cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1642
Views
0
Helpful
3
Replies

How does vlan work on routers

Fartingdragon
Level 1
Level 1

Layer 3 devices, I'm unsure how it treats vlans? I got an edge router which has a wan address on the interface of vlan 3 i.e 50.50.50.1. It's connected to the ASA as a secondary wan interface giving that interface another static wan 50.50.50.2 ip address. If I create a sub interface with a different vlan 13. would the sub interface wan with it's own static wan of 50.50.50.3 have trouble reaching out on the internet? The layer 3 device has static ips setting the default route to the isp.

3 Replies 3

Hello,

 If you create another interface vlan on the router, you can not assign ip address 50.50.50.3. The router must refuse saying to you that you already have 50.50.50.1 on Vlan3.

 I know you are using examples but just to let you know that you need to use different network for different interfaces or interface vlans.

And yes, both vlan will be able to access the interface as long as you have routes on the router send the vlan traffic to the gateway. In case you have NAT you also need to have NAT on both  interfaces vlans.

Sorry I was not clear. This router is on the edge, it set default routes to the ISP. It is mainly used almost like a switch, talking to the isp's edge gear. This router has ip address of i.e. 50.50.50.1 and has vlan 3. It sets default routes to the ISP. On the wan side of the FW, is set ip 50.50.50.2 without any vlan. I want to create a sub interface of that same WAN, and assign it static ip 50.50.50.3 with vlan 100 to dedicate for a s2s vpn. Will it have trouble? 

 

image.png

Hello


@Fartingdragon wrote:

 This router has ip address of i.e. 50.50.50.1 and has vlan 3.

On the wan side of the FW, is set ip 50.50.50.2 without any vlan.

I want to create a sub interface of that same WAN, and assign it static ip 50.50.50.3 with vlan 100 to dedicate for a s2s vpn. Will it have trouble? 

 


You wont be able to do this, all 3 ip addresses reside in the same network range within the global route table (GRT)as such the rtr will complain as when you try to add 50.50.50.3, although the sub-interface is applicable but you will need to use a different ip address.


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul