<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic i love your explanation, but in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832185#M916063</link>
    <description>&lt;P&gt;i love your explanation, but with all that said, In distant site, is all my routed trafic into vlan 99 going to change its vlan tagging to vlan 99 ?&lt;/P&gt;</description>
    <pubDate>Mon, 07 Dec 2015 14:12:26 GMT</pubDate>
    <dc:creator>Halil.Zakaria</dc:creator>
    <dc:date>2015-12-07T14:12:26Z</dc:date>
    <item>
      <title>L2/3 switch intervlan behaviour</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832171#M916049</link>
      <description>&lt;P&gt;hello what happens in case of a L3 Switch that is capable of routing packets(in presence of a route entry)from an access-port(blongs to Vlan40) to a trunkport(allowed vlan 90).are we allowed to route this packet, if yes, will it keep its vlan tag 40?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:37:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832171#M916049</guid>
      <dc:creator>Halil.Zakaria</dc:creator>
      <dc:date>2020-02-21T13:37:28Z</dc:date>
    </item>
    <item>
      <title>hi you cant route across a</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832172#M916050</link>
      <description>&lt;P&gt;hi you cant route across a trunk its layer 2 , you can encapsulate layer3 packets and switch them accros the trunk at layer 2, either way if tag 40 is not allowed on trunk switch will drop it&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2015 15:15:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832172#M916050</guid>
      <dc:creator>Mark Malone</dc:creator>
      <dc:date>2015-11-27T15:15:04Z</dc:date>
    </item>
    <item>
      <title>but if i have an interface</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832173#M916051</link>
      <description>&lt;P&gt;but if i have an interface vlan 40 configured with ip 192.168.2.2/24, that intercepts&amp;nbsp; frames from switch interface&amp;nbsp; configured with switchport access vlan 40, will theseframes be tagged?&lt;/P&gt;
&lt;P&gt;and&amp;nbsp;&amp;nbsp;with a a trunk port that &amp;nbsp;allows vlan 90 only &amp;nbsp;and there is an interface vlan 90 with ip adress 192.168.1.2/24,and a route entry that routes a destination to&amp;nbsp;&amp;nbsp;a next hop: 192.168.1.3, will my traffic be routed from vlan 40 to 90? if yes will it keep its tag40.&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2015 15:52:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832173#M916051</guid>
      <dc:creator>Halil.Zakaria</dc:creator>
      <dc:date>2015-11-27T15:52:12Z</dc:date>
    </item>
    <item>
      <title>Hello Halil,</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832174#M916052</link>
      <description>&lt;P&gt;Hello Halil,&lt;/P&gt;
&lt;P&gt;For L2 switching to work, if a fram in vlan 40 wants to communicates with same vlan 40 members then it will check the arp table of the switch and local switching will happen.&lt;/P&gt;
&lt;P&gt;and if the host of the same vlan exists on different switch then frame will be tagged with vlan 40 and traverse over trunk port where vlan 40 is allowed to reach other switch for sucessfull communication.&lt;/P&gt;
&lt;P&gt;For L3 routing &amp;amp; switching, Any traffic if it requires for different subnet packet will lad to default gateway which would be L3 SVI and if it is another SVI Vlan then it will be done as intervlan routing by L3 switch for fast switching.&lt;/P&gt;
&lt;P&gt;Hope it Helps..&lt;/P&gt;
&lt;P&gt;-GI&lt;/P&gt;
&lt;P&gt;Rate if it Helps..&lt;/P&gt;</description>
      <pubDate>Fri, 27 Nov 2015 17:34:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832174#M916052</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2015-11-27T17:34:49Z</dc:date>
    </item>
    <item>
      <title>let s say for example in a l3</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832175#M916053</link>
      <description>&lt;P&gt;let s say for example in a l3 switch i configured an interface vlan 10 with an ip adress then i configured a physical switch interface as trunk port and i allowed only vlan 10,if trafic sourced from vlan20 needs to ne routed to an ip nexthop thats in the same network as vlan 10,will it be routed?&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2015 01:13:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832175#M916053</guid>
