Advertisement

09.04.2008 at 08:53AM PDT, ID: 23703126
[x]
Attachment Details
[x]
The Solution Rating System

With so many solutions, how can you tell which solutions are most likely to help you and which ones are not? To provide you with a tool to use, we rate our solutions based on various elements that most accurately determine if a solution is a quality solution. To explain what factors affect the solution rating, here are the elements we take into consideration when formulating our solution rating.

  • The Grade of the Solution
  • The Zone Rank of the Expert Providing the Solution
  • The Number of Author and Expert Comments
  • The Number of Experts Contributing
  • The Feedback of the Community

Your Input Matters
Because of the way the system is set up, the most important variable in this equation is you. As a member of Experts Exchange, you are able to cast your vote on the quality of the solutions in regard to how complete, accurate, helpful and easy to understand each solution is. When you provide your feedback, each rating is adjusted accordingly. So, if you see a solution that has a poor rating that you think is a good solution, let us know by rating it. As you do, the rating will be adjusted and will become more accurate for other members of our site.

If you have any suggestions that you would like to make for our rating system, please ask a question in the Suggestions Zone of Community Support.

Thank you!

8.4

Starting point for fiber Conversion

Asked by CityofKerrville in Network Routers, Network Switches & Hubs, Network Design & Methodology

Tags: , ,

This is a question regarding the starting point for the following bigger picture

http://www.experts-exchange.com/Hardware/Networking_Hardware/Routers/Q_23688899.html

...where to start.  We are about to begin our migration from a T1 infrastructure to Time Warner's Metro Ethernet. 4 of our 15 sites including our main site are already on the fiber.  I would like to get the core configurations done with these site first before I start moving others.  Being a local government entity, with police and fire and EMS, I am sure you can understand that down time is a major issue.  I have attache a diagram of the initial plan but will lay out a few minor requirements and some of what I have done so far for review and critique.

We will start with 4 Sites

Site A - This is our City Hall where most of our servers are located and where our internet comes in.  We will have a Cisco 2821 Router with 2 - GigabitEthernet, 4 FastEthernet, and 1 DSU.  I and pretty sure I need to configure a trunk port on this router to connect to the Metro-E.  Here a what I have done so far for the configuration of the router.
!
interface FastEthernet0/0                                                                            <--------MGMT on Diagram
 description VLAN10 MGMT-IT
 ip address 192.168.96.1 255.255.255.0
!
interface FastEthernet0/1
 description ASA FIREWALL
 ip address 192.168.110.1 255.255.255.224
!
interface FastEthernet0/2                                                                            <--------SITE A users on Diagram
 description VLAN20 CITYHALL
 ip address 192.168.99.1 255.255.255.252
!
interface FastEthernet0/3                             <--------To existing network where site to be migrate are
 description TEMPORARY LINK TO EXISTING ROUTERS
 ip address 192.168.109.1 255.255.255.252
!
interface GigabitEthernet0/0                                                                        <--------SITE A on Diagram
 description VLAN30 SERVERS
 ip address 192.168.101.1 255.255.255.0
!
interface GigabitEthernet0/1
 description dot1q trunk port to METRO ETHERNET
 no ip address
!
interface GigabitEthernet0/1.1
 description VLAN 10 NATIVE
 encapsulation dot1q 10 native
!
interface GigabitEthernet0/1.2
 description VLAN80 UNUSED
 encapsulation dot1q 80
 ip address 192.168.98.1 255.255.255.254
!
interface GigabitEthernet0/1.3                                                                   <--------SITES B and C on Diagram
 description VLAN COURT, FIREADMIN, LIBARY, KSP, STREETS, GOLF
 encapsulation dot1q 20
 ip address 192.168.100.1 255.255.255.0
!
interface GigabitEthernet0/1.4
 description VLAN40 WATER
 encapsulation dot1q 40
 ip address 192.168.104.1 255.255.255.0
!
interface GigabitEthernet0/1.5
 description VLAN50 WASTERWATER
 encapsulation dot1q 50
 ip address 192.168.105.1 255.255.255.0
!
interface GigabitEthernet0/1.6
 description VLAN90 UNUSED
 encapsulation dot1q 90
 ip address 192.168.107.1 255.255.255.254
!
interface GigabitEthernet0/1.7
 description VLAN100 UNUSED
 encapsulation dot1q 100
 ip address 192.168.109.1 255.255.255.254
!
interface GigabitEthernet0/1.8                                                                         <--------SITE D on Diagram
 description VLAN70 KPD
 encapsulation dot1q 70
 ip address 192.168.109.1 255.255.255.254
!
interface dsu0/1
 description VLAN60 AIRPORT
 ip address 192.168.1.25 255.255.255.248
!

