cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
818
Views
0
Helpful
7
Replies
gcoates66744
Beginner

inter-vlan routing

I have a customer that has two vlans setup on their idf switches (vlan 10, 20).

 

on the core switch they all come in on multiple fiber trunks set for vlans (1, 10, 20)

 

ports 1/0/1-8 are access ports on vlan 10

ports 2/0/1-8 are acess ports on vlan 20

 

now they want to be able to have cross traffic from ports 1-8 vlan 10 to talk to devices on vlan 20, and ports 1-8 vlan 20 to talk to devices on vlan 10. 

 

can someone explain to me how to do this. (I'm pretty new at this but it makes no sense to me since it would be easier to get rid of the vlans since in doing this they seem to have no purpose).

 

i was told to setup vlan int on both vlans with ip addresses to use as gateways and the IP routing would take care of the rest, but I can't seem to make that work. 

 

help, the more I go into this the more confusing it is getting.

Thanks for any help.

7 REPLIES 7
Jon Marshall
VIP Community Legend

 

Assuming your core switch is L3 capable then depending on the model you may need to enable routing ie. 

 

ip routing 

 

then - 

 

vlan 10 = 192.168.3.0/24
vlan 20 = 192.168.4.0/24

 

int vlan 10
ip address 192.168.3.1 255.255.255.0
no shut

 

int vlan 20
ip address 192.168.4.1 255.255.255.0
no shut

 

clients in vlan 10 have a default gateway of 192.168.3.1 and clients in vlan 20 a gateway of 192.168.4.1. 

 

Jon

Thanks john, i do have it programmed something like that (see updated post below), however it still doesn't work.
do I need to do anything else with IP routing? the core switch is a stacked 3850-24s and has layer 3 capability.

thanks for any info.
Joseph W. Doherty
Hall of Fame Expert

Whether you tried to go to using one VLAN, or to continue to use two, IP addressing on hosts in important.

Jon provides a great example of how your core switch might be configured and how the hosts PC need a gateway IP defined that corresponds to a SVI (switch virtual interface) on the core switch.
gcoates66744
Beginner

just to clarify;

 

my core switch has trunk ports. all trunk ports have vlan 1,10,20 on them.

 

also on my core switch I have ports gi1/0/1-8 as access ports on vlan 10

int vlan 10 ip address is 192.168.151.254.255.255.254.0

 

also on my core switch i have ports gi2/0/1-8 as access ports on vlan 20

int vlan 20 ip address is 192.168.152.254 255.255.254.0

 

ip routing has been enabled.

 

i set up access ports; 

gi3/0/1 access port on vlan 10

gi3/0/2 access port on vlan 20

 

my laptop is setup for testing as;

192.168.152.253

255.255.254.0

192.168.152.254

 

i can ping the gateway for vlan 20 (152.254) and one of my ip cameras on the same vlan (152.100)

i cannot ping the gateway for vlan 10 (151.254) or any of my cams on vlan 10.

 

what am I missing?

 

thanks again for your input.

Hello,

 

post the full running configuration of the layer 3 switch...

Here it is;

Core-Switch-2.1.1#show run
Building configuration...

