I will try to give as much detail as I can. We recently had the need to subnet our little network for ADFS and best practices which is great. I basically followed the suggestions here and built mine similar.
Once I had set things up it worked. The 2960 routed the vlan traffic via the Sonicwall but it created an odd problem. Name resolution stopped when clients were connected on the VPN. When I shut down the interface on the 2960 from the Sonicwall the name resolution comes back instantly. Only difference on the procedure I found was that because I am using a 2960 it uses dot1q and so the "switchport trunk encpsulation dot1q" doesn't show as an option. But it looked like it was routing to the VLANs fine when I tested it from an internal test server.
XO; lan 172.20.0.1
X1: WAN Primary ISP
X2: WAN Failover ISP
X3; Accounting 172.24.0.1
X4: Router on a Stick 172.20.40.1 LAN
V41 172.20.41.1 LAN
V42 172.20.42.1 LAN
V43 172.20.43.1 LAN
V44 172.20.44.1 LAN
X5: 172.16.0.1 DMZ
VPN Clients have access to X0, X1 AND X2 ONLY.
Any help I can get would be greatly appreciated. And this is the first real vlan experience I have had outside of a Cisco exam. Not an expert.
Once I had set things up it worked. The 2960 routed the vlan traffic via the Sonicwall but it created an odd problem. Name resolution stopped when clients were connected on the VPN. When I shut down the interface on the 2960 from the Sonicwall the name resolution comes back instantly. Only difference on the procedure I found was that because I am using a 2960 it uses dot1q and so the "switchport trunk encpsulation dot1q" doesn't show as an option. But it looked like it was routing to the VLANs fine when I tested it from an internal test server.
XO; lan 172.20.0.1
X1: WAN Primary ISP
X2: WAN Failover ISP
X3; Accounting 172.24.0.1
X4: Router on a Stick 172.20.40.1 LAN
V41 172.20.41.1 LAN
V42 172.20.42.1 LAN
V43 172.20.43.1 LAN
V44 172.20.44.1 LAN
X5: 172.16.0.1 DMZ
VPN Clients have access to X0, X1 AND X2 ONLY.
Any help I can get would be greatly appreciated. And this is the first real vlan experience I have had outside of a Cisco exam. Not an expert.