Cisco Systems, Inc.(R)    Cisco | Profile | Contacts & Feedback | Help
Cisco SMB Support Assistant
Create a Secure Server VLAN on an Integrated Services Router
Home > SMB Support Assistant Configuration Overview > Create a Secure Server VLAN on an Integrated Services Router  
 

Create a Secure Server VLAN on an Integrated Services Router



     Introduction
     Requirements
     VLAN Overview
          Supported VLANs
          The Secure Server VLAN
     Enable the Secure Server VLAN
          Enable the VLAN on the Router
          Enable Security
          Enable the VLAN on an Integrated Switch
     Add Users
          Add a Wired Guest User
     Next Step
     Troubleshoot the Procedure
     Related Information



Introduction

This document provides instructions for how to create a virtual LAN (VLAN) for Secure Server users on your network. A secure server VLAN gives secure server users protected access to the Internet and access to the default VLAN.

Note: VLANs are not supported on Cisco 800 series and SB 100 series routers.


Back to Top



Requirements

  • You must have completed these worksheets from the Site Survey:

    • LAN Addressing Worksheet

    • Internet Worksheet

    • Firewall Worksheet

  • You must have completed the initial configuration of your router. If you have not configured your router, refer to the Site Survey.


Back to Top



VLAN Overview

This section provides an overview of the Secure Server VLAN and how to use VLANs in your network.

Supported VLANs

The Site IP Addressing Plan includes subnets for up to four virtual LANs (VLANs) at each site. Each VLAN has a custom level of security for a specific type of computer on the network, and uses firewalls to control access between VLANs.

The site survey defines these VLANs:

  1. Default VLAN (20)

  2. Network Management VLAN (21)

  3. Secure Server VLAN (22)

  4. Guest VLAN (23)

The diagram gives an overview of each VLAN in the network. For more information on other VLANs, refer to the Configuration Overview page.

vlandiagram.gif

The Secure Server VLAN

This document provides instructions for how to create a virtual LAN (VLAN) for Secure Server users on your network. A secure server VLAN gives secure server users protected access to the Internet and access to the default VLAN.

The Secure Server VLAN provides these benefits:

  • Secure Server users can send traffic to the Internet and receive valid responses

  • Secure Server users can send traffic to the Default VLAN and receive valid responses

  • The Secure Server VLAN does not provide wireless access


Back to Top



Enable the Secure Server VLAN

Follow these steps to configure the Secure Server VLAN on an Integrated Services Router:

Enable the VLAN on the Router

To enable the Secure Server VLAN on the router, follow these steps:

  1. Follow these steps to create connect to the router with Telnet.

    1. Click Start > Run.

    2. In the Run dialog box, type cmd or command, and then click OK to open a command prompt window.

    3. At the command prompt, type telnet router-ip-address and press Enter. For router-ip-address , use the Router IP address that you entered in field L6A of the LAN Addressing Worksheet.

    4. Log into the router with the router password that you entered in field B11 of the Integrated Services Router Worksheet. For more information about how to access the router, refer to Configure Your Router with Security Device Manager.

  2. Type enable and press Enter to enter privileged mode. Enter the enable password that you entered in field B12 of the Integrated Services Router Worksheet.

    Router> enable
    Router#
  3. Type configure terminal and press Enter to enter configuration mode.

    Router# configure terminal
    Router(config)#
  4. Type interface vlan 22 and press Enter.

    Router(config)#interface vlan 22
    
  5. Type description Secure Server VLAN and press Enter.

    Router(config-if)#description Secure Server VLAN
    
  6. Type encapsulation dot1Q 22 and press Enter.

    Router(config-if)#encapsulation dot1Q 22
    
  7. Type ip address router-ip-address 255.255.255.0 and press Enter. For router-ip-address , use the Secure Server network router IP address that you entered in field L6C of the Secure Server VLAN Addressing Worksheet.

    Router(config-if)#ip address 192.168.12.1 255.255.255.0
    
  8. Type ip nat inside and press Enter.

    Router(config-if)#ip nat inside
    
  9. Type no shutdown and press Enter.

    Router(config-if)#no shutdown
    
  10. Type exit and press Enter.

    Router(config-if)#exit
    Router(config)#

Enable Security

To enable security for the Secure Server VLAN, follow these steps:

  1. Type access-list 22 permit secure-server-subnet 0.0.0.255 and press Enter. For secure-server-subnet , use the subnet that you entered in field L1C of the Secure Server VLAN Addressing Worksheet.

    Router(config)#access-list 22 permit 192.168.12.0 0.0.0.255
    
  2. Type ip nat inside source list 22 interface wan-interface overload and press Enter. For wan-interface , use the Internet interface that you entered in field B37 of the Router worksheet.

    Note: If you have more than one available Internet interface, choose the Internet interface that will be your primary connection to the Internet.

    Router(config)#ip nat inside source list 22 interface Ethernet0/1
    			 overload
    
  3. Follow these steps to create firewall rules for the Secure Server VLAN:

    1. Type no access-list 122 and press Enter.

      Router(config)#no access-list 122
      
    2. Type access-list 122 remark Traffic to Secure Server VLAN and press Enter.

      Router(config)#access-list 122 remark Traffic from Secure Server
      			 VLAN
      
    3. Type access-list 122 permit ip default-subnet 0.0.0.255 secure-server-subnet 0.0.0.255 and press Enter. For default-subnet , use the subnet you entered in field L1A of the LAN Addressing Worksheet. For secure-server-subnet , use the subnet that you entered in field L1C of the Secure Server VLAN Addressing Worksheet.