      <dc:creator>Halil.Zakaria</dc:creator>
      <dc:date>2015-11-28T01:13:54Z</dc:date>
    </item>
    <item>
      <title>let s say for example in a l3</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832176#M916054</link>
      <description>&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;let s say for example in a l3 switch i configured an interface vlan 10 with an ip adress then i configured a physical switch interface as trunk port and i allowed only vlan 10,if trafic sourced from vlan20 needs to ne routed to an ip nexthop thats in the same network as vlan 10,will it be routed?&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;Hello Halil,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Trunk link communiction is to traverse vlans between swithces is happens by&amp;nbsp;VLAN Tagging, also known as Frame Tagging, is to help identify packets travelling through trunk links.&lt;/P&gt;
&lt;P&gt;When an Ethernet frame traverses a trunk link, a special VLAN tag is added to the frame and sent across the trunk link.&lt;/P&gt;
&lt;P align="left"&gt;As it arrives at the end of the trunk link the tag is removed and the frame is sent to the correct access link port according to the switch's table, so that the receiving end is unaware of any VLAN information&lt;/P&gt;
&lt;P align="left"&gt;Could you clarify by what you want to convey by below&amp;nbsp;&lt;/P&gt;
&lt;PRE align="left" class="prettyprint"&gt;&lt;SPAN&gt;if trafic sourced from vlan20 needs to ne routed to an ip nexthop thats in the same network as vlan 10&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;Do you want to convey a traffic is source from vlan 20 for destination vlan 10 which are allowed over trunk then the will it route , Is this your query ? If yes , then what i have explained above for vlan trunking will normally the frame would flow.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope it Helps..&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-GI&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Rate if it Helps..&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 28 Nov 2015 01:55:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832176#M916054</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2015-11-28T01:55:07Z</dc:date>
    </item>
    <item>
      <title>please i have another</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832177#M916055</link>
      <description>&lt;P&gt;please i have another question.&lt;/P&gt;
&lt;P&gt;when an interface vlan 10 is configured,a logical mac adress is associated to it, and when a host connected to switch port (mode acces for vlan 10),and this host wants to send trafic to a destination not in his subnet,it sends framewith destination mac of the interface vlan 10.am i right?&lt;/P&gt;
&lt;P&gt;then according to routing table ,the l3 switch rewrites source mac adress of frame to the exit interface and destination mac adress to mac adress of next hop in routing entry?&lt;/P&gt;</description>
      <pubDate>Sun, 29 Nov 2015 21:30:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832177#M916055</guid>
      <dc:creator>Halil.Zakaria</dc:creator>
      <dc:date>2015-11-29T21:30:19Z</dc:date>
    </item>
    <item>
      <title>please i have another</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832178#M916056</link>
      <description>&lt;PRE class="prettyprint"&gt;please i have another question.when an interface vlan 10 is configured,a logical mac adress is associated to it, and when a host connected to switch port (mode acces for vlan 10),and this host wants to send trafic to a destination not in his subnet,it sends framewith destination mac of the interface vlan 10.am i right?then according to routing table ,the l3 switch rewrites source mac adress of frame to the exit interface and destination mac adress to mac adress of next hop in routing entry?&lt;/PRE&gt;
&lt;P&gt;Hello Halil,&lt;/P&gt;
&lt;P&gt;Yes, You are right. If packet is destined for other subnet not for vlan 10 it will get into gateway for searching of that subnet under routing instance.&lt;/P&gt;
&lt;P&gt;So what happen here is the host in VLAN 10 request to reach to VLAN 20 host.Now see the packet flow,Host in VLAN 10 add the destination ip of the VLAN 20 host address and source ip of the self at Layer 3 in TCP/IP stack.&lt;/P&gt;
