Hello!
I am currently building a new virtualization architecture, but I need help for the network configuration.
- Hardware :
- 2x Powerconnect 6248
- 3x PowerEdge R710 with 8x Nics
- 2x PowerEdge R410 (Firewall)
I have 3 VLAN :
- VLAN 2 : DMZ (10.98.X.X) (VM Network)
- VLAN 3 : PUBLIC (10.100.X.X)
- VLAN 4 : ADMIN (10.94.X.X)
- 3 LAGs between my 3 esxs servers for Vm Network (HA, FT...)
I need this configuration for my two switchs, so I think setting up a LAG/Trunk between my two switch. I don't know if I must do one trunk by VLAN or a global trunk where my VLAN can passed.
After that, I must 3 LAG for my 3 ESX server corresponding to my VM Network. 6x Nics per servers.
I have few question :
What type of switch port mode and lag/trunk mode must I use? Access, General, Trunk? I must used tagged packets?
Here, a schema of my architecture :
I have tried to realised a first configuration with only one switch, so I have do that :
But I have an issue, my VMs can communicat with outside, but I can't access them only on the VLAN 2 (DMZ).
LAG between my 3 esxi :
LAG configuration :
VLAN 4 (ADMIN) :
VLAN 2 (DMZ) :
VLAN 3 (PUBLIC) :
VLAN LAG Settings :
My running config :
!Current Configuration:!System Description "PowerConnect 6248, 3.3.1.10, VxWorks 6.5"!System Software Version 3.3.1.10!Cut-through mode is configured as disabled!configurevlan databasevlan 2-5exitsntp unicast client enablesntp server fr.pool.ntp.orgclock timezone 1 minutes 0stackmember 1 2exitip address 10.94.0.1 255.255.0.0ip default-gateway 10.94.0.254ip address vlan 4ip routinginterface vlan 2name "DMZ"
exitinterface vlan 3name "PUBLIC"exitinterface vlan 4name "ADMIN"exitinterface vlan 5name "Heartbeat"exitusername "admin" password 161ebd7d45089b3446ee4e0d86dbcf92 level 15 encrypted!interface ethernet 1/g1switchport mode generalswitchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g2switchport mode general
switchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g3switchport mode generalswitchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g4switchport mode generalswitchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g5switchport mode general
switchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g6switchport mode generalswitchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g7switchport mode generalswitchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g8switchport mode general
switchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g9switchport mode generalswitchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g10switchport mode generalswitchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g11switchport mode general
switchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g12switchport mode generalswitchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g13switchport mode generalswitchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g14switchport mode general
switchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g15switchport mode generalswitchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g16switchport mode generalswitchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g17switchport mode general
switchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g18switchport mode generalswitchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g19switchport mode generalswitchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g20switchport mode general
switchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g21spanning-tree disableswitchport mode generalswitchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!interface ethernet 1/g22spanning-tree disableswitchport mode generalswitchport general pvid 4switchport general allowed vlan add 4switchport general allowed vlan remove 1exit!
interface ethernet 1/g23channel-group 1 mode onspanning-tree mst 0 external-cost 20000switchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!
interface ethernet 1/g24channel-group 1 mode onspanning-tree mst 0 external-cost 20000switchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!interface ethernet 1/g25channel-group 1 mode onswitchport mode general
switchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!interface ethernet 1/g26channel-group 1 mode onswitchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!interface ethernet 1/g27channel-group 1 mode onswitchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!
interface ethernet 1/g28channel-group 1 mode onswitchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!interface ethernet 1/g29channel-group 2 mode onswitchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!interface ethernet 1/g30channel-group 2 mode onswitchport mode generalswitchport general pvid 2switchport general allowed vlan add 2
switchport general allowed vlan remove 1exit!interface ethernet 1/g31channel-group 2 mode onswitchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!interface ethernet 1/g32channel-group 2 mode onswitchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!interface ethernet 1/g33spanning-tree disable
spanning-tree mst 0 external-cost 20000switchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!interface ethernet 1/g34spanning-tree disablespanning-tree mst 0 external-cost 20000switchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!interface ethernet 1/g35channel-group 2 mode onswitchport mode generalswitchport general pvid 2switchport general allowed vlan add 2
switchport general allowed vlan remove 1exit!interface ethernet 1/g36channel-group 2 mode onswitchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!interface ethernet 1/g37channel-group 3 mode onswitchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!interface ethernet 1/g38channel-group 3 mode on
switchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!interface ethernet 1/g39channel-group 3 mode onswitchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!interface ethernet 1/g40channel-group 3 mode onswitchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit
!interface ethernet 1/g41channel-group 3 mode onswitchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!interface ethernet 1/g42channel-group 3 mode onswitchport mode generalswitchport general pvid 2switchport general allowed vlan add 2switchport general allowed vlan remove 1exit!interface ethernet 1/g43spanning-tree disablespanning-tree mst 0 external-cost 20000switchport mode general
switchport general pvid 3switchport general allowed vlan add 3switchport general allowed vlan remove 1exit!interface ethernet 1/g44spanning-tree disablespanning-tree mst 0 external-cost 20000switchport mode generalswitchport general pvid 3switchport general allowed vlan add 3switchport general allowed vlan remove 1exit!interface ethernet 1/g45switchport mode generalswitchport general pvid 3switchport general allowed vlan add 3switchport general allowed vlan remove 1exit!
interface ethernet 1/g46switchport mode generalswitchport general pvid 3switchport general allowed vlan add 3switchport general allowed vlan remove 1exit!interface ethernet 1/g47switchport mode generalswitchport general pvid 3switchport general allowed vlan add 3switchport general allowed vlan remove 1exit!interface ethernet 1/g48switchport mode generalswitchport general pvid 3switchport general allowed vlan add 3switchport general allowed vlan remove 1exit!
interface port-channel 1description 'LAG1-ESX1'hashing-mode 6switchport access vlan 2exit!interface port-channel 2description 'LAG2-ESX2'hashing-mode 6switchport access vlan 2exit!interface port-channel 3description 'LAG3-ESX3'hashing-mode 6switchport access vlan 2exitexit
Channel Ports Hash Algorithm Type------- ----------------------------- -------------------ch1 Active: 1/g23, 1/g24, 6 1/g25, 1/g26, 1/g27, 1/g28ch2 Active: 1/g29, 1/g30, 6 1/g31, 1/g32, 1/g35, 1/g36ch3 Active: 1/g37, 1/g38, 6 1/g39, 1/g40, 1/g41, 1/g42
VLAN Name Ports Type Authorization----- --------------- ------------- ----- -------------1 Default ch4-48, Default Required 1/xg1-1/xg42 DMZ ch1-3, Static Required 1/g33-1/g343 PUBLIC 1/g43-1/g48 Static Required4 ADMIN 1/g1-1/g22 Static Required5 Heartbeat Static Required
After that, I would like to trunk my two switch and have the same segmention on my two switch with my VLAN.
I would like to know If I must create one trunk by VLAN, or one trunk where all VLAN can passed.
Someone have an example of configuration? adviced? Because I have little knowledge in VLAN architecture.
Thank's for your help!
Regard's!