cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1797
Views
35
Helpful
10
Replies

No internet access other than default vlan.

suriya7
Level 1
Level 1

Hi Team, 


Need your help on this. 

 

I have configured Router 2951 with sub-ip on GigabitEthernet0/1 for multiple vlans and switch WS-C3750X-48P-L with trunk port and multiple vlans. I can able to access the internet on the default vlan 1(192.168.2.0), but no internet access in other vlans. 

Also I couldn't ping the ip assigned to desktop from switch or router from same subnet.

Example - ping 192.168.5.6 source 192.168.5.1 - from router is not pingable. 



Switch - config

Current configuration : 6808 bytes
!
! Last configuration change at 17:03:33 UTC Mon Jan 2 2006 
!
version 15.0
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname
!
boot-start-marker
boot-end-marker
!
enable secret 5 
enable password 
!
username 
no aaa new-model
switch 1 provision ws-c3750x-48p
system mtu routing 1500
!
!
ip domain-name 
!
!

cts server deadtime 0
no cts server test all enable
cts server test all idle-time 0
cts server test all deadtime 0
!
!
!
spanning-tree mode pvst
spanning-tree extend system-id
!
!
!
!
!
!
vlan internal allocation policy ascending
!
!
!
!
!
!
interface FastEthernet0
 no ip address
 no ip route-cache
 shutdown
!
interface GigabitEthernet1/0/1
 switchport trunk encapsulation dot1q
 switchport mode trunk
!
interface GigabitEthernet1/0/2
!
interface GigabitEthernet1/0/3
!
interface GigabitEthernet1/0/4
!
interface GigabitEthernet1/0/5
!
interface GigabitEthernet1/0/6
!
interface GigabitEthernet1/0/7
!
interface GigabitEthernet1/0/8
!
interface GigabitEthernet1/0/9
 switchport access vlan 10
 switchport mode access
!
interface GigabitEthernet1/0/10
 switchport access vlan 10
 switchport mode access
!
interface GigabitEthernet1/0/11
 switchport access vlan 10
 switchport mode access
!
interface GigabitEthernet1/0/12
 switchport access vlan 10
 switchport mode access
!
interface GigabitEthernet1/0/13
 switchport access vlan 10
 switchport mode access
!
interface GigabitEthernet1/0/14
 switchport access vlan 10
 switchport mode access
!
interface GigabitEthernet1/0/15
 switchport access vlan 10
 switchport mode access
!
interface GigabitEthernet1/0/16
 switchport access vlan 10
 switchport mode access
!
interface GigabitEthernet1/0/17
 switchport access vlan 10
 switchport mode access
!
interface GigabitEthernet1/0/18
 switchport access vlan 10
 switchport mode access
!
interface GigabitEthernet1/0/19
 switchport access vlan 20
 switchport mode access
!
interface GigabitEthernet1/0/20
 switchport access vlan 20
 switchport mode access
!
interface GigabitEthernet1/0/21
 switchport access vlan 20
 switchport mode access
!
interface GigabitEthernet1/0/22
 switchport access vlan 20
 switchport mode access
!
interface GigabitEthernet1/0/23
 switchport access vlan 20
 switchport mode access
!
interface GigabitEthernet1/0/24
 switchport access vlan 20
 switchport mode access
!
interface GigabitEthernet1/0/25
 switchport access vlan 20
 switchport mode access
!
interface GigabitEthernet1/0/26
 switchport access vlan 20
 switchport mode access
!
interface GigabitEthernet1/0/27
 switchport access vlan 20
 switchport mode access
!
interface GigabitEthernet1/0/28
 switchport access vlan 20
 switchport mode access
!
interface GigabitEthernet1/0/29
 switchport access vlan 20
 switchport mode access
!
interface GigabitEthernet1/0/30
 switchport access vlan 20
 switchport mode access
!
interface GigabitEthernet1/0/31
 switchport access vlan 30
 switchport mode access
!
interface GigabitEthernet1/0/32
 switchport access vlan 30
 switchport mode access
!
interface GigabitEthernet1/0/33
 switchport access vlan 30
 switchport mode access
!
interface GigabitEthernet1/0/34
 switchport access vlan 30
 switchport mode access
!
interface GigabitEthernet1/0/35
 switchport access vlan 30
 switchport mode access
!
interface GigabitEthernet1/0/36
 switchport access vlan 30
 switchport mode access
!
interface GigabitEthernet1/0/37
 switchport access vlan 30
 switchport mode access
!
interface GigabitEthernet1/0/38
 switchport access vlan 30
 switchport mode access
!
interface GigabitEthernet1/0/39
 switchport access vlan 30
 switchport mode access
!
interface GigabitEthernet1/0/40
 switchport access vlan 30

 switchport access vlan 30
 switchport mode access
!
interface GigabitEthernet1/0/41
 switchport access vlan 40
 switchport mode access
!
interface GigabitEthernet1/0/42
 switchport access vlan 40
 switchport mode access
!
interface GigabitEthernet1/0/43
 switchport access vlan 40
 switchport mode access
!
interface GigabitEthernet1/0/44
 switchport access vlan 40
 switchport mode access
!
interface GigabitEthernet1/0/45
 switchport access vlan 40
 switchport mode access
!
interface GigabitEthernet1/0/46
 switchport access vlan 40
 switchport mode access
!
interface GigabitEthernet1/0/47
 switchport access vlan 40
 switchport mode access
!
interface GigabitEthernet1/0/48
 switchport access vlan 40
 switchport mode access
!
interface GigabitEthernet1/1/1
!
interface GigabitEthernet1/1/2
!
interface GigabitEthernet1/1/3
!
interface GigabitEthernet1/1/4
!
interface TenGigabitEthernet1/1/1
!
interface TenGigabitEthernet1/1/2
!
interface Vlan1
 ip address 192.168.2.2 255.255.255.0
 no ip route-cache
!
interface Vlan10
 no ip address
 no ip route-cache
!
interface Vlan20
 no ip address
 no ip route-cache
!
interface Vlan30
 ip address dhcp
 no ip route-cache
!
interface Vlan40
 ip address dhcp
 no ip route-cache
!
ip http server
ip http secure-server
!
!
line con 0
 logging synchronous
 login local
line vty 0 4
 password 
 login local
 transport input ssh
line vty 5 15
 password 
 login
!
end


Router Config :

Current configuration : 3618 bytes
!
! Last configuration change at 12:42:04 UTC Mon Jan 11 2021 by admin
!
version 15.1
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname 
!
boot-start-marker
boot-end-marker
!
!
enable secret 
enable password 
!
no aaa new-model
!
!
crypto pki token default removal timeout 0
!
!
no ipv6 cef
ip source-route
ip cef
!
!
!
ip dhcp excluded-address 192.168.3.1 192.168.3.5
ip dhcp excluded-address 192.168.3.255
ip dhcp excluded-address 192.168.4.1 192.168.4.5
ip dhcp excluded-address 192.168.4.255
ip dhcp excluded-address 192.168.5.1 192.168.5.5
ip dhcp excluded-address 192.168.5.255
ip dhcp excluded-address 192.168.6.1 192.168.6.5
ip dhcp excluded-address 192.168.6.255
!
ip dhcp pool mainuser
   network 192.168.2.0 255.255.255.0
   default-router 192.168.2.1
   dns-server 8.8.8.8
!
ip dhcp pool vlan10
   network 192.168.3.0 255.255.255.0
   default-router 192.168.3.1
   dns-server 8.8.8.8
!
ip dhcp pool vlan20
   network 192.168.4.0 255.255.255.0
   default-router 192.168.4.1
   dns-server 8.8.8.8
!
ip dhcp pool vlan30
   network 192.168.5.0 255.255.255.0
   default-router 192.168.5.1
   dns-server 8.8.8.8
!
ip dhcp pool vlan40
   network 192.168.6.0 255.255.255.0
   default-router 192.168.6.1
   dns-server 8.8.8.8
!
!
ip domain name 
!
multilink bundle-name authenticated
!
!
license udi pid CISCO2951/K9 sn 
!
!
username 
username 
!
redundancy
!
!
!
!
!
!
!
!
!
!
!
interface GigabitEthernet0/0
 ip address 192.168.1.2 255.255.255.0
 ip nat outside
 ip virtual-reassembly in
 duplex auto
 speed auto
 no mop enabled
!
interface GigabitEthernet0/1
 ip address 192.168.2.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly in
 duplex auto
 speed auto
!
interface GigabitEthernet0/1.10
 description vlan10_subinterface
 encapsulation dot1Q 10
 ip address 192.168.3.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly in
!
interface GigabitEthernet0/1.20
 description vlan20_subinterface
 encapsulation dot1Q 20
 ip address 192.168.4.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly in
!
interface GigabitEthernet0/1.30
 description vlan30_subinterface
 encapsulation dot1Q 30
 ip address 192.168.5.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly in
!
interface GigabitEthernet0/1.40
 description vlan30_subinterface
 encapsulation dot1Q 40
 ip address 192.168.6.1 255.255.255.0
 ip nat inside
 ip virtual-reassembly in
!
interface GigabitEthernet0/2
 no ip address
 shutdown
 duplex auto
 speed auto
!
!
router eigrp 10
 network 192.168.2.0
 network 192.168.3.0
 network 192.168.4.0
 network 192.168.5.0
 network 192.168.6.0
!
ip default-gateway 192.168.1.254
ip forward-protocol nd
!
no ip http server
no ip http secure-server
!
ip nat inside source list 1 interface GigabitEthernet0/0 overload
ip route 0.0.0.0 0.0.0.0 192.168.1.254
ip route 192.168.3.0 255.255.255.0 192.168.2.2
ip route 192.168.4.0 255.255.255.0 192.168.2.2
ip route 192.168.5.0 255.255.255.0 192.168.1.254
ip route 192.168.5.0 255.255.255.0 192.168.2.2
ip route 192.168.6.0 255.255.255.0 192.168.2.2
!
access-list 1 permit any
access-list 1 permit 192.168.5.0 0.0.0.255
access-list 1 permit 192.168.3.0 0.0.0.255
access-list 1 permit 192.168.4.0 0.0.0.255
access-list 1 permit 192.168.6.0 0.0.0.255
!
!
!
!
!
!
control-plane
!
!
!
line con 0
line aux 0
line vty 0 4
 password 
 login local
 transport input ssh
!
scheduler allocate 20000 1000
end


