01-11-2021 06:04 AM
Hi Team,
Need your help on this.
I have configured Router 2951 with sub-ip on GigabitEthernet0/1 for multiple vlans and switch WS-C3750X-48P-L with trunk port and multiple vlans. I can able to access the internet on the default vlan 1(192.168.2.0), but no internet access in other vlans.
Also I couldn't ping the ip assigned to desktop from switch or router from same subnet.
Example - ping 192.168.5.6 source 192.168.5.1 - from router is not pingable.
Switch - config
Current configuration : 6808 bytes ! ! Last configuration change at 17:03:33 UTC Mon Jan 2 2006 ! version 15.0 no service pad service timestamps debug datetime msec service timestamps log datetime msec no service password-encryption ! hostname ! boot-start-marker boot-end-marker ! enable secret 5 enable password ! username no aaa new-model switch 1 provision ws-c3750x-48p system mtu routing 1500 ! ! ip domain-name ! ! cts server deadtime 0 no cts server test all enable cts server test all idle-time 0 cts server test all deadtime 0 ! ! ! spanning-tree mode pvst spanning-tree extend system-id ! ! ! ! ! ! vlan internal allocation policy ascending ! ! ! ! ! ! interface FastEthernet0 no ip address no ip route-cache shutdown ! interface GigabitEthernet1/0/1 switchport trunk encapsulation dot1q switchport mode trunk ! interface GigabitEthernet1/0/2 ! interface GigabitEthernet1/0/3 ! interface GigabitEthernet1/0/4 ! interface GigabitEthernet1/0/5 ! interface GigabitEthernet1/0/6 ! interface GigabitEthernet1/0/7 ! interface GigabitEthernet1/0/8 ! interface GigabitEthernet1/0/9 switchport access vlan 10 switchport mode access ! interface GigabitEthernet1/0/10 switchport access vlan 10 switchport mode access ! interface GigabitEthernet1/0/11 switchport access vlan 10 switchport mode access ! interface GigabitEthernet1/0/12 switchport access vlan 10 switchport mode access ! interface GigabitEthernet1/0/13 switchport access vlan 10 switchport mode access ! interface GigabitEthernet1/0/14 switchport access vlan 10 switchport mode access ! interface GigabitEthernet1/0/15 switchport access vlan 10 switchport mode access ! interface GigabitEthernet1/0/16 switchport access vlan 10 switchport mode access ! interface GigabitEthernet1/0/17 switchport access vlan 10 switchport mode access ! interface GigabitEthernet1/0/18 switchport access vlan 10 switchport mode access ! interface GigabitEthernet1/0/19 switchport access vlan 20 switchport mode access ! interface GigabitEthernet1/0/20 switchport access vlan 20 switchport mode access ! interface GigabitEthernet1/0/21 switchport access vlan 20 switchport mode access ! interface GigabitEthernet1/0/22 switchport access vlan 20 switchport mode access ! interface GigabitEthernet1/0/23 switchport access vlan 20 switchport mode access ! interface GigabitEthernet1/0/24 switchport access vlan 20 switchport mode access ! interface GigabitEthernet1/0/25 switchport access vlan 20 switchport mode access ! interface GigabitEthernet1/0/26 switchport access vlan 20 switchport mode access ! interface GigabitEthernet1/0/27 switchport access vlan 20 switchport mode access ! interface GigabitEthernet1/0/28 switchport access vlan 20 switchport mode access ! interface GigabitEthernet1/0/29 switchport access vlan 20 switchport mode access ! interface GigabitEthernet1/0/30 switchport access vlan 20 switchport mode access ! interface GigabitEthernet1/0/31 switchport access vlan 30 switchport mode access ! interface GigabitEthernet1/0/32 switchport access vlan 30 switchport mode access ! interface GigabitEthernet1/0/33 switchport access vlan 30 switchport mode access ! interface GigabitEthernet1/0/34 switchport access vlan 30 switchport mode access ! interface GigabitEthernet1/0/35 switchport access vlan 30 switchport mode access ! interface GigabitEthernet1/0/36 switchport access vlan 30 switchport mode access ! interface GigabitEthernet1/0/37 switchport access vlan 30 switchport mode access ! interface GigabitEthernet1/0/38 switchport access vlan 30 switchport mode access ! interface GigabitEthernet1/0/39 switchport access vlan 30 switchport mode access ! interface GigabitEthernet1/0/40 switchport access vlan 30 switchport access vlan 30 