Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

vlan 1 and intervlan routing

Status
Not open for further replies.

dogsbod

Technical User
Sep 25, 2003
88
0
0
GB
I'm planning the vlan scheme to be used and have created several test vlans and assigned SVIs to them.
The plan is to leave the servers on the 192.168.225.x network and assign different network addresses to departmental hosts.
I've created vlans 2 and 3 and assigned 192.168.1.1 and 192.168.3.1 to them respectively. A statically configure host in vlan 1 or 3 can ping each other, but there is no ping response from these two vlans to vlan 1 where all the hosts reside at the moment. Can vlan 1 participate in intervlan routing?
 
Yes VLAN 1 can participate in inter-vlan routing. What kind of switch are you using? Can you paste a copy of the switch's running configuration here as well?

In the meantime, check the IP settings on some of the hosts that cannot communicate with each other. Ensure the IP address, subnet mask and default gateway is set correctly.
 
the hosts on vlan 1 have their default gateway set to the lan interface of the firewall, the hosts in other vlan have default gateway set to the svi ip address interface for their respective vlans. An ip address is configured on vlan 1 to allow management of switch (4500), is this equivalent to an svi on vlan 1? I don't want to change the ip address scheme of the servers as I've heard this can cause probelms with active directory. Is there a recommended way to procede with intervlan routing in mind.
 
1 add a test host in vlan 1 and assign it a gateway of svi, see if it works, ping an address on vlan 2/3 and see if it works. See if it can reach devices on the other side of the firewall.

2 Add routes to your vlan's 2 and 3 networks on your firewall.
3 Add a default route on your 4500 that points to your firewall (if you want vlan 2 and 3 to use the firewall).

Paste that config(s) for more detailed help.
 
Anything on vlan 1 cannot have a gateway of the firewall if you want to route to the other vlans . The gateway has to be the 4500 vlan 1 SVI address as the gateway and if needed you point a default static route to the firewall .
 
thanks for the points. I didn't think the default gateway settings for hosts on vlan 1 had relavence to a host on vlan 2\3 pinging a host on vlan 1, the otherway round (vlan 1 ping vlan 2) I understand
 
The hosts on vlan 2 and 3 gateways have to be the SVI on the 4500 for vlan 2 and 3 respectively .
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top