We want to implement VLANS for are site that require extra security (i.e. Waster Plant and Police).  Aside from the site was really want to isolate, most everyone else will be on the same VLAN.

VLAN10 (I think this is the native but not sure about that)
This is our management VLAN  Everything on this VLAN is physically located at SITE A.  out IT staff will be on this VLAN and also our back-end Virtual Server management is here.  Devices on this VLAN should be able to access anything on the entire network.  Devices on the VLAN will have static ip addresses on the 192.168.96.0 network

VLAN20
Is the primary VLAN for most of the city's regular users.  For today's purposes, the users at SITE A, All of SITE B, and all of SITE C will be on this VLAN.  There will be more sites added to this VLAN, but our hope is to have everything ready so we easily transition them over when their time comes.  Devises on the VLAN should pull DHCP from our Domain controllers using the 192.168.100.0/24 address pool.

VLAN30
All of our Servers (Physical Machines and Virtual Front-ends) are on this VLAN.  Servers should be accessible from all devices on the network.  All addresses are static on the 192.168.101.0 network.  Management will be done through the back-end through the management network (VLAN10).

VLAN70
The is our Police Department and SITE D on the diagram.  This site has  Cisco 2811 router.  The reason for the router is Police specific to resources outside our network. Not sure how to configure the access port here.  All users and department specific server are on this VLAN.  Certain users on SITE C will need access to the servers on this VLAN.

The switches at all of the site are Cisco 3560 (port count varies)  Here is a sample config for the access port on each switch.

!
interface FastEthernet0/24
 description VLAN20 traffic from fe0/2 on CHR1
 switchport mode access
 switchport access vlan 20
!
interface VLAN10
 description MGMT ACCESS
 ip address 192.168.96.50 255.255.255.0
!

Obviously the VLAN tags and descriptions will change accordingly.

Like I said before, this a live migration and all the devices on the T1 site still need to be active while the migration is underway.  That being said, I think you have enough information to answer a few starting questions.

1 - What is the Native VLAN?  Is it the VLAN provided by the ISP for the Metro-E?  Should my management Network be on the native?

2 - When we migrate the Servers and put them on their new VLAN, will the devices on the old network not yet migrated to fiber still be able to access them?  Should I move them last?

3 - I know there is 1 access port on the remote switches to connect to the Metro-E.  Do the rest of the ports on these switches need VLAN tags too?

4 - From what you have looked at so far, are we on the right track?  Are we missing something?  Is there a better way?  What are some of the best practices for what we are trying to accomplish?  Please let me know any ideas or concerns you have with my design.Start Free Trial
Attachments:
 
Starting point
Starting point
 
[+][-]09.04.2008 at 02:40PM PDT, ID: 22392999

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]09.05.2008 at 08:30AM PDT, ID: 22400047

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]09.05.2008 at 09:24AM PDT, ID: 22400712

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.05.2008 at 09:43PM PDT, ID: 22406000

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]09.08.2008 at 03:27PM PDT, ID: 22422221

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]09.09.2008 at 06:02AM PDT, ID: 22426926

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.30.2008 at 07:58AM PDT, ID: 22605968

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.30.2008 at 11:43AM PDT, ID: 22608129

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.30.2008 at 12:24PM PDT, ID: 22608548

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.30.2008 at 01:01PM PDT, ID: 22608888

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]09.30.2008 at 10:05PM PDT, ID: 22611730

Experts Exchange has a courteous staff of administrators who help members get the most out of the website by means of administrative comments like this one.

Start your 7-day free trial to view this Administrative Comment or ask the Experts your question.

 
[+][-]10.01.2008 at 02:50PM PDT, ID: 22619467

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.02.2008 at 11:58AM PDT, ID: 22627319

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
[+][-]10.03.2008 at 06:44AM PDT, ID: 22633804

Experts Exchange has a courteous staff of administrators who help members get the most out of the website by means of administrative comments like this one.

Start your 7-day free trial to view this Administrative Comment or ask the Experts your question.

 
[+][-]10.03.2008 at 11:43AM PDT, ID: 22636776

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zones: Network Routers, Network Switches & Hubs, Network Design & Methodology
Tags: Cisco, 2821, 2811, 3560, VLAN Trunking and Metro Ethernet
Sign Up Now!
Solution Provided By: lrmoore
Participating Experts: 4
Solution Grade: A
 
 
 
Loading Advertisement...
20080716-EE-VQP-32 / EE_QW_2_20070628