We are redesigning our network at work and our aim is for all subnets to be able to access the internet. Our core switch is an alcatel 7800 omniswitch. It hosts 5 VLANS and the switch also has an IP address on each VLAN that is the default gateway for each VLAN.
Clients can ping other computers on other VLANS, a traceroute shows the packets being routed to other VLANS through the switch just fine.
Our firewall is located in VLAN2. Clients on VLAN2 (192.168.2.0/24) send packets to default gateway (the switch 192.168.2.254) which forwards them to the firewall 192.168.2.1. Its not true routing, the packets never leave the subnet but internet access works fine.
The real problem is other VLANS can't get out to the internet. Clients send packets to the switch as the default gateway, but then it can;t talk to the firewall. I have entered a default route (static route)into the switch that sends all traffic to the firewall but it just doesn't work.
Firewall is a watchguard firebox 1000...I can't see anything on the firebox as to why it doesn't accept traffic routed to it from other VLANS. It works fine for our vlan2 network.
Little visual diagram:
192.168.2.0/24-->192.198.2.254 (D.G.)-->192.168.2.1(firewall)-->internet works just fine.
192.168.3.0/24-->192.168.3.1 (D.G.)->192.168.2.1(firewall) no internet
Same thing with other VLANS.
Any suggestions? I'm about scraping the bottom of the barrell here. Thanks in advance.
Clients can ping other computers on other VLANS, a traceroute shows the packets being routed to other VLANS through the switch just fine.
Our firewall is located in VLAN2. Clients on VLAN2 (192.168.2.0/24) send packets to default gateway (the switch 192.168.2.254) which forwards them to the firewall 192.168.2.1. Its not true routing, the packets never leave the subnet but internet access works fine.
The real problem is other VLANS can't get out to the internet. Clients send packets to the switch as the default gateway, but then it can;t talk to the firewall. I have entered a default route (static route)into the switch that sends all traffic to the firewall but it just doesn't work.
Firewall is a watchguard firebox 1000...I can't see anything on the firebox as to why it doesn't accept traffic routed to it from other VLANS. It works fine for our vlan2 network.
Little visual diagram:
192.168.2.0/24-->192.198.2.254 (D.G.)-->192.168.2.1(firewall)-->internet works just fine.
192.168.3.0/24-->192.168.3.1 (D.G.)->192.168.2.1(firewall) no internet
Same thing with other VLANS.
Any suggestions? I'm about scraping the bottom of the barrell here. Thanks in advance.