<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic layer 2 layer 3 vlan  cisco 3750 in Switching</title>
    <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462898#M292279</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amit &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It depends on whether you are routing vlan 10 on the firewall or not. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You wouldn't do "no switchport" if you are routing vlan 10 on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please be specific in what you want as it keeps changing and it's not clear what you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Mar 2014 14:46:41 GMT</pubDate>
    <dc:creator>Jon Marshall</dc:creator>
    <dc:date>2014-03-05T14:46:41Z</dc:date>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462885#M292266</link>
      <description>&lt;P&gt;hello we have a 3750 cisco switch , need to built a setup with 2 vlans &lt;/P&gt;&lt;P&gt;vlan 10 with subnet 172.16.20.0/24&amp;nbsp; gateway ip address is 172.16.20.1 which is on firewall which is connected to uplink port eth 1/1 on 3750&lt;/P&gt;&lt;P&gt;vlan 20 10.10.10.0/24&amp;nbsp; with gateway 10.10.10.1 on this 3750 switch . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand we need to create Layer 2 vlan for Vlan 10 and layer 3 vlan for Vlan 20 , but was not sure what config i need to put if any one can help will be great &lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2019 02:32:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462885#M292266</guid>
      <dc:creator>amit bhatnagar</dc:creator>
      <dc:date>2019-03-08T02:32:22Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462886#M292267</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amit &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you need vlan 10 to have it's gateway as the firewall ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would be more logical to have both vlans routed on the 3750 and then have a separate connection to the firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it for security reasons ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also is it just one firewall or a pair ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you could clarify we can help you with the config. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 11:36:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462886#M292267</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-03-05T11:36:00Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462887#M292268</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello John , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have one firewall its not a pair , &lt;/P&gt;&lt;P&gt;And we are asked to use the firewall interface for Vlan 10 , can we still configure layer 3 for both vlan on 3750 ? if not what will be suggested solution . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Amit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 12:22:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462887#M292268</guid>
      <dc:creator>amit bhatnagar</dc:creator>
      <dc:date>2014-03-05T12:22:05Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462888#M292269</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amit &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the firewall for vlan 10 but that means for traffic between the two vlans you will need to send traffic back out of the same interface on the firewall ie. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC1 in vlan 10 has it's default gateway set to the firewall inside interface. If that PC1 sends traffic to PC2 in vlan 20 then the traffic goes to the firewall and then has to be sent back out of the same interface to the 3750. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know if your firewall can do this and are you okay with configuring that ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 12:37:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462888#M292269</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-03-05T12:37:19Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462889#M292270</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes our firewall can do that , we are ok with this config . &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Amit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 12:59:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462889#M292270</guid>
      <dc:creator>amit bhatnagar</dc:creator>
      <dc:date>2014-03-05T12:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462890#M292271</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amit &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the 3750 - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) enable ip routing if it isn't already ie. - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switch(config)# ip routing &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) create both vlans at L2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switch(config)# vlan 10 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switch(config)# vlan 20 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) create L3 SVIs for both vlans eg. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int vlan 10&lt;/P&gt;&lt;P&gt;ip address 172.16.20.x 255.255.255.0&amp;nbsp;&amp;nbsp; &amp;lt;-- where x is unused IP&lt;/P&gt;&lt;P&gt;no shut &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int vlan 20&lt;/P&gt;&lt;P&gt;ip address 10.10.10.1 255.255.255.0&amp;nbsp; &lt;/P&gt;&lt;P&gt;no shut &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) add a default route pointing to the firewall - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 172.16.20.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;then on the firewall you need to add a route for vlan 20 if it is ASA it would look like - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 10.10.10.0 255.255.255.0 &lt;L3 vlan="" 10="" interface="" ip="" on="" 3750=""&gt; &lt;/L3&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the default gateway for clients in vlan 10 is still the firewall. The vlan 10 SVI on the 3750 is only used to route to and from vlan 20 clients. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 13:04:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462890#M292271</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-03-05T13:04:49Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462891#M292272</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;really sincerely appreicate your help on this Jon , one quick query I need to keep PC default gateway as below&lt;/P&gt;&lt;P&gt;PC 1 Vlan 10 172.16.20.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;------which is the firewall&lt;/P&gt;&lt;P&gt; PC2 Vlan 20 10.10.10.1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;lt;--------- which is 3750&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also is this standard solution or work around ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Amit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 13:44:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462891#M292272</guid>
      <dc:creator>amit bhatnagar</dc:creator>
