04-03-2023 03:10 PM - edited 04-03-2023 04:49 PM
Layer 3 devices, I'm unsure how it treats vlans? I got an edge router which has a wan address on the interface of vlan 3 i.e 50.50.50.1. It's connected to the ASA as a secondary wan interface giving that interface another static wan 50.50.50.2 ip address. If I create a sub interface with a different vlan 13. would the sub interface wan with it's own static wan of 50.50.50.3 have trouble reaching out on the internet? The layer 3 device has static ips setting the default route to the isp.
04-03-2023 03:31 PM
Hello,
If you create another interface vlan on the router, you can not assign ip address 50.50.50.3. The router must refuse saying to you that you already have 50.50.50.1 on Vlan3.
I know you are using examples but just to let you know that you need to use different network for different interfaces or interface vlans.
And yes, both vlan will be able to access the interface as long as you have routes on the router send the vlan traffic to the gateway. In case you have NAT you also need to have NAT on both interfaces vlans.
04-03-2023 04:37 PM - edited 04-03-2023 04:49 PM
Sorry I was not clear. This router is on the edge, it set default routes to the ISP. It is mainly used almost like a switch, talking to the isp's edge gear. This router has ip address of i.e. 50.50.50.1 and has vlan 3. It sets default routes to the ISP. On the wan side of the FW, is set ip 50.50.50.2 without any vlan. I want to create a sub interface of that same WAN, and assign it static ip 50.50.50.3 with vlan 100 to dedicate for a s2s vpn. Will it have trouble?
04-04-2023 12:18 AM
Hello
@Fartingdragon wrote:
This router has ip address of i.e. 50.50.50.1 and has vlan 3.
On the wan side of the FW, is set ip 50.50.50.2 without any vlan.
I want to create a sub interface of that same WAN, and assign it static ip 50.50.50.3 with vlan 100 to dedicate for a s2s vpn. Will it have trouble?
You wont be able to do this, all 3 ip addresses reside in the same network range within the global route table (GRT)as such the rtr will complain as when you try to add 50.50.50.3, although the sub-interface is applicable but you will need to use a different ip address.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide