Answer the question
In order to leave comments, you need to log in
Aruba 2930f how to properly configure VLAN&Routing and Internet through firewall DFL-860e and Proxy Traff Inspector?
The scheme is not complete, in fact, HP 1920 switches 9pcs and VLANs are planned (now everything is in the broadcast domain), somewhere VLAN 10,20,30 -110 (about 250 computers, the rest of the network equipment is still about 120pcs)
1- On D-Link (192.168.2.2) and PROXY (192.168.2.10) I did not indicate either VLANs or trunks, because for me it is not yet clear how best to do it so that, for example, users from VLAN 70, 5PCs go for the Internet via d-link, and other 25 PCs went through proxy??? It should be the same from other Vlans.
2- How to deal with printers, wi-fi access points, barcode scanners, etc (they are assigned static IP-192.168.1.* , 192.168.2.* )?? and they are connected to HP 1920 L2 switches.
It may not be difficult for the pros, but for me it turned out to be a non-trivial task to drive this zoo into VLANs, please help !!!
Answer the question
In order to leave comments, you need to log in
All the pieces of iron are in the lab, except for the long link and the proxy (in production, I can’t touch it)
As I think, as the default gateway, specify the IP address of the L3 interface of the switch for the corresponding VLAN. On the L3 switch itself, then specify as the destination for the default route (0.0.0.0/0) the address of the internal interface of Dlink or Proxy ?.
Can Dlink and Proxy internal interfaces be taken out into separate VLANs?
I'm not very familiar with routing, so I need help.
On the example of this switch, I can’t tell, but I would do this:
1. On l3 switches, I would raise the necessary vlans with the corresponding l3 interfaces.
2. I would raise the routing between l3 switches and long (your dlink seems to be able to spf) and would give 0.0.0.0/0 from l3 long to switches.
3. If aruba does not know how to spf, then you will have to be content with static routes or look towards RIP, like all pieces of iron have it.
4. If the proxy is not transparent, I would leave everything as it is, who will need to default through the length to go to the Internet, and whoever has the proxy specified will go through it.
5. If the proxy is transparent, then it would connect both of its ports to different vlans (1 internal, the second external).
6. Your length seems to know how to PBR. Through it, I would send traffic to the proxy's internal interface to those devices that need access to the Internet through a proxy.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question