<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: BES-53248 default vLAN 1 - change for stigs in ONTAP Hardware</title>
    <link>https://community.netapp.com/t5/ONTAP-Hardware/BES-53248-default-vLAN-1-change-for-stigs/m-p/440562#M11438</link>
    <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/12128"&gt;@andris&lt;/a&gt;&amp;nbsp;thank you for the response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running&amp;nbsp;EFOS, 3.9.0.2&lt;/P&gt;&lt;P&gt;vLan 999 has been added to the vlan database&lt;/P&gt;&lt;P&gt;here is the running-config on port 0/1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;interface 0/1
service-policy in CLUSTER
no shutdown
description "10/25GbE Node Port"
spanning-tree edgeport
mtu 9216
switchport mode trunk
switchport trunk allowed vlan 1,17-18
datacenter-bridging
priority-flow-control mode on
priority-flow-control priority 2 no-drop
priority-flow-control priority 5 no-drop
exit
exit&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I added 999 to the allowed vlans&amp;nbsp;&lt;/P&gt;&lt;P&gt;and made 999 the native vlan.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; Current Configuration:
!
interface 0/1
service-policy in CLUSTER
no shutdown
description "10/25GbE Node Port"
spanning-tree edgeport
mtu 9216
switchport mode trunk
switchport trunk native vlan 999
switchport trunk allowed vlan 1,17-18,999
datacenter-bridging
priority-flow-control mode on
priority-flow-control priority 2 no-drop
priority-flow-control priority 5 no-drop
exit
exit &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; 
          Port       Port                  Ingress    Ingress
          VLAN ID    VLAN ID  Acceptable   Filtering  Filtering  Default
Interface Configured Current  Frame Types  Configured Current    Priority
--------- ---------- -------- ------------ ---------- ---------  --------
0/1       999        999      Admit All    Enable     Enable     0
0/2       1          1        Admit All    Enable     Enable     0
0/3       1          1        Admit All    Enable     Enable     0
0/4       1          1        Admit All    Enable     Enable     0 &lt;/LI-CODE&gt;&lt;P&gt;This is exactly what I was looking for! Thank you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I can ask two more questions:&lt;/P&gt;&lt;P&gt;1: If port 0/1 will be using vlan 17 either as the Netapp connection or a server connection to the netapp it's ok to change the native vlan to 17 for that port correct?&amp;nbsp;&lt;/P&gt;&lt;P&gt;2: My current config is&amp;nbsp;&lt;U&gt;switchport trunk allowed vlan 1,17-18,999&lt;/U&gt; - vlan 1 is the default vlan - is there any reason why I can't remove vlan 1 from the trunk allowed vlan ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for the help!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 15 Dec 2022 12:00:47 GMT</pubDate>
    <dc:creator>Loxley</dc:creator>
    <dc:date>2022-12-15T12:00:47Z</dc:date>
    <item>
      <title>BES-53248 default vLAN 1 - change for stigs</title>
      <link>https://community.netapp.com/t5/ONTAP-Hardware/BES-53248-default-vLAN-1-change-for-stigs/m-p/440527#M11436</link>
      <description>&lt;P&gt;I have 2 BES-53248 switches clustered using Netapps&amp;nbsp;BES-53248-RCF-v1.8-Cluster config. Prior to installing this config I was able to change the default vlan from 1 to 999 as part of security stigs I need to apply. After running the config I can no long change that setting or at least when I run&amp;nbsp;&lt;/P&gt;&lt;P&gt;(cs01)(Interface 0/1)#vlan pvid 999&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do see 999 applied to the running config but when I run&amp;nbsp;&lt;/P&gt;&lt;P&gt;(cs01)#show vlan port all&lt;/P&gt;&lt;P&gt;0/1 Port vlan ID configured and current are both vlan 1 .&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any thoughts? I have a felling it has something to do with the clustering, but I just don't know enough about these switches to speak to it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 09:54:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Hardware/BES-53248-default-vLAN-1-change-for-stigs/m-p/440527#M11436</guid>
      <dc:creator>Loxley</dc:creator>
      <dc:date>2025-06-04T09:54:24Z</dc:date>
    </item>
    <item>
      <title>Re: BES-53248 default vLAN 1 - change for stigs</title>
      <link>https://community.netapp.com/t5/ONTAP-Hardware/BES-53248-default-vLAN-1-change-for-stigs/m-p/440558#M11437</link>
      <description>&lt;P&gt;What EFOS version are you on?&lt;/P&gt;&lt;P&gt;Make sure you add VLAN 999 to the VLAN database.&lt;/P&gt;&lt;P&gt;The cluster node ports are in "trunk"mode.&lt;/P&gt;&lt;P&gt;So, you would set the native VLAN to 999 (it defaults to VLAN 1) for your untagged ingress traffic.&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;interface 0/1-0/16&lt;/STRONG&gt;&lt;BR /&gt;&lt;STRONG&gt;switchport trunk native vlan&amp;nbsp;999&lt;/STRONG&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 14 Dec 2022 19:57:23 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Hardware/BES-53248-default-vLAN-1-change-for-stigs/m-p/440558#M11437</guid>
      <dc:creator>andris</dc:creator>
      <dc:date>2022-12-14T19:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: BES-53248 default vLAN 1 - change for stigs</title>
      <link>https://community.netapp.com/t5/ONTAP-Hardware/BES-53248-default-vLAN-1-change-for-stigs/m-p/440562#M11438</link>
      <description>&lt;P&gt;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/12128"&gt;@andris&lt;/a&gt;&amp;nbsp;thank you for the response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm running&amp;nbsp;EFOS, 3.9.0.2&lt;/P&gt;&lt;P&gt;vLan 999 has been added to the vlan database&lt;/P&gt;&lt;P&gt;here is the running-config on port 0/1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;interface 0/1
service-policy in CLUSTER
no shutdown
description "10/25GbE Node Port"
spanning-tree edgeport
mtu 9216
switchport mode trunk
switchport trunk allowed vlan 1,17-18
datacenter-bridging
priority-flow-control mode on
priority-flow-control priority 2 no-drop
priority-flow-control priority 5 no-drop
exit
exit&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So I added 999 to the allowed vlans&amp;nbsp;&lt;/P&gt;&lt;P&gt;and made 999 the native vlan.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; Current Configuration:
!