      <dc:date>2014-03-05T13:44:33Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462892#M292273</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The "standard" solution is as i say to route both vlans on the 3750 and only send traffic to the firewall for the internet. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With this solution you use a separate subnet for connectivity between the 3750 and the firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But you said you had to have the default gateway of the clients in vlan 10 to be the firewall so i adjusted the configuration accordingly. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 13:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462892#M292273</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-03-05T13:48:39Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462893#M292274</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;just wanted to know if we want to use standard solution with both subnets VLAN 10 and VLAN 20 , do we need another subnet for P2P link between 3750 and firewall . will be great help if you can share config for it &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 13:54:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462893#M292274</guid>
      <dc:creator>amit bhatnagar</dc:creator>
      <dc:date>2014-03-05T13:54:05Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462894#M292275</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amit &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you wanted to do that then you can use the same config as before but it would mean readdressing the inside interface of your firewall plus some modifications to the routing. So using the original config i posted - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) use a new subnet for the 3750 to firewall connection. As you only have one firewall then you can use a L3 routed link eg. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3750&lt;/P&gt;&lt;P&gt;====&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int gi0/0 &amp;lt;-- this connect to the firewall &lt;/P&gt;&lt;P&gt;no switchport &lt;/P&gt;&lt;P&gt;ip address 192.168.5.1 255.255.255.252&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall&lt;/P&gt;&lt;P&gt;======&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the inside interface then needs to use the IP address 192.168.5.2 255.255.255.252 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) you need to update the routing - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3750&lt;/P&gt;&lt;P&gt;====&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;replace the existing default route with - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 192.168.5.2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;firewall&lt;/P&gt;&lt;P&gt;=======&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you need routes for both subnets now eg. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;route inside 172.16.20.0 255.255.255.0 192.168.5.1 &lt;/P&gt;&lt;P&gt;route inside 10.10.10.0 255.255.255.0 192.168.5.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) finally the default gateway of the vlan 10 clients should point to the 3750 L3 vlan 10 interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note, if you do not want to readdress the firewall interface then you can use the existing vlan 10 subnet for the connection from the 3750 to the firewall and then use a new IP subnet for vlan 10. If all the clients used DHCP this may be easier but it may not. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would need to modfy the config accordingly if you did that. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 14:01:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462894#M292275</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-03-05T14:01:48Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462895#M292276</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jon , One more thing , in the first solution I need to put the trunk port config on 3750 right ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gi0/0 connects to Firewall &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;int gi0/0 &amp;lt;-- this connect to the firewall&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;no switchport&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;switchport mode trunk aloowed all &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;is that right ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;regards&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;Amit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 14:25:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462895#M292276</guid>
      <dc:creator>amit bhatnagar</dc:creator>
      <dc:date>2014-03-05T14:25:32Z</dc:date>
    </item>
    <item>
      <title>Re: layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462896#M292277</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amit &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No it is not a trunk unless you want to route both vlans off the firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you do then the configuration needs changing but you said you wanted to route vlan 20 on the 3750. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 14:27:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462896#M292277</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-03-05T14:27:37Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462897#M292278</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thats right want to keep vlan 20 layer 3 on 3750 . &lt;/P&gt;&lt;P&gt;So below is the only configration i need to do on 3750 on port which connects to firewall ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;int gi0/0 &amp;lt;-- this connect to the firewall&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;no switchport&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Amit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 14:43:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462897#M292278</guid>
      <dc:creator>amit bhatnagar</dc:creator>
      <dc:date>2014-03-05T14:43:53Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462898#M292279</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amit &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It depends on whether you are routing vlan 10 on the firewall or not. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You wouldn't do "no switchport" if you are routing vlan 10 on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please be specific in what you want as it keeps changing and it's not clear what you want.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 14:46:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462898#M292279</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-03-05T14:46:41Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462899#M292280</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Apology for confusion and taking your time , &lt;/P&gt;&lt;P&gt;Just wanted to know with below config which was prepaired for first time what configration i need to give on interface gi0/0 which connects to firewall please thanks &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;----------------------------------------------------&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;1) enable ip routing if it isn't already ie. -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;switch(config)# ip routing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;2) create both vlans at L2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;switch(config)# vlan 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;switch(config)# vlan 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;3) create L3 SVIs for both vlans eg.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;int vlan 10&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;ip address 172.16.20.x 255.255.255.0&amp;nbsp;&amp;nbsp; &amp;lt;-- where x is unused IP&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;int vlan 20&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;ip address 10.10.10.1 255.255.255.0 &lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;4) add a default route pointing to the firewall -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;ip route 0.0.0.0 0.0.0.0 172.16.20.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;then on the firewall you need to add a route for vlan 20 if it is ASA it would look like -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;route inside 10.10.10.0 255.255.255.0 &lt;L3 vlan="" 10="" interface="" ip="" on="" 3750=""&gt;&lt;/L3&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;the default gateway for clients in vlan 10 is still the firewall. The vlan 10 SVI on the 3750 is only used to route to and from vlan 20 clients.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; ------------------------------&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 15:16:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462899#M292280</guid>
