

Thank you
 
I had a look, and it looks like although the 2650 supports IP routing, it doesn't do access lists.

Maybe you can filter on your internet router instead?
 
I am going to check our Internet router today, thanks for your assistance.

I will post back with my findings.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top