&lt;P&gt;As this packet is not in same broadcast domain then it search for gateway mac to send the traffic to gateway which is VLAN 10 by sending arp request for gateway mac.&lt;/P&gt;
&lt;P&gt;Source with host VLAN 10 mac is added and destination is gateway mac of VLAN 10 is added in frame and send to physical layer in ethernet cable to switch port.&lt;/P&gt;
&lt;P&gt;and then switch process the packet based on detination ip address and strip surce and destination mac accordingly.&lt;/P&gt;
&lt;DIV&gt;
&lt;DIV&gt;Please keep in mind that&amp;nbsp;layer 3 or network layer destination IP address never changes through out the path of IP packet, except from cases like NATing or VPN.&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV&gt;
&lt;DIV&gt;Only thing which changes is source and destination MAC addresses at data link layer.&lt;/DIV&gt;
&lt;DIV&gt;&lt;/DIV&gt;
&lt;DIV&gt;Hope it clears your query..&lt;/DIV&gt;
&lt;DIV&gt;&lt;/DIV&gt;
&lt;DIV&gt;-GI&lt;/DIV&gt;
&lt;DIV&gt;&lt;/DIV&gt;
&lt;DIV&gt;Rate if it Helpss&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Mon, 30 Nov 2015 03:36:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832178#M916056</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2015-11-30T03:36:04Z</dc:date>
    </item>
    <item>
      <title>distant site:</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832179#M916057</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;distant site(#L3 switchsite1)&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet0/24&lt;BR /&gt;&amp;nbsp;description&amp;nbsp;MAN&lt;BR /&gt;&amp;nbsp;switchport&lt;BR /&gt;&amp;nbsp;switchport trunk encapsulation dot1q&lt;BR /&gt;&amp;nbsp;switchport trunk allowed vlan 99&lt;BR /&gt;&amp;nbsp;switchport mode trunk&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;interface vlan 99&lt;/P&gt;
&lt;P&gt;description Interco&lt;/P&gt;
&lt;P&gt;ip address 10.0.253.128 255.255.255.0&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;ip route 192.168.1.0 255.255.255.0 10.0.253.129&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Core site:&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet6/31&lt;BR /&gt;&amp;nbsp;description INF_RTR-MAN-NATIONAL&lt;BR /&gt;&amp;nbsp;switchport&lt;BR /&gt;&amp;nbsp;switchport trunk encapsulation dot1q&lt;BR /&gt;&amp;nbsp;switchport trunk allowed vlan 99&lt;BR /&gt;&amp;nbsp;switchport mode trunk&lt;BR /&gt;&amp;nbsp;udld port&lt;BR /&gt;&amp;nbsp;storm-control broadcast level 10.00&lt;BR /&gt;&amp;nbsp;storm-control multicast level 10.00&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;interface GigabitEthernet6/32&lt;BR /&gt;&amp;nbsp;description&amp;nbsp;to a firewall&lt;BR /&gt;&amp;nbsp;switchport&lt;BR /&gt;&amp;nbsp;switchport access vlan 99&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;storm-control broadcast level 10.00&lt;BR /&gt;&amp;nbsp;storm-control multicast level 10.00&lt;BR /&gt;!&lt;/P&gt;
&lt;P&gt;------------&lt;/P&gt;
&lt;P&gt;my question is if i have a packet (in distant site) coming from (#L3 switchsite1)switch interface fas0/20 assigned to vlan 20 and need to be routed to 10.0.253.129.will it be routed,if yes will it keep&amp;nbsp;its vlan tagging 20.And if it keeps it,&amp;nbsp;will it &amp;nbsp;be allowed to cross the trunk.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;in my opinion packets routed to vlan 99 must be tagged 99 so that they are recognized&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;this configuration is working well for moving trafic from routed vlans into transit vlan 99.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;thank you for your time and care&lt;/P&gt;</description>
      <pubDate>Wed, 02 Dec 2015 17:50:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832179#M916057</guid>
      <dc:creator>Halil.Zakaria</dc:creator>
      <dc:date>2015-12-02T17:50:23Z</dc:date>
    </item>
    <item>
      <title>Hello Halil,</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832180#M916058</link>
      <description>&lt;P&gt;Hello Halil,&lt;/P&gt;
&lt;P&gt;Yes this would work.. Let me try to explain.&lt;/P&gt;
&lt;P&gt;Vlan 99 is a transit vlan between distant and core site which is having point to point connection over trunk and running routing.&lt;/P&gt;
&lt;P&gt;So when packet comes from vlan 20 at distant site towards core site ip address 10.0.253.129, it will land on to his gateway at distant site and there would be a arp entry for 10.0.253.129 in distant site switch whcih will responde to vlan 20 host as a part of intervlan routing.&lt;/P&gt;
