07-08-2004 06:07 PM - edited 03-02-2019 04:57 PM
i have below config in the 3550
vlan 2
10.x.x.x
vlan 3
20.x.x.x
0.0.0.0 0.0.0.0 20.x.x.1
30.x.x.x 255.255.255.0 10.x.x.1
behind 10.x.x.1 router there is a user ip segment 30.x.x.x and they need to reach networks behind 20.x.x.x
the users in 30.x.x.x cannot reach the networks behind 20.x.x.x . the trace stops at the router
what is missing? btw is it possible to ?
07-08-2004 06:07 PM
What are the default gateways of the 30.x.x.x user PCs or do they have a more specific route to get to 20.x.x.x ?
Does the 10.x.x.1 router have a route for 20.x.x.x pointing to the 3550 VLAN 2 interface? I'm under asumption the 30.x.x.x users default gateway/route is the 10.x.x.1 routers interface for the 30.x.x.x network.
What is the VLAN 2 IP address on the 3550?
Have you tried running a routing protocol?
07-12-2004 10:09 PM
It looks your router doesnt have a route to 20.X.X.X .define a route for the 20.X.X.X network in your router via the 10.0.0.2 .
07-15-2004 06:07 PM
vlan 2
10.x.x.2
vlan 3
20.x.x.2
i have route from 10.x.x.1 (fw) point to 10.x.x.2 for the 20.x.x.x network.
I have not tried a routing protocol.
but the above should do the job ?
Any suggestions? or is it anything to do with the IOS ?
07-15-2004 07:57 PM
Hi,
you can get this to work without a routing protocol, if you ensure that:
- hosts on the 30.x.x.x network have a default route pointing towards 30.x.x.1
- firewall 30.x.x.1 has a route for 20.x.x.0 via 10.1.1.2
- ip routing is enabled on the 3550
- hosts on the 20.x.x.x network have a route to 30.x.x.x
The latter can be accomplished in a few different ways. If the host you're trying to reach from 30.x.x.x is on the same segment as the VLAN3 interface (i.e. in the 20.x.x.x range), then that host's default gatweway should point to 20.x.x.2.
If the hosts you're trying to reach from 30.x.x.x is behind 20.x.x.1, then you'll need to make sure that that host's default gateway points to the ip addres of (presumably) the firewall.
Finally, you'll have to make sure that the firewall's policies permit traffic between these networks.
Maybe you could show us a traceroute and some more debug info, if this doesn't help?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide