CLEANACCESS Archives

May 2006

CLEANACCESS@LISTSERV.MIAMIOH.EDU

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Mark Duling <[log in to unmask]>
Reply To:
Perfigo SecureSmart and CleanMachines Discussion List <[log in to unmask]>
Date:
Tue, 2 May 2006 18:05:18 -0400
Content-Type:
text/plain
Parts/Attachments:
text/plain (30 lines)
I need to setup CA in "inline mode" (we have non-Cisco equipment) as a "virtual gateway".  As 
such, I understand I can use my enterprise DHCP server as is and make no routing changes.  I have 
the manager setup and a server talking to it fine.  Both interfaces on server are in the same subnet 
etc,  etc.  And I have 802.1q vlan trunking setup correctly on our switches so that traffic flows to 
the CA server.  It was working at one point, for a day or so I think, but we are just testing right 
now.

But now I cannot get a DHCP address from our server anymore, nor can I assign a manual address 
to our test VLAN.  So it seems that vlan mapping is broken somehow and I don't know how to 
troubleshoot it or know what the correct settings should be.

CAM settings:
Status page says DHCP FORWARD (network -> dhcp says DHCP PASSTHROUGH)
DHCP passthrough is ON
Advanced -> VLAN Mapping has my test untrusted VLAN 510 mapped to my trusted one, VLAN 
10.

Questions:
1) How do I troubleshoot this thing?  The logfiles are not helpful.
2) Should "pass through VLAN IDS to managed network" be checked?
3) I only have the CAM subnet listed under Advanced -> Managed Subnet.  Is that right?
-Some documentation leads me to believe I need the test VLAN listed as a managed subnet too.  If 
so what whould be the IP address of the subnet?  This confuses me because subnets only have 
network numbers so what do they mean?  Default gateway?  But what would be the default 
gateway of my untrusted network?

Thank you.

Mark

ATOM RSS1 RSS2