Current configuration : 13960 bytes
!
! Last configuration change at 17:54:54 UTC Fri Mar 6 2020 by admin
!
version 16.6
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service unsupported-transceiver
no platform punt-keepalive disable-kernel-core
!
hostname Core-Switch-2.1.1
!
!
vrf definition Mgmt-vrf
!
address-family ipv4
exit-address-family
!
address-family ipv6
exit-address-family
!
enable secret 5 $1$kara$2Y0IkDApm7WCi87l41vXA/
enable password mustang1
!
no aaa new-model
switch 1 provision ws-c3850-24s
switch 2 provision ws-c3850-24s
switch 3 provision ws-c3850-24s
software auto-upgrade enable
!
!
!
!
!
ip routing
!
no ip domain lookup
ip domain name JCI.net
!
!
!
!
!
!
!
!
!
!
!
crypto pki trustpoint TP-self-signed-2528316547
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-2528316547
revocation-check none
rsakeypair TP-self-signed-2528316547
!
!
crypto pki certificate chain TP-self-signed-2528316547
certificate self-signed 01
30820330 30820218 A0030201 02020101 300D0609 2A864886 F70D0101 05050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 32353238 33313635 3437301E 170D3139 31323137 31373537
35375A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D32 35323833
31363534 37308201 22300D06 092A8648 86F70D01 01010500 0382010F 00308201
0A028201 01009FBC 697D468D A9E91DF7 2436A35F 6270AB58 65406977 E856B8E3
7B476A04 B9DEA9B4 FD493F0D 1BD0E573 9F3CAED4 27BCD38E 9E33A031 1A0788E9
C19AA40A 1ED83F67 1A9CBBED E2DDAE19 81A10925 AD05981B 019B5301 A856E61D
7784AD28 56CE993C 333FB577 11AAF710 1D8C0B82 EC610B86 5C64ECFE F140D6AA
A02CDD47 B53CC9A2 8BDCA650 DE1712E0 C165F9BE D6531DFF A98824EE 211EEDF1
2DFBB280 C1E265B3 1120658E 8C8E23DF E3A2BCB0 B747266B 60FDC076 6F0F64D7
EB1873BC 99233D61 B51777A6 691D68FE 380B8998 034DE7A4 7ADB8DB9 7C44B2F9
E8AD093F 23DB6E3D AA159E36 8F797A62 FF9E7B16 44E122A6 67F11D8A A7C94781
6B012D21 3A3B0203 010001A3 53305130 0F060355 1D130101 FF040530 030101FF
301F0603 551D2304 18301680 140E1F86 1891A58D 9C53BAA1 1096330E 5AAD3778
28301D06 03551D0E 04160414 0E1F8618 91A58D9C 53BAA110 96330E5A AD377828
300D0609 2A864886 F70D0101 05050003 82010100 23355FF6 28A0FE14 5E0EE8B7
577060B9 F572D309 9C77A0EF 37EB9AC9 88AEDC87 6F84D5D5 D7CC0F1C 68B34DE6
1FE59DB5 B403D4D4 93A00F32 8FB6EEA9 4B97B1BB FCC04DFA CBCCE7E2 0CAAC193
97C3C2B7 21C1CCB4 8C46ED14 9E72EAC9 89BBDADF B0D7AB1B A4AE3A15 9FA04147
EC5982CA ED2BC0C1 51478633 22E3BD78 C96B1776 C6FCA9E9 AF84BEDF BD6E291F
E35D192B AC879E93 682126B8 86511F6C 3F0DDE9B F0A5E0AC 108A0126 8210B50D
1621BD82 1F1AB0CB 3DC57C8E 4BCBC58C 2CC3989C CDCEB3C4 908B32D6 58641EAC
513425EF 3C137AAB 9E8AB456 F662E1D4 1904F59A 888ED449 5D03DE24 5B62CE02
8B3794DC BB3D5A4B EABFEDCF 1FFCE576 D50435AF
quit
!
!
!
diagnostic bootup level minimal
spanning-tree mode rapid-pvst
spanning-tree portfast default
spanning-tree extend system-id
no errdisable detect cause gbic-invalid
!
username admin privilege 15 password 0 cisco
!
redundancy
mode sso
!
!
transceiver type all
monitoring
lldp run
!
!
class-map match-any system-cpp-police-topology-control
description Topology control
class-map match-any system-cpp-police-sw-forward
description Sw forwarding, L2 LVX data, LOGGING
class-map match-any system-cpp-default
description DHCP Snooping, EWLC control, EWCL data
class-map match-any system-cpp-police-sys-data
description Learning cache ovfl, Crypto Control, Exception, EGR Exception, NFL SAMPLED DATA, RPF Failed
class-map match-any system-cpp-police-punt-webauth
description Punt Webauth
class-map match-any system-cpp-police-l2lvx-control
description L2 LVX control packets
class-map match-any system-cpp-police-forus
description Forus Address resolution and Forus traffic
class-map match-any system-cpp-police-multicast-end-station
description MCAST END STATION
class-map match-any system-cpp-police-multicast
description Transit Traffic and MCAST Data
class-map match-any system-cpp-police-l2-control
description L2 control
class-map match-any system-cpp-police-dot1x-auth
description DOT1X Auth
class-map match-any system-cpp-police-data
description ICMP redirect, ICMP_GEN and BROADCAST
class-map match-any system-cpp-police-stackwise-virt-control
description Stackwise Virtual
class-map match-any non-client-nrt-class
class-map match-any system-cpp-police-routing-control
description Routing control
class-map match-any system-cpp-police-protocol-snooping
description Protocol snooping
class-map match-any system-cpp-police-system-critical
description System Critical and Gold
!
policy-map system-cpp-policy
!
!
!
!
!
!
!
!
!
!
!
!
!
!
interface GigabitEthernet0/0
vrf forwarding Mgmt-vrf
ip address 192.168.1.254 255.255.255.0
shutdown
speed 1000
negotiation auto
spanning-tree portfast disable
!
interface GigabitEthernet1/0/1
switchport access vlan 20
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet1/0/2
switchport access vlan 20
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet1/0/3
switchport access vlan 20
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet1/0/4
switchport access vlan 20
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet1/0/5
switchport access vlan 20
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet1/0/6
switchport access vlan 20
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet1/0/7
switchport access vlan 20
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet1/0/8
switchport access vlan 20
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet1/0/9
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/0/10
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/0/11
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/0/12
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/0/13
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/0/14
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/0/15
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/0/16
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/0/17
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/0/18
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/0/19
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/0/20
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/0/21
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/0/22
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/0/23
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/0/24
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/1/1
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet1/1/2
!
interface GigabitEthernet1/1/3
!
interface GigabitEthernet1/1/4
!
interface TenGigabitEthernet1/1/1
!
interface TenGigabitEthernet1/1/2
switchport mode trunk
spanning-tree portfast disable
!
interface TenGigabitEthernet1/1/3
switchport mode trunk
spanning-tree portfast disable
!
interface TenGigabitEthernet1/1/4
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/1
switchport access vlan 10
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet2/0/2
switchport access vlan 10
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet2/0/3
switchport access vlan 10
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet2/0/4
switchport access vlan 10
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet2/0/5
switchport access vlan 10
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet2/0/6
switchport access vlan 10
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet2/0/7
switchport access vlan 10
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet2/0/8
switchport access vlan 10
switchport mode access
spanning-tree portfast disable
!
interface GigabitEthernet2/0/9
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/10
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/11
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/12
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/13
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/14
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/15
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/16
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/17
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/18
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/19
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/20
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/21
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/22
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/23
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/0/24
switchport trunk allowed vlan 1,10,20
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/1/1
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/1/2
switchport mode trunk
spanning-tree portfast disable
!
interface GigabitEthernet2/1/3
!
interface GigabitEthernet2/1/4
!
interface TenGigabitEthernet2/1/1
!
interface TenGigabitEthernet2/1/2
!
interface TenGigabitEthernet2/1/3
!
interface TenGigabitEthernet2/1/4
!
interface GigabitEthernet3/0/1
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet3/0/2
switchport access vlan 20
switchport trunk allowed vlan 1,10,20
switchport mode trunk
!
interface GigabitEthernet3/0/3
!
interface GigabitEthernet3/0/4
!
interface GigabitEthernet3/0/5
!
interface GigabitEthernet3/0/6
!
interface GigabitEthernet3/0/7
!
interface GigabitEthernet3/0/8
!
interface GigabitEthernet3/0/9
switchport mode trunk
!
interface GigabitEthernet3/0/10
switchport mode trunk
!
interface GigabitEthernet3/0/11
switchport mode trunk
!
interface GigabitEthernet3/0/12
switchport mode trunk
!
interface GigabitEthernet3/0/13
switchport mode trunk
!
interface GigabitEthernet3/0/14
switchport mode trunk
!
interface GigabitEthernet3/0/15
switchport mode trunk
!
interface GigabitEthernet3/0/16
switchport mode trunk
!
interface GigabitEthernet3/0/17
switchport mode trunk
!
interface GigabitEthernet3/0/18
switchport mode trunk
!
interface GigabitEthernet3/0/19
switchport mode trunk
!
interface GigabitEthernet3/0/20
switchport mode trunk
!
interface GigabitEthernet3/0/21
switchport mode trunk
!
interface GigabitEthernet3/0/22
switchport mode trunk
!
interface GigabitEthernet3/0/23
switchport mode trunk
!
interface GigabitEthernet3/0/24
switchport mode trunk
!
interface GigabitEthernet3/1/1
!
interface GigabitEthernet3/1/2
!
interface GigabitEthernet3/1/3
!
interface GigabitEthernet3/1/4
!
interface TenGigabitEthernet3/1/1
!
interface TenGigabitEthernet3/1/2
!
interface TenGigabitEthernet3/1/3
!
interface TenGigabitEthernet3/1/4
!
interface Vlan1
ip address 192.168.1.254 255.255.255.0
!
interface Vlan10
ip address 192.168.151.254 255.255.254.0
!
interface Vlan20
ip address 192.168.152.254 255.255.254.0
!
ip forward-protocol nd
ip http server
ip http authentication local
ip http secure-server
ip ssh version 2
!
!
!
!
!
!
control-plane
service-policy input system-cpp-policy
!
!
line con 0
logging synchronous
login local
stopbits 1
line aux 0
stopbits 1
line vty 0 4
access-class 1 in vrf-also
exec-timeout 50 0
password mustang2
login local
length 0
transport input ssh
line vty 5 15
password mustang2
login
!
!
mac address-table notification mac-move
!
!
!
!
!

Thanks for posting the config. Based on this I would expect that devices in vlan 10 and vlan 20 should be able to communicate and am surprised that they do not. Can you tell us which switch port your computer is connected to and post the output of these commands

show interface status

show ip route

show ip interface brief

HTH

Rick