interface 0/1
service-policy in CLUSTER
no shutdown
description "10/25GbE Node Port"
spanning-tree edgeport
mtu 9216
switchport mode trunk
switchport trunk native vlan 999
switchport trunk allowed vlan 1,17-18,999
datacenter-bridging
priority-flow-control mode on
priority-flow-control priority 2 no-drop
priority-flow-control priority 5 no-drop
exit
exit &lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; 
          Port       Port                  Ingress    Ingress
          VLAN ID    VLAN ID  Acceptable   Filtering  Filtering  Default
Interface Configured Current  Frame Types  Configured Current    Priority
--------- ---------- -------- ------------ ---------- ---------  --------
0/1       999        999      Admit All    Enable     Enable     0
0/2       1          1        Admit All    Enable     Enable     0
0/3       1          1        Admit All    Enable     Enable     0
0/4       1          1        Admit All    Enable     Enable     0 &lt;/LI-CODE&gt;&lt;P&gt;This is exactly what I was looking for! Thank you.&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I can ask two more questions:&lt;/P&gt;&lt;P&gt;1: If port 0/1 will be using vlan 17 either as the Netapp connection or a server connection to the netapp it's ok to change the native vlan to 17 for that port correct?&amp;nbsp;&lt;/P&gt;&lt;P&gt;2: My current config is&amp;nbsp;&lt;U&gt;switchport trunk allowed vlan 1,17-18,999&lt;/U&gt; - vlan 1 is the default vlan - is there any reason why I can't remove vlan 1 from the trunk allowed vlan ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you very much for the help!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 12:00:47 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Hardware/BES-53248-default-vLAN-1-change-for-stigs/m-p/440562#M11438</guid>
      <dc:creator>Loxley</dc:creator>
      <dc:date>2022-12-15T12:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: BES-53248 default vLAN 1 - change for stigs</title>
      <link>https://community.netapp.com/t5/ONTAP-Hardware/BES-53248-default-vLAN-1-change-for-stigs/m-p/440569#M11439</link>
      <description>&lt;P&gt;A1: VLANs 17 and 18 are used for HA traffic on AFF/FAS platforms that use a shared cluster+HA Ethernet ports (AFF A320, AFF A250, FAS500f).&amp;nbsp; Please do not change anything related to VLANs 17 and 18.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A2: The ISL ports 0/55 and 0/56 normally ONLY span VLAN 1 (default VLAN). You should NOT be spanning VLAN 17/18 (this is by design).&amp;nbsp; Now with VLAN 999 being used natively for cluster traffic, I would go with this config:&lt;BR /&gt;&lt;U&gt;switchport trunk allowed vlan 1,999&lt;/U&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I believe VLAN 1 is still used for some control traffic (e.g. CDP/ISDP), so that's why I'm keeping VLAN 1 in there. But you can remove it and see what happens &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 18:03:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Hardware/BES-53248-default-vLAN-1-change-for-stigs/m-p/440569#M11439</guid>
      <dc:creator>andris</dc:creator>
      <dc:date>2022-12-15T18:03:06Z</dc:date>
    </item>
    <item>
      <title>Re: BES-53248 default vLAN 1 - change for stigs</title>
      <link>https://community.netapp.com/t5/ONTAP-Hardware/BES-53248-default-vLAN-1-change-for-stigs/m-p/440570#M11440</link>
      <description>&lt;P&gt;Thanks for the info - I'll play with the config for a bit and see how everything works out.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks again for the help have a Merry Christmas&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 15 Dec 2022 18:08:24 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Hardware/BES-53248-default-vLAN-1-change-for-stigs/m-p/440570#M11440</guid>
      <dc:creator>Loxley</dc:creator>
      <dc:date>2022-12-15T18:08:24Z</dc:date>
    </item>
  </channel>
</rss>

