Networking-Blog

My WordPress Blog

4G -> 887 working around L2 Interfaces (vlan connectivity)

For context:

887 router is connected to a 4G modem through a L2 physical interface (switchport access vlan 3) – It has 4 L2 ports only.

Vlan 3 SVI ip address = 10.212.6.239/24

4G public IP has been used to create a tunnel directly to one of our corporate sites, configuration for the VPN has been done on both sides, this includes matching crypto keys (isakmp), ospf networking statements and source/destination IPs. Our source, on the 4G side, for the tunnel is 10.212.6.239 (int vlan 3) which is within the same subnet as the 4G box interface – VLAN 3 is an SVI created to provide L3 connectivity to clients, as L2 interfaces cannot be assigned IP addresses

TRAFFIC FLOW

DHCP has been configured on the 887 to hand out ip addresses in the 172.16.152.0/24 network. with a default-router statment for 172.16.152.254 which is the IP address for int VLAN 1.

So clients connected to the 887 are within the 172.16.152.0/24 subnet. What I failed to understand is, is how we get clients in 172.16.152.0/24 OUT of vlan 1 and into vlan 3 to then be routed to the corporate network over the tunnel.

I think this confusion was because the ports are L2 so I was thinking more in sense of L2 switching, where you cannot hop vlans – as that requires routing (L3). But in this case we are using an 887 which is fully capable of ROUTING and is able to route vlans between eachother.

So traffic comes in on vlan 1 destined for the corporate network over the tunnel (say 172.31.0.0/16), it hits its default gateway (VLAN 1 SVI). 887 looks in its routing table looking for entries for 172.31.0.0/16.

The route above was advertised via OSPF over the tunnel. Its next hop is 10.230.152.1 (the tunnel interface). Traffic then gets sent out that tunnel interface and hits the other end (10.230.152.2). Then the corporate firewall on the other end routes traffic to its destination through its own routing table.

Bare in mind – Config has to be done on both sides particularly with the VPN configuration and access control – the firewall natively blocks traffic, so it requires permit statements for both the tunnel and the 172.16.152.0/24 network.

Access control on the 4G side (887 config):

Show ip route:

Cisco: VLAN’s

What Is a VLAN?

A virtual LAN (VLAN) is a logical LAN, or a logical subnet. It defines
a broadcast domain. A physical subnet is a group of devices that shares
the same physical wire. A logical subnet is a group of switch ports
assigned to the same VLAN, regardless of their physical location in a
switched network.

Two types of VLANs are:

End-to-end VLAN—VLAN members are assigned by function
and can reside on different switches. They are used when hosts are
assigned to VLANs based on functions or workgroups, rather than
physical location. VLANs should not extend past the Building
Distribution submodule. Figure 2-1 shows end-to-end VLANs.

Local VLAN—Hosts are assigned to VLANs based on their location,
such as a floor in a building. A router accomplishes sharing
of resources between VLANs. This type is typically found in the
Building Access submodule. Figure 2-2 shows an example of local
VLANs.

Best Practices

VLAN networks need many of the same considerations that normal
Ethernet lines demand. For instance, VLANs should have one IP subnet.
By supplying consecutive subnets to VLANs, the routing advertisements
can be summarized (which has many benefits to convergence).
A stereotypical description of capacity requirements is possible. Access
ports are assigned to a single VLAN and should be Fast Ethernet or
faster. Ports to the distribution layer should be Gigabit Ethernet or
better. Core ports are Gigabit Etherchannel or 10-Gig Ethernet.
Remember that uplink ports need to be able to handle all hosts communicating
concurrently, and remember that although VLANs logically
separate traffic, traffic in different VLANs can still experience
contention with other VLANs when both VLANs travel over the same
trunk line.
Take into account the entire traffic pattern of applications found in your
network. For instance, Voice VLANs pass traffic to a remote Call
Manager. Multicast traffic has to communicate back to the routing
process and possibly call upon a Rendezvous Point.

Creating a VLAN in Global

Config Mode
VLANs must be created before they may be used. VLANs may be
created in global configuration mode or in VLAN database mode.
Creating VLANs in global configuration is easy—just identify the
VLAN number and name it!

(config)#vlan 12
(config-vlan)#name MYVLAN

Assigning Ports to VLANs

When statically assigning ports to VLANs, first make it an access port,
and then assign the port to a VLAN. At the interface configuration prompt:

(config-if)#switchport mode access
(config-if)#switchport access vlan 12

The commands are similar when using dynamic VLAN assignment. At
interface configuration mode:

(config-if)#switchport mode access
(config-if)#switchport access vlan dynamic

If you use dynamic, you must also enter the IP address of the VMPS
server at global configuration mode:

(config-if)#vmps server ip address

Verifying VLAN Configuration

To see a list of all the VLANs and the ports assigned to them, use the
command show vlan. To narrow down the information displayed, you
can use these keywords after the command: brief, id, vlan-number, or
name vlan-name:

ASW# show vlan brief
VLAN Name Status Ports
—— ———————————————— ————- ———————
————————
1 default active Fa0/1, Fa0/2, Fa0/3,
Fa0/10,Fa0/11,Fa0/12
20 VLAN0020 active Fa0/5,Fa0/6,Fa0/7
21 VLAN0021 active Fa0/8,Fa0/9
1002 fddi-default active
1003 trcrf-default active
1004 fddinet-default active
1005 trbrf-default active