&lt;P&gt;But if any packet on the subnet required to be reached&amp;nbsp;&lt;SPAN&gt;192.168.1.0 255.255.255.0 which is behind 10.0.253.19 then packet will land on to distant switch van 20 gateway and there would come routing decision to send the packet to core switch ip address without any vlan tag because they are communicating over routing instance between two sites.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Consider in your case trunk is tunnel over which you are running L3 point to point link , which is same as if link router to router connectivity.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Hope it clears your query..&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Happy to help you till you are clear with your concept..:)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-GI&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 03:55:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832180#M916058</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2015-12-03T03:55:15Z</dc:date>
    </item>
    <item>
      <title>But how the core switch knows</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832181#M916059</link>
      <description>&lt;P&gt;But how the core switch trunk interface knows without tagging&amp;nbsp;about packets that&amp;nbsp;belong to vlan 99 and dispatch them to &amp;nbsp;GigabitEthernet6/32(to firewall).&lt;/P&gt;
&lt;P&gt;in core switch,please&amp;nbsp;note &amp;nbsp;that no interface vlan 99 exits in core switch:&lt;/P&gt;
&lt;P&gt;Core switch:&lt;/P&gt;
&lt;P&gt;interface vlan 99&lt;/P&gt;
&lt;P&gt;no ip address&lt;/P&gt;
&lt;P&gt;shutdown&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2015 13:45:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832181#M916059</guid>
      <dc:creator>Halil.Zakaria</dc:creator>
      <dc:date>2015-12-03T13:45:32Z</dc:date>
    </item>
    <item>
      <title>So where is 10.0.253.129 ip</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832182#M916060</link>
      <description>&lt;P&gt;So where is&amp;nbsp;&lt;SPAN&gt;10.0.253.129 ip is configured ???, As distant site is having routing pointing towards this ip .&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;-GI&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 04:43:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832182#M916060</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2015-12-04T04:43:21Z</dc:date>
    </item>
    <item>
      <title>this ip is configured in the</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832183#M916061</link>
      <description>&lt;P&gt;this ip is configured in the interface of the firewall connected to interface GigabitEthernet6/32 of core switch&lt;/P&gt;</description>
      <pubDate>Fri, 04 Dec 2015 08:14:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832183#M916061</guid>
      <dc:creator>Halil.Zakaria</dc:creator>
      <dc:date>2015-12-04T08:14:59Z</dc:date>
    </item>
    <item>
      <title>Halil,</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832184#M916062</link>
      <description>&lt;P&gt;Halil,&lt;/P&gt;
&lt;P&gt;As per your earlier post, you have clearly shown core site is having two interface configuration, which clearly states that vlan 99 is been trunked from distant site and access vlan configured on port whcih is connected to firewall end.&lt;/P&gt;
&lt;P&gt;VLAN interface is not required becasue firewall port is l3 and having vlan in 99 with same subnet which is extended over trunk.&lt;/P&gt;
&lt;PRE class="prettyprint"&gt;Core site:&lt;BR /&gt;interface GigabitEthernet6/31&lt;BR /&gt;&amp;nbsp;description INF_RTR-MAN-NATIONAL&lt;BR /&gt;&amp;nbsp;switchport&lt;BR /&gt;&amp;nbsp;switchport trunk encapsulation dot1q&lt;BR /&gt;&amp;nbsp;switchport trunk allowed vlan 99 -- &lt;STRONG&gt;&lt;SPAN style="color: #ff0000;"&gt;VLAN 99 is been trunked to core site with dot1q encap.&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;switchport mode trunk&lt;BR /&gt;&amp;nbsp;udld port&lt;BR /&gt;&amp;nbsp;storm-control broadcast level 10.00&lt;BR /&gt;&amp;nbsp;storm-control multicast level 10.00&lt;BR /&gt;&lt;BR /&gt;interface GigabitEthernet6/32&lt;BR /&gt;description&amp;nbsp;to a firewall&lt;BR /&gt;&amp;nbsp;switchport&lt;BR /&gt;&amp;nbsp;switchport access vlan 99 --- &lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;VLAN 99 is configred on your core switch&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp;switchport mode access&lt;BR /&gt;&amp;nbsp;storm-control broadcast level 10.00&lt;BR /&gt;&amp;nbsp;storm-control multicast level 10.00&lt;BR /&gt;!&lt;/PRE&gt;