switchport mode access ! interface GigabitEthernet1/0/41 switchport access vlan 40 switchport mode access ! interface GigabitEthernet1/0/42 switchport access vlan 40 switchport mode access ! interface GigabitEthernet1/0/43 switchport access vlan 40 switchport mode access ! interface GigabitEthernet1/0/44 switchport access vlan 40 switchport mode access ! interface GigabitEthernet1/0/45 switchport access vlan 40 switchport mode access ! interface GigabitEthernet1/0/46 switchport access vlan 40 switchport mode access ! interface GigabitEthernet1/0/47 switchport access vlan 40 switchport mode access ! interface GigabitEthernet1/0/48 switchport access vlan 40 switchport mode access ! interface GigabitEthernet1/1/1 ! interface GigabitEthernet1/1/2 ! interface GigabitEthernet1/1/3 ! interface GigabitEthernet1/1/4 ! interface TenGigabitEthernet1/1/1 ! interface TenGigabitEthernet1/1/2 ! interface Vlan1 ip address 192.168.2.2 255.255.255.0 no ip route-cache ! interface Vlan10 no ip address no ip route-cache ! interface Vlan20 no ip address no ip route-cache ! interface Vlan30 ip address dhcp no ip route-cache ! interface Vlan40 ip address dhcp no ip route-cache ! ip http server ip http secure-server ! ! line con 0 logging synchronous login local line vty 0 4 password login local transport input ssh line vty 5 15 password login ! end
Router Config :
Current configuration : 3618 bytes ! ! Last configuration change at 12:42:04 UTC Mon Jan 11 2021 by admin ! version 15.1 service timestamps debug datetime msec service timestamps log datetime msec service password-encryption ! hostname ! boot-start-marker boot-end-marker ! ! enable secret enable password ! no aaa new-model ! ! crypto pki token default removal timeout 0 ! ! no ipv6 cef ip source-route ip cef ! ! ! ip dhcp excluded-address 192.168.3.1 192.168.3.5 ip dhcp excluded-address 192.168.3.255 ip dhcp excluded-address 192.168.4.1 192.168.4.5 ip dhcp excluded-address 192.168.4.255 ip dhcp excluded-address 192.168.5.1 192.168.5.5 ip dhcp excluded-address 192.168.5.255 ip dhcp excluded-address 192.168.6.1 192.168.6.5 ip dhcp excluded-address 192.168.6.255 ! ip dhcp pool mainuser network 192.168.2.0 255.255.255.0 default-router 192.168.2.1 dns-server 8.8.8.8 ! ip dhcp pool vlan10 network 192.168.3.0 255.255.255.0 default-router 192.168.3.1 dns-server 8.8.8.8 ! ip dhcp pool vlan20 network 192.168.4.0 255.255.255.0 default-router 192.168.4.1 dns-server 8.8.8.8 ! ip dhcp pool vlan30 network 192.168.5.0 255.255.255.0 default-router 192.168.5.1 dns-server 8.8.8.8 ! ip dhcp pool vlan40 network 192.168.6.0 255.255.255.0 default-router 192.168.6.1 dns-server 8.8.8.8 ! ! ip domain name ! multilink bundle-name authenticated ! ! license udi pid CISCO2951/K9 sn ! ! username username ! redundancy ! ! ! ! ! ! ! ! ! ! ! interface GigabitEthernet0/0 ip address 192.168.1.2 255.255.255.0 ip nat outside ip virtual-reassembly in duplex auto speed auto no mop enabled ! interface GigabitEthernet0/1 ip address 192.168.2.1 255.255.255.0 ip nat inside ip virtual-reassembly in duplex auto speed auto ! interface GigabitEthernet0/1.10 description vlan10_subinterface encapsulation dot1Q 10 ip address 192.168.3.1 255.255.255.0 ip nat inside ip virtual-reassembly in ! interface GigabitEthernet0/1.20 description vlan20_subinterface encapsulation dot1Q 20 ip address 192.168.4.1 255.255.255.0 ip nat inside ip virtual-reassembly in ! interface GigabitEthernet0/1.30 description vlan30_subinterface encapsulation dot1Q 30 ip address 192.168.5.1 255.255.255.0 ip nat inside ip virtual-reassembly in ! interface GigabitEthernet0/1.40 description vlan30_subinterface encapsulation dot1Q 40 ip address 192.168.6.1 255.255.255.0 ip nat inside ip virtual-reassembly in ! interface GigabitEthernet0/2 no ip address shutdown duplex auto speed auto ! ! router eigrp 10 network 192.168.2.0 network 192.168.3.0 network 192.168.4.0 network 192.168.5.0 network 192.168.6.0 ! ip default-gateway 192.168.1.254 ip forward-protocol nd ! no ip http server no ip http secure-server ! ip nat inside source list 1 interface GigabitEthernet0/0 overload ip route 0.0.0.0 0.0.0.0 192.168.1.254 ip route 192.168.3.0 255.255.255.0 192.168.2.2 ip route 192.168.4.0 255.255.255.0 192.168.2.2 ip route 192.168.5.0 255.255.255.0 192.168.1.254 ip route 192.168.5.0 255.255.255.0 192.168.2.2 ip route 192.168.6.0 255.255.255.0 192.168.2.2 ! access-list 1 permit any access-list 1 permit 192.168.5.0 0.0.0.255 access-list 1 permit 192.168.3.0 0.0.0.255 access-list 1 permit 192.168.4.0 0.0.0.255 access-list 1 permit 192.168.6.0 0.0.0.255 ! ! ! ! ! ! control-plane ! ! ! line con 0 line aux 0 line vty 0 4 password login local transport input ssh ! scheduler allocate 20000 1000 end
