<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrating to new firewall with VLANs in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/migrating-to-new-firewall-with-vlans/m-p/84369#M20423</link>
    <description>&lt;P&gt;Yes, VRRP is in use because your Core-Switches are two standalone switches (and no stack/chassis/vsb...). The two X690 share the virtual ip address 10.165.18.1 - one of the two switches has a higher priority and is the Master. The Backup will become the master if the Master fails.&lt;/P&gt;&lt;P&gt;And yes, in your Case you can disable vrrp since your Core-Switches won’t route any more.&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;configure vrrp vlan CLIENTS vrid 118 delete 10.165.18.1&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;is the command to delete the virtual ip address. You can look up the current vrrp config by issuing&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;show configuration vrrp&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;To completely remove it, use these commands:&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;configure vrrp vlan CLIENTS vrid 118 delete 10.165.18.1&lt;BR /&gt;delete vrrp vlan CLIENTS vrid 118&lt;BR /&gt;disable vrrp&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;(deleting the vrrp might be enough, but I’m currently unsure if you can delete a vrrp on a vlan if there is still a virtual ip configured)&lt;/P&gt;&lt;P&gt;to remove the ip address and disable ip-forwarding:&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;unconfigure vlan CLIENTS ipaddress&lt;BR /&gt;disable ipforwarding vlan CLIENTS&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;If your new firewall is also a cluster it will most likely also use vrrp, although you probably won’t have to configure it. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 22 Sep 2020 02:11:52 GMT</pubDate>
    <dc:creator>Stefan_K_</dc:creator>
    <dc:date>2020-09-22T02:11:52Z</dc:date>
    <item>
      <title>Migrating to new firewall with VLANs</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/migrating-to-new-firewall-with-vlans/m-p/84366#M20420</link>
      <description>&lt;P&gt;Good Morning everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are running Extreme X690’s for our core.&amp;nbsp; This currently does our VLAN routing for us, with a default gateway to an old firewall that is not configured for VLANs (its being sent untagged packets).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a new firewall I am installing and it is now required to have the new firewall be passed the VLANs so we can handle any firewalling/routing between those VLANs.&amp;nbsp; I have configured the new firewall with appropriate VLAN interfaces, and trunked the appropriate VLANs to it from the core with TAGs.&amp;nbsp; Each VLAN interface on the firewall has its own IP (for example 10.165.8.254, 10.165.18.254, 10.165.22.84, etc).&amp;nbsp; In testing I can ping these IPs from the respective VLANS, so that looks OK from what I&amp;nbsp;can tell.&amp;nbsp; So far, so good I hope.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here comes the part where I admit I am NOT an network engineer.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp; How do I change the core so that each VLAN will report to its own gateway IP?&amp;nbsp; Currently the default gateway of the switches reports to 10.165.8.254, which I&amp;nbsp;do not believe will work if we need to firewall between these VLANs.&amp;nbsp; Shouldn’t each VLAN report to its own gateway on the subnet?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any help is appreciated.&amp;nbsp; Hopefully I’m on the right track.&amp;nbsp; The new firewall is not live yet, but I am hoping to figure this out ahead of time to save me a weekend of debugging trying to get this live in October.&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;Ray&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 22:18:54 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/migrating-to-new-firewall-with-vlans/m-p/84366#M20420</guid>
      <dc:creator>RayR</dc:creator>
      <dc:date>2020-09-21T22:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating to new firewall with VLANs</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/migrating-to-new-firewall-with-vlans/m-p/84367#M20421</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;the things you said make sense, so I don’t really understand what your problems are. &lt;span class="lia-inline-image-display-wrapper" image-alt="b284bba522fb4d3b9c1fdd710c29d089_1f601.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/3018iDCC3466BD64447C8/image-size/large?v=v2&amp;amp;px=999" role="button" title="b284bba522fb4d3b9c1fdd710c29d089_1f601.png" alt="b284bba522fb4d3b9c1fdd710c29d089_1f601.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;the firewall has the same IP-Addresses on its VLAN-interfaces as the X690? Then you just have to unconfigure the IP-Addresses from the X690. The X690 will switch the tagged packets to firewall. The firewall will be the new gateway for the vlans and handle all the traffic/routing.&lt;/P&gt;&lt;P&gt;You only might need to configure a new IP-Interface on the X690 for the management of the switch itself (after you have unconfigured all IP-addresses.)&lt;/P&gt;&lt;P&gt;Simple example:&lt;BR /&gt;You have VLANs 10,20,30. VLAN30 is used for Switch/Network-Mgmt.&lt;BR /&gt;Firewall is connected to Port 1 of the X690, Edge-Switches are connected to Port 2-9.&lt;BR /&gt;You tag VLAN 10,20 and 30 on Port 1 to 9.&lt;BR /&gt;Firewall has 1 physical interfaces (connected to Port 1 of the X690) which has 3 VLAN interfaces: VLAN10, 20 and 30. The IP-Addresses of these VLANs are the old IP-Addresses of the X690 (so you don’t have to change DHCP-Settings or static configurations on some devices)&lt;BR /&gt;You unconfigure all IP-Addresses of the X690.&lt;BR /&gt;The firewall-interfaces are now reachable from the VLANs.&lt;BR /&gt;Configure a new IP-Address on VLAN30 on the X690. Default Gateway of the X690 is the IP-Address of the firewall (on VLAN30). X690 is now manageable again.&lt;/P&gt;&lt;P&gt;I hope my text is not too confusing… If you have any questions, feel free to ask.&lt;/P&gt;&lt;P&gt;Best regards&lt;BR /&gt;Stefan&lt;/P&gt;</description>
      <pubDate>Mon, 21 Sep 2020 22:49:03 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/migrating-to-new-firewall-with-vlans/m-p/84367#M20421</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2020-09-21T22:49:03Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating to new firewall with VLANs</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/migrating-to-new-firewall-with-vlans/m-p/84368#M20422</link>
      <description>&lt;P&gt;Stefan,&lt;/P&gt;&lt;P&gt;Thanks, that makes perfect sense!&amp;nbsp; I was starting to look at using static routes to get me there.&lt;/P&gt;&lt;P&gt;I’m looking in the config of the core switches, and see this on 2 of them for one of&amp;nbsp;our VLANs I need to change.&amp;nbsp; Others are the same with IPs respective to their net…&amp;nbsp;so Im assuming the same solution for all involved VLANs.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;configure vrrp vlan CLIENTS vrid 118 add 10.165.18.1&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;This looks like its assigning an IP to a virtual router correct?&amp;nbsp; So, would I just be removing this IP&amp;nbsp;and assigning the IP 10.165.18.1 on the firewall interface?&amp;nbsp; If so, would I just &lt;EM&gt;&lt;STRONG&gt;configure vrrp vlan CLIENTS vrid 118 delete 10.165.18.1&lt;/STRONG&gt;&lt;/EM&gt;?&lt;/P&gt;&lt;P&gt;If not, then maybe it didn’t make perfect sense to me after all!&amp;nbsp;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper" image-alt="e28474442316430f8aed3bbbe2259395_1f602.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/2993i7B2532FF5B7BED81/image-size/large?v=v2&amp;amp;px=999" role="button" title="e28474442316430f8aed3bbbe2259395_1f602.png" alt="e28474442316430f8aed3bbbe2259395_1f602.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;Ray&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 00:17:59 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/migrating-to-new-firewall-with-vlans/m-p/84368#M20422</guid>
      <dc:creator>RayR</dc:creator>
      <dc:date>2020-09-22T00:17:59Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating to new firewall with VLANs</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/migrating-to-new-firewall-with-vlans/m-p/84369#M20423</link>
      <description>&lt;P&gt;Yes, VRRP is in use because your Core-Switches are two standalone switches (and no stack/chassis/vsb...). The two X690 share the virtual ip address 10.165.18.1 - one of the two switches has a higher priority and is the Master. The Backup will become the master if the Master fails.&lt;/P&gt;&lt;P&gt;And yes, in your Case you can disable vrrp since your Core-Switches won’t route any more.&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;configure vrrp vlan CLIENTS vrid 118 delete 10.165.18.1&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;is the command to delete the virtual ip address. You can look up the current vrrp config by issuing&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;show configuration vrrp&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;To completely remove it, use these commands:&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;configure vrrp vlan CLIENTS vrid 118 delete 10.165.18.1&lt;BR /&gt;delete vrrp vlan CLIENTS vrid 118&lt;BR /&gt;disable vrrp&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;(deleting the vrrp might be enough, but I’m currently unsure if you can delete a vrrp on a vlan if there is still a virtual ip configured)&lt;/P&gt;&lt;P&gt;to remove the ip address and disable ip-forwarding:&lt;/P&gt;&lt;PRE&gt;&lt;CODE&gt;unconfigure vlan CLIENTS ipaddress&lt;BR /&gt;disable ipforwarding vlan CLIENTS&lt;/CODE&gt;&lt;/PRE&gt;&lt;P&gt;If your new firewall is also a cluster it will most likely also use vrrp, although you probably won’t have to configure it. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 02:11:52 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/migrating-to-new-firewall-with-vlans/m-p/84369#M20423</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2020-09-22T02:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating to new firewall with VLANs</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/migrating-to-new-firewall-with-vlans/m-p/84370#M20424</link>
      <description>&lt;P&gt;It sounds like I had better plan a good revert strategy for this one in case it goes poorly!&amp;nbsp;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper" image-alt="1e69b9cee527401b80157acbe3b7f960_1f600.png"&gt;&lt;img src="https://community.extremenetworks.com/t5/image/serverpage/image-id/909iEB3C01E1A53DB4BF/image-size/large?v=v2&amp;amp;px=999" role="button" title="1e69b9cee527401b80157acbe3b7f960_1f600.png" alt="1e69b9cee527401b80157acbe3b7f960_1f600.png" /&gt;&lt;/span&gt; &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for your help!&amp;nbsp; I will let you know how the project went when it is complete.&amp;nbsp; And, if you are ever in the Heilbronn area, I will have Markus in our Heilbronn office buy you some bier!&lt;/P&gt;&lt;P&gt;Best regards Stefan!&lt;/P&gt;&lt;P&gt;Ray&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 02:35:33 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/migrating-to-new-firewall-with-vlans/m-p/84370#M20424</guid>
      <dc:creator>RayR</dc:creator>
      <dc:date>2020-09-22T02:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating to new firewall with VLANs</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/migrating-to-new-firewall-with-vlans/m-p/84371#M20425</link>
      <description>&lt;P&gt;In the past I was monthly in Heilbronn. I don’t know about the future though, but I appreciate your offer! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Sep 2020 03:39:42 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/migrating-to-new-firewall-with-vlans/m-p/84371#M20425</guid>
      <dc:creator>Stefan_K_</dc:creator>
      <dc:date>2020-09-22T03:39:42Z</dc:date>
    </item>
  </channel>
</rss>