      Router(config)#access-list 122 permit ip 192.168.10.0 0.0.0.255 192.168.12.0 0.0.0.255
      
    4. Type access-list 122 permit ip management-subnet 0.0.0.255 secure-server-subnet 0.0.0.255 and press Enter. For management-subnet , use the subnet that you entered in field L1B of the Management VLAN Addressing Worksheet.

      Router(config)#access-list 122 permit ip 192.168.11.0 0.0.0.255 192.168.12.0 0.0.0.255
      
    5. Type access-list 122 permit tcp any secure-server-subnet 0.0.0.255 established and press Enter. For secure-server-subnet , use the subnet that you entered in field L1C of the Secure Server VLAN Addressing Worksheet.

      Router(config)#access-list 122 permit tcp any 192.168.12.0 0.0.0.255 established
      
    6. Type access-list 122 permit udp any any eq domain and press Enter.

      Router(config)#access-list 122 permit udp any any eq domain
      
    7. Type access-list 122 deny ip ip any and press Enter.

      Router(config)#access-list 122 deny ip ip any
      
  4. Type interface vlan 22 and press Enter.

    Router(config)#interface vlan 22
    
  5. Type ip access-group 122 out and press Enter.

    Router(config-if)#ip access-group 122 out
    
  6. Type end and press Enter to exit configuration mode.

    Router(config-if)#end
    Router#
  7. Type write memory and press Enter to save your configuration.

    Router#write memory
    

Enable the VLAN on an Integrated Switch

Follow these steps to enable the Secure Server VLAN on an integrated switch:

  1. Type enable and press Enter to enter privileged mode. Enter the enable password that you entered in field B12 of the Router Worksheet and press Enter.

    Router>enable
    Router#
  2. Type vlan database and press Enter.

    Router#vlan database
    Router(vlan)#
  3. Type vlan 22 name Secure Server media ethernet state active and press Enter.

    Router(vlan)#vlan 22 name Secure Server media ethernet state
    		  active
    
  4. Type exit and press Enter.

    Router(vlan)#exit
    APPLY completed.
    Exiting....
    Router#
    
  5. Type configure terminal and press Enter.

    Router#configure terminal
    Router(config)#
  6. Type spanning-tree vlan 22 root primary and press Enter.

    Router(config-if)#spanning-tree vlan 22 root primary
     VLAN 22 bridge priority set to 8192
     VLAN 22 bridge max aging time unchanged at 20
     VLAN 22 bridge hello time unchanged at 2
     VLAN 22 bridge forward delay unchanged at 15
  7. Type end and press Enter.

    Router(config-if)#end
    Router#
  8. Type write memory and press Enter.

    Router#write memory
    

Back to Top



Add Users

To move users to the Secure Server VLAN, follow these steps:

Add a Wired Guest User

Follow these steps to add a Secure Server user connected directly to a switch port on the ISR:

  1. Type configure terminal and press Enter.

    Router#configure terminal
    Router(config)#
  2. Type interface FastEthernet interface-number and press Enter. For interface-number , use the number of the switch port that you want to assign to a Secure Server user. The available switch ports are listed in field B36 of the Router Worksheet.

    Router(config)#interface FastEthernet0/2
    Router(config-if)#
  3. Type description Secure Server Switch Port and press Enter.

    Router(config-if)#description Secure Server Switch Port
    
  4. Type switchport access vlan 22 and press Enter.

    Router(config-if)#switchport access vlan 22
    
  5. Type end and press Enter.

    Router(config-if)#end
    Router#
  6. Type write memory and press Enter.

    Router#write memory
    
  7. Record the device name in the first available field from fields L8-L35 of the Secure Server VLAN Addressing Worksheet.

  8. Configure the device with the IP address in the Secure Server VLAN Addressing Worksheet. For example, the first device in the Secure Server VLAN is configured with the IP address 192.168.12.2. For more information about how to configure an IP address on a PC, refer to Configure an IP Address on Your PC.


Back to Top



Next Step

You have now set up a Secure Server VLAN on your network.

To make further changes to your network, refer to the Configuration Overview page.


Back to Top



Troubleshoot the Procedure

This section provides information about common problems that you may encounter. If this information does not solve your problem, contact the SMB Technical Assistance Center (SMB TAC) for assistance.

Problem

Cause(s) and Suggested Solution(s)

I cannot connect to the router with Security Device Manager (SDM).

Refer to Configure Your Router with Security Device Manager

I have a Secure Server user that cannot connect to the Secure Server VLAN.

Refer to Move a LAN User Between Groups to move the appropriate switch port to the Secure Server VLAN.


Back to Top



Related Information

Service Requests

  Open a service request
  Update a service request

Feedback

Please rate this document.
++ + +/- - --

This document solved my problem.

Yes No Just Browsing

Suggestions for improvement:




If Cisco may contact you for more details
or for future feedback opportunities,
please enter your contact information.

Full Name:
E-mail:



© 1992-2006 Cisco Systems, Inc. All rights reserved. Terms and Conditions, Privacy Statement, Cookie Policy and Trademarks of Cisco Systems, Inc.