01-11-2021 06:26 AM
Router make sure parent interface dont have any config, if you looking dot1q to work
here is example :
01-11-2021 06:59 AM
Hello,
make the changes marked in bold:
Switch
Current configuration : 6808 bytes
!
! Last configuration change at 17:03:33 UTC Mon Jan 2 2006
!
version 15.0
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname
!
boot-start-marker
boot-end-marker
!
enable secret 5
enable password
!
username
no aaa new-model
switch 1 provision ws-c3750x-48p
system mtu routing 1500
!
ip domain-name
!
cts server deadtime 0
no cts server test all enable
cts server test all idle-time 0
cts server test all deadtime 0
!
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
interface FastEthernet0
no ip address
no ip route-cache
shutdown
!
interface GigabitEthernet1/0/1
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface GigabitEthernet1/0/2
!
interface GigabitEthernet1/0/3
!
interface GigabitEthernet1/0/4
!
interface GigabitEthernet1/0/5
!
interface GigabitEthernet1/0/6
!
interface GigabitEthernet1/0/7
!
interface GigabitEthernet1/0/8
!
interface GigabitEthernet1/0/9
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/10
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/11
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/12
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/13
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/14
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/15
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/16
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/17
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/18
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/19
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/20
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/21
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/22
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/23
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/24
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/25
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/26
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/27
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/28
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/29
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/30
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/31
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/32
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/33
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/34
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/35
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/36
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/37
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/38
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/39
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/40
switchport access vlan 30
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/41
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/0/42
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/0/43
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/0/44
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/0/45
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/0/46
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/0/47
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/0/48
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/1/1
!
interface GigabitEthernet1/1/2
!
interface GigabitEthernet1/1/3
!
interface GigabitEthernet1/1/4
!
interface TenGigabitEthernet1/1/1
!
interface TenGigabitEthernet1/1/2
!
interface Vlan1
ip address 192.168.2.2 255.255.255.0
no ip route-cache
!
--> ip default-gateway 192.168.2.1
!
--> no interface Vlan10
no ip address
no ip route-cache
!
--> no interface Vlan20
no ip address
no ip route-cache
!
-> no interface Vlan30
ip address dhcp
no ip route-cache
!
--> no interface Vlan40
ip address dhcp
no ip route-cache
!
ip http server
ip http secure-server
!
line con 0
logging synchronous
login local
line vty 0 4
password
login local
transport input ssh
line vty 5 15
password
login
!
end
Router
Current configuration : 3618 bytes
!
! Last configuration change at 12:42:04 UTC Mon Jan 11 2021 by admin
!
version 15.1
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname
!
boot-start-marker
boot-end-marker
!
!
enable secret
enable password
!
no aaa new-model
!
!
crypto pki token default removal timeout 0
!
!
no ipv6 cef
ip source-route
ip cef
!
ip dhcp excluded-address 192.168.3.1 192.168.3.5
ip dhcp excluded-address 192.168.3.255
ip dhcp excluded-address 192.168.4.1 192.168.4.5
ip dhcp excluded-address 192.168.4.255
ip dhcp excluded-address 192.168.5.1 192.168.5.5
ip dhcp excluded-address 192.168.5.255
ip dhcp excluded-address 192.168.6.1 192.168.6.5
ip dhcp excluded-address 192.168.6.255
!
ip dhcp pool mainuser
network 192.168.2.0 255.255.255.0
default-router 192.168.2.1
dns-server 8.8.8.8
!
ip dhcp pool vlan10
network 192.168.3.0 255.255.255.0
default-router 192.168.3.1
dns-server 8.8.8.8
!
ip dhcp pool vlan20
network 192.168.4.0 255.255.255.0
default-router 192.168.4.1
dns-server 8.8.8.8
!
ip dhcp pool vlan30
network 192.168.5.0 255.255.255.0
default-router 192.168.5.1
dns-server 8.8.8.8
!
ip dhcp pool vlan40
network 192.168.6.0 255.255.255.0
default-router 192.168.6.1
dns-server 8.8.8.8
!
ip domain name
!
multilink bundle-name authenticated
!
license udi pid CISCO2951/K9 sn
!
username
username
!
redundancy
!
interface GigabitEthernet0/0
ip address 192.168.1.2 255.255.255.0
ip nat outside
ip virtual-reassembly in
duplex auto
speed auto
no mop enabled
!
interface GigabitEthernet0/1
ip address 192.168.2.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
duplex auto
speed auto
!
interface GigabitEthernet0/1.10
description vlan10_subinterface
encapsulation dot1Q 10
ip address 192.168.3.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
!
interface GigabitEthernet0/1.20
description vlan20_subinterface
encapsulation dot1Q 20
ip address 192.168.4.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
!
interface GigabitEthernet0/1.30
description vlan30_subinterface
encapsulation dot1Q 30
ip address 192.168.5.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
!
interface GigabitEthernet0/1.40
description vlan30_subinterface
encapsulation dot1Q 40
ip address 192.168.6.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
!
interface GigabitEthernet0/2
no ip address
shutdown
duplex auto
speed auto
!
router eigrp 10
network 192.168.2.0
network 192.168.3.0
network 192.168.4.0
network 192.168.5.0
network 192.168.6.0
!
