Cisco SG500 <-> 2960/2950 VPN

, posted: 20-Oct-2015 09:47


I am no Cisco tech so this may seem obvious to the Pros.
Googling did not return the solution in one hit.
Recently had to get get a network of Catalyst 2960 and SG500 to work together with VPNs.
The SG500 was the backbone and powered the 2960's via POE.

The SG500's do not support VTP.
They do support the industry equivilant of GVRP (IEEE 802.1p).
This means you have to manually set up VPNs on both devices.
Names assigned to the VPN do not matter only the VPN number.

The ports default to Trunks, you would assume that all VPN traffic would pass through by default.
Not so.
1. Create the VPN on the SG500.
2. Assign the port to the VPN.
3. Add the port to the VPN.

2 and 3 may seem like the same thing.
2 Controls access, while 3 controls membership.

Of course I may be doing this wrong but this is what I had to do to get it to work for me.

You can imagine 10 switches x 5 VPNs adds up to a lot of manual configuration without the auto propagating VTP.

Good setup guide on the SG500

VLAN and VTP config information