Screenshot 2021-01-11 at 7.29.20 PM.png


 

10 Replies 10

balaji.bandi
Hall of Fame
Hall of Fame

Router make sure parent interface dont have any config, if you looking dot1q to work

 

here is example :

 

http://www.firewall.cx/cisco-technical-knowledgebase/cisco-routers/336-cisco-router-8021q-router-stick.html

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hello,

 

make the changes marked in bold:

 

Switch

 

Current configuration : 6808 bytes
!
! Last configuration change at 17:03:33 UTC Mon Jan 2 2006
!
version 15.0
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname
!
boot-start-marker
boot-end-marker
!
enable secret 5
enable password
!
username
no aaa new-model
switch 1 provision ws-c3750x-48p
system mtu routing 1500
!
ip domain-name
!
cts server deadtime 0
no cts server test all enable
cts server test all idle-time 0
cts server test all deadtime 0
!
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
interface FastEthernet0
no ip address
no ip route-cache
shutdown
!
interface GigabitEthernet1/0/1
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface GigabitEthernet1/0/2
!
interface GigabitEthernet1/0/3
!
interface GigabitEthernet1/0/4
!
interface GigabitEthernet1/0/5
!
interface GigabitEthernet1/0/6
!
interface GigabitEthernet1/0/7
!
interface GigabitEthernet1/0/8
!
interface GigabitEthernet1/0/9
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/10
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/11
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/12
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/13
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/14
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/15
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/16
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/17
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/18
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/0/19
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/20
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/21
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/22
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/23
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/24
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/25
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/26
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/27
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/28
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/29
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/30
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/31
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/32
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/33
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/34
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/35
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/36
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/37
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/38
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/39
switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/40
switchport access vlan 30

switchport access vlan 30
switchport mode access
!
interface GigabitEthernet1/0/41
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/0/42
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/0/43
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/0/44
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/0/45
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/0/46
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/0/47
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/0/48
switchport access vlan 40
switchport mode access
!
interface GigabitEthernet1/1/1
!
interface GigabitEthernet1/1/2
!
interface GigabitEthernet1/1/3
!
interface GigabitEthernet1/1/4
!
interface TenGigabitEthernet1/1/1
!
interface TenGigabitEthernet1/1/2
!
interface Vlan1
ip address 192.168.2.2 255.255.255.0
no ip route-cache
!
--> ip default-gateway 192.168.2.1
!
--> no interface Vlan10
no ip address
no ip route-cache
!
--> no interface Vlan20
no ip address
no ip route-cache
!
-> no interface Vlan30
ip address dhcp
no ip route-cache
!
--> no interface Vlan40
ip address dhcp
no ip route-cache
!
ip http server
ip http secure-server
!
line con 0
logging synchronous
login local
line vty 0 4
password
login local
transport input ssh
line vty 5 15
password
login
!
end

 

Router

 