--> no ip default-gateway 192.168.1.254
ip forward-protocol nd
!
no ip http server
no ip http secure-server
!
ip nat inside source list 1 interface GigabitEthernet0/0 overload
ip route 0.0.0.0 0.0.0.0 192.168.1.254
--> no ip route 192.168.3.0 255.255.255.0 192.168.2.2
--> no ip route 192.168.4.0 255.255.255.0 192.168.2.2
--> no ip route 192.168.5.0 255.255.255.0 192.168.1.254
--> no ip route 192.168.5.0 255.255.255.0 192.168.2.2
--> no ip route 192.168.6.0 255.255.255.0 192.168.2.2
!
--> no access-list 1 permit any
access-list 1 permit 192.168.5.0 0.0.0.255
access-list 1 permit 192.168.3.0 0.0.0.255
access-list 1 permit 192.168.4.0 0.0.0.255
access-list 1 permit 192.168.6.0 0.0.0.255
!
control-plane
!
line con 0
line aux 0
line vty 0 4
password
login local
transport input ssh
!
scheduler allocate 20000 1000
end
01-11-2021 08:50 AM
I agree with the changes that @Georg Pauwen suggests. Be careful about this one
--> no access-list 1 permit any
It is likely that the result of this command is that all of the access list will be removed and not just the single line. You man need to manually add the other lines back into the config.
It might be helpful in understanding the issue if you would post the output of these commands on the switch
show interface trunk
show interface status
and of these commands on the router
show ip interface brief
show arp
01-11-2021 04:08 PM - edited 01-11-2021 04:12 PM
Hello
Can you try the following and test again:
switch
no ip routng
interface Vlan1
ip route-cache
ip default-gateway 192.168.2.1
no interface Vlan10
no interface Vlan20
no interface Vlan30
no interface Vlan40
vlan 10,20,30,40
exit
Rtr1
no ip route 192.168.3.0 255.255.255.0 192.168.2.2
no ip route 192.168.4.0 255.255.255.0 192.168.2.2
no ip route 192.168.5.0 255.255.255.0 192.168.1.254
no ip route 192.168.5.0 255.255.255.0 192.168.2.2
no ip route 192.168.6.0 255.255.255.0 192.168.2.2
no access-list 1 permit any
no ip source-route
no router eigrp 10
no ip route 0.0.0.0 0.0.0.0 192.168.1.254
access-list 1 permit 192.168.2.0 0.0.0.255
access-list 1 permit 192.168.3.0 0.0.0.255
access-list 1 permit 192.168.4.0 0.0.0.255
access-list 1 permit 192.168.5.0 0.0.0.255
access-list 1 permit 192.168.6.0 0.0.0.255
ip nat inside source list 1 interface GigabitEthernet0/0 overload
ip route 0.0.0.0 0.0.0.0 GigabitEthernet0/0 192.168.1.254
01-11-2021 09:55 AM
ip address 192.168.2.1 255.255.255.0<- this IP assign to main interface, please add sub interface and assign this ip to it instead assign ip to main interface.
01-11-2021 10:09 AM
Just a remark: untagged traffic for Vlan 1 typically actually DOES go on the physical interface.
In this case, this is also the only traffic that DOES work, so it is definitely no misconfiguration.
01-12-2021 09:56 AM
You are right @Georg Pauwen It works fine. Sorry for the confusion.
01-11-2021 10:19 AM - edited 01-12-2021 09:58 AM
as I can see there is two L3 connect to each other,
SW have SVI for native VLAN only and it connect to L3 route-port and hence the connection is OK
SW have not SVI for other VLAN and hence the connection to internet is failed ?
only
NO ip routing in SW solve this,
and also make sub-interface for active to check.
01-11-2021 10:55 AM
Where do you see IP routing enabled on the switch ? Interface GigabitEthernet1/0/1 is trunked to the router for a router-on-a-stick setup. The switch does not do any routing.
01-12-2021 09:51 AM
Thanks Everyone for your reply and time
I will do the best practices said above. Once again thanks everyone for your valuable time
Thanks
Suriya
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide