Thursday, February 14, 2019

VLAN confusion ... Sonicwall/HP Switches/VOIP

I'm a beginner and having a difficult time with VLANs.

In my home lab, I have a Sonicwall TZ firewall, 2 8-port HP 1820 switches and a VMWare ESXi box.

Sonicwall port X0 (LAN zone): 192.168.10.1

HP1820_01 - 192.168.10.2

HP1820_02 - 192.168.10.3

ESXi host - 191.168.10.10

VM01 (DHCP) - 192.168.10.20


Sonicwall X0 is connected to HP1820_01 Port 1

HP1820_01 Port 8 is connected to HP1820_02 Port 1

HP1820_02 Port 2 is connected to the ESXi host


I'd like to be able to set up a VLAN for VOIP such that I have a VOIP phone connected to any port on HP1820_02 and then a PC connected to the VOIP phone.

The phone should get an IP adddress on a separate VLAN (100) from the DHCP server eg 192.168.100.x

The PC should get an IP address from the DHCP server in the 192.168.10.x range.

Is this possible?

Sonicwall's documentation says to add a virtual sub interface to X0. i.e. X0:V100 192.168.100.1

I'm struggling with the next step(s) on the HP switches.

There is a feature where you can add ports to a "trunk" group which is what I assumed I wanted for ports that would have both the default 192.168.10.x and the 192.168.100.x networks. When I tried configuring ports 1 and 8 of HP1820_01 in this trunk group, I lost connectivity from the Sonicwall to HP1820_01.

I removed that config then tried just creating a VLAN ID:100 on both HP swtiches.

On HP1820_01, I added the VLAN(100) to ports 1 and 8 (tagged), and left the default VLAN (1, for the 192.168.10.x network??) untagged. Is that correct?

On HP1820_02, I added the VLAN(100) for all the ports 1-8 (tagged), and left the default VLAN untagged.

Should I be able (at this point) to connect a laptop to any port on HP1820_02 with a static IP of e.g. 192.168.100.55/24 and have it be able to communicate to another laptop on the swtich with another static IP in that VLAN - e.g. 192.168.100.66/24?

On the ESXi box, is there additional network config required to recognize the VLAN?

On the DHCP VM, can I just configure a scope for each VLAN?



No comments:

Post a Comment