      <dc:creator>amit bhatnagar</dc:creator>
      <dc:date>2014-03-05T15:16:06Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462900#M292281</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Amit &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The gi0/0 interface should be in vlan 10 ie. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int gi0/0&lt;/P&gt;&lt;P&gt;switchport &lt;/P&gt;&lt;P&gt;switchport mode access&lt;/P&gt;&lt;P&gt;switchport access vlan 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 15:18:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462900#M292281</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-03-05T15:18:46Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462901#M292282</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks allot Jon&amp;nbsp; appreciate your time &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;amit&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 15:20:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462901#M292282</guid>
      <dc:creator>amit bhatnagar</dc:creator>
      <dc:date>2014-03-05T15:20:52Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462902#M292283</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like amit may be looking for config which is simialr to RoA,. Instead of router they have got firewall here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amit, you may need to use the belwo cinfig on your switch and needto check with your FW team on the config at their end.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface Ethernet1/1&lt;/P&gt;&lt;P&gt; description ** Trunk, to FW Inside interface**&lt;/P&gt;&lt;P&gt; switchport trunk encapsulation dot1q&lt;/P&gt;&lt;P&gt; switchport trunk allowed vlan 10,20&lt;/P&gt;&lt;P&gt; switchport mode trunk&lt;/P&gt;&lt;P&gt; speed 100&lt;/P&gt;&lt;P&gt; duplex full&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip default-gateway 172.16.20.1 or ip route 0.0.0.0 0.0.0.0 172.16.20.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on Firewall end &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And they need to have L3 SVI interface cretaed , config to be checkd with FW team as it may&amp;nbsp; chnage according to vendor.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int e1/1.10&amp;nbsp; --&amp;gt; &lt;/P&gt;&lt;P&gt;encap dot1q 10&lt;/P&gt;&lt;P&gt;ip add 172.16.20.1/24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int e 1/1.20&lt;/P&gt;&lt;P&gt;encap dot1q 20&lt;/P&gt;&lt;P&gt;ip add 10.10.10.1/24 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the above config routing of VLAN's will happen at forewall.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;Hope this hleps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 15:55:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462902#M292283</guid>
      <dc:creator>srprasaad_nj</dc:creator>
      <dc:date>2014-03-05T15:55:16Z</dc:date>
    </item>
    <item>
      <title>Re: layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462903#M292284</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;EM&gt;vlan 10 with subnet 172.16.20.0/24&amp;nbsp; gateway ip address is 172.16.20.1 which is on firewall which is connected to uplink port eth 1/1 on 3750&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;vlan 20 10.10.10.0/24&amp;nbsp; with gateway 10.10.10.1 on this 3750 switch &lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;If you look at the above from the original post it clearly states that vlan 20 should be routed on the L3 switch. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 15:59:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462903#M292284</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2014-03-05T15:59:02Z</dc:date>
    </item>
    <item>
      <title>layer 2 layer 3 vlan  cisco 3750</title>
      <link>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462904#M292285</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Then it hsould work in theb elwo way &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; vlan 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 20&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; list-style-type: none; border-collapse: collapse; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;create L3 SVIs for both vlans &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; list-style-type: none; border-collapse: collapse; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;int vlan 10&lt;/P&gt;&lt;P style="background-color: #f7fafb; list-style-type: none; border-collapse: collapse; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;ip address 172.16.20.x254255.255.255.0&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; list-style-type: none; border-collapse: collapse; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;int vlan 20&lt;/P&gt;&lt;P style="background-color: #f7fafb; list-style-type: none; border-collapse: collapse; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;ip address 10.10.10.1 255.255.255.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; list-style-type: none; border-collapse: collapse; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;ip route 0.0.0.0 0.0.0.0 172.16.20.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; list-style-type: none; border-collapse: collapse; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;If firewall is connected to G0/0 then&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; list-style-type: none; border-collapse: collapse; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;int g 0/0&lt;/P&gt;&lt;P style="background-color: #f7fafb; list-style-type: none; border-collapse: collapse; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;switchport&lt;/P&gt;&lt;P style="background-color: #f7fafb; list-style-type: none; border-collapse: collapse; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;switchport mode access&lt;/P&gt;&lt;P style="background-color: #f7fafb; list-style-type: none; border-collapse: collapse; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;switchport access vlan 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; list-style-type: none; border-collapse: collapse; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;This should work for amit as he has got all vlan 10 pc's with DG as firewall and VLAN 20 Pc's wiill have routign in L3 switch itself. &lt;/P&gt;&lt;P style="background-color: #f7fafb; list-style-type: none; border-collapse: collapse; font-family: Arial, verdana, sans-serif; font-size: 12px;"&gt;Any inter vlan routing between vlan 10 and vlan 20 will happen within L3 switch itself. Corretc me if I am wrong.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Mar 2014 16:15:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/switching/layer-2-layer-3-vlan-cisco-3750/m-p/2462904#M292285</guid>
      <dc:creator>srprasaad_nj</dc:creator>
      <dc:date>2014-03-05T16:15:02Z</dc:date>
    </item>
  </channel>
</rss>

