NetScreen
[Top] [All Lists]

[nn] Vlan Tagging and DHCP

To: nn@qorbit.net
Subject: [nn] Vlan Tagging and DHCP
From: hboogz <hboogz@gmail.com>
Date: Thu, 4 Jan 2007 17:00:04 -0500
Delivered-to: sp-com-lists@consult.net
Delivered-to: ns-list2@consult.net
Delivered-to: nn@qorbit.net
Domainkey-signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:to:subject:mime-version:content-type; b=HRP6rAWlcdxguo3iFM/tfQB9rFR/8HfjH+lUeWwBVINj4yWw1KLpeKWuwuT01/5nEFAc54OqS1PQz7jIGRO6I229UxQojOO52/1Rbi6VzoRU4r6YesrtZzQBjSKwOlh89ihODDmuV8bzcK+Lk7JGexvLhMhSIQB+5zObMYNiaps=
List-archive: <http://www.qorbit.net/nn>
List-help: <mailto:nn-request@qorbit.net?subject=help>
List-id: "Netscreen mailing list for netscreen admins." <nn.qorbit.net>
List-post: <mailto:nn@qorbit.net>
List-subscribe: <http://qorbit.net/mailman/listinfo/nn>, <mailto:nn-request@qorbit.net?subject=subscribe>
List-unsubscribe: <http://qorbit.net/mailman/listinfo/nn>, <mailto:nn-request@qorbit.net?subject=unsubscribe>
Sender: nn-bounces@qorbit.net
Hi all,

I currently have a netscreen 5GT terminating to a checkpoint FW-1 firewall using an ipsec vpn tunnel.

Behind the checkpoint there is a central DHCP server. Behind the netscreen we have Cisco 1130 AG access points deployed and the netscreen's DHCP function is set to DHCP-relay.

The issue i am having is, when i introduce a second guest SSID, i want that SSID to map to a different VLAN. i have done the necessary config on the Cisco AP, but can't seem to get an IP for the second VLAN i've defined.

Central Office - 192.168.1.x

Site office - 192.168.8.x

Vlan1 gets an ip from the central office's DHCP scope 192.168.1.x

Vlan2 - 192.168.254.x

Now, what needs to be done on the netscreen in order for it to receive the vlan 2 tag in order to issue an IP from the vlan 2 scope defined on the switches and dhcp server at the central office ?

any ideas would be great.

I'm thinking if i define a sub-interface on the netscreen with vlan 2 tag and somehow issue a udp-helper command for that interface to point to the dhcp-server 192.168.1.x -- ?

Thanks,

--

_______________________________________________
nn mailing list
nn@qorbit.net
http://qorbit.net/mailman/listinfo/nn
<Prev in Thread] Current Thread [Next in Thread>