&lt;P&gt;Please re-check your port and come back if any further query you have.&lt;/P&gt;
&lt;P&gt;Do you still having query after seeing your configuration which you have pasted.&lt;/P&gt;
&lt;P&gt;-GI&lt;/P&gt;</description>
      <pubDate>Sat, 05 Dec 2015 06:34:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832184#M916062</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2015-12-05T06:34:45Z</dc:date>
    </item>
    <item>
      <title>i love your explanation, but</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832185#M916063</link>
      <description>&lt;P&gt;i love your explanation, but with all that said, In distant site, is all my routed trafic into vlan 99 going to change its vlan tagging to vlan 99 ?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2015 14:12:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832185#M916063</guid>
      <dc:creator>Halil.Zakaria</dc:creator>
      <dc:date>2015-12-07T14:12:26Z</dc:date>
    </item>
    <item>
      <title>i love your explanation, but</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832186#M916064</link>
      <description>&lt;PRE class="prettyprint"&gt;&lt;SPAN&gt;i love your explanation, but with all that said, In distant site, is all my routed trafic into vlan 99 going to change its vlan tagging to vlan 99 ?&lt;/SPAN&gt;&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN&gt;Hello Halil,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Ok ..Now got that what is your query is ..:)&lt;/P&gt;
&lt;P&gt;Let me try to explain. Taking your example of Access Port VLAN 40 and trunk vlan 99 between switches.&lt;/P&gt;
&lt;P&gt;PC1 ---(Vlan 40 Access VLAN)-- SWA -----(Trunk 99) --- SWB --- (VLAN 99) --Access Port of Firewall.&lt;/P&gt;
&lt;P&gt;When packet leaves from PC NIC it lands on SWA ( Access Port over VLAN 40 ) which is &lt;STRONG&gt;untagged&amp;nbsp;&lt;/STRONG&gt;and you know that switch maintains&amp;nbsp;&lt;STRONG&gt;F&lt;/STRONG&gt;&lt;SPAN&gt;orwarding&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;D&lt;/STRONG&gt;&lt;SPAN&gt;ata&lt;/SPAN&gt;&lt;STRONG&gt;B&lt;/STRONG&gt;&lt;SPAN&gt;ase which&amp;nbsp;comprised of tuples of three elements: (MAC, port, VLAN).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So it has full detail of vlan 40 PC1 mac address and port it is connected with vlan id in FDB of SW1.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So , In order to reach subnet behind vlan 99 traffic lands on VLAN 40 gateway which would SVI configured on SW1 and there happens inter vlan routing to VLAN 99 for destination subnet as per routing configured.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Once it lands on trunk port which encapusalted with 802.1q trunk which means vlan tagging is happening with VLAN 99 and packet reaches at SW B with destination and src ip.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Once Frame lands on SWB over the trunk with &lt;STRONG&gt;tagged&lt;/STRONG&gt; , SW B checks FDB based on MAC which is been identify on packet destination ip. Which would be firewall interface on access port vlan 99 and packet goes to firewall interface &lt;STRONG&gt;untagged.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;I Hope the above explanation would be helpful.&lt;/P&gt;
&lt;P&gt;-GI&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2015 16:45:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832186#M916064</guid>
      <dc:creator>Ganesh Hariharan</dc:creator>
      <dc:date>2015-12-07T16:45:06Z</dc:date>
    </item>
    <item>
      <title>i got the answer i want,</title>
      <link>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832187#M916065</link>
      <description>&lt;P&gt;You cleared my doubts, Thnak you for helping&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2015 11:58:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/l2-3-switch-intervlan-behaviour/m-p/2832187#M916065</guid>
      <dc:creator>Halil.Zakaria</dc:creator>
      <dc:date>2015-12-09T11:58:27Z</dc:date>
    </item>
  </channel>
</rss>