Current configuration : 3618 bytes
!
! Last configuration change at 12:42:04 UTC Mon Jan 11 2021 by admin
!
version 15.1
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname
!
boot-start-marker
boot-end-marker
!
!
enable secret
enable password
!
no aaa new-model
!
!
crypto pki token default removal timeout 0
!
!
no ipv6 cef
ip source-route
ip cef
!
ip dhcp excluded-address 192.168.3.1 192.168.3.5
ip dhcp excluded-address 192.168.3.255
ip dhcp excluded-address 192.168.4.1 192.168.4.5
ip dhcp excluded-address 192.168.4.255
ip dhcp excluded-address 192.168.5.1 192.168.5.5
ip dhcp excluded-address 192.168.5.255
ip dhcp excluded-address 192.168.6.1 192.168.6.5
ip dhcp excluded-address 192.168.6.255
!
ip dhcp pool mainuser
network 192.168.2.0 255.255.255.0
default-router 192.168.2.1
dns-server 8.8.8.8
!
ip dhcp pool vlan10
network 192.168.3.0 255.255.255.0
default-router 192.168.3.1
dns-server 8.8.8.8
!
ip dhcp pool vlan20
network 192.168.4.0 255.255.255.0
default-router 192.168.4.1
dns-server 8.8.8.8
!
ip dhcp pool vlan30
network 192.168.5.0 255.255.255.0
default-router 192.168.5.1
dns-server 8.8.8.8
!
ip dhcp pool vlan40
network 192.168.6.0 255.255.255.0
default-router 192.168.6.1
dns-server 8.8.8.8
!
ip domain name
!
multilink bundle-name authenticated
!
license udi pid CISCO2951/K9 sn
!
username
username
!
redundancy
!
interface GigabitEthernet0/0
ip address 192.168.1.2 255.255.255.0
ip nat outside
ip virtual-reassembly in
duplex auto
speed auto
no mop enabled
!
interface GigabitEthernet0/1
ip address 192.168.2.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
duplex auto
speed auto
!
interface GigabitEthernet0/1.10
description vlan10_subinterface
encapsulation dot1Q 10
ip address 192.168.3.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
!
interface GigabitEthernet0/1.20
description vlan20_subinterface
encapsulation dot1Q 20
ip address 192.168.4.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
!
interface GigabitEthernet0/1.30
description vlan30_subinterface
encapsulation dot1Q 30
ip address 192.168.5.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
!
interface GigabitEthernet0/1.40
description vlan30_subinterface
encapsulation dot1Q 40
ip address 192.168.6.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
!
interface GigabitEthernet0/2
no ip address
shutdown
duplex auto
speed auto
!
router eigrp 10
network 192.168.2.0
network 192.168.3.0
network 192.168.4.0
network 192.168.5.0
network 192.168.6.0
!
--> no ip default-gateway 192.168.1.254
ip forward-protocol nd
!
no ip http server
no ip http secure-server
!
ip nat inside source list 1 interface GigabitEthernet0/0 overload
ip route 0.0.0.0 0.0.0.0 192.168.1.254
--> no ip route 192.168.3.0 255.255.255.0 192.168.2.2
--> no ip route 192.168.4.0 255.255.255.0 192.168.2.2
--> no ip route 192.168.5.0 255.255.255.0 192.168.1.254
--> no ip route 192.168.5.0 255.255.255.0 192.168.2.2
--> no ip route 192.168.6.0 255.255.255.0 192.168.2.2
!
--> no access-list 1 permit any
access-list 1 permit 192.168.5.0 0.0.0.255
access-list 1 permit 192.168.3.0 0.0.0.255
access-list 1 permit 192.168.4.0 0.0.0.255
access-list 1 permit 192.168.6.0 0.0.0.255
!
control-plane
!
line con 0
line aux 0
line vty 0 4
password
login local
transport input ssh
!
scheduler allocate 20000 1000
end

I agree with the changes that @Georg Pauwen suggests. Be careful about this one

--> no access-list 1 permit any

It is likely that the result of this command is that all of the access list will be removed and not just the single line. You man need to manually add the other lines back into the config.

 

It might be helpful in understanding the issue if you would post the output of these commands on the switch

show interface trunk

show interface status

and of these commands on the router

show ip interface brief

show arp

HTH

Rick

Hello
Can you try the following and test again:

switch
no ip routng

interface Vlan1
ip route-cache
ip default-gateway 192.168.2.1

no interface Vlan10
no interface Vlan20
no interface Vlan30
no interface Vlan40

vlan 10,20,30,40
exit

 

Rtr1
no ip route 192.168.3.0 255.255.255.0 192.168.2.2
no ip route 192.168.4.0 255.255.255.0 192.168.2.2
no ip route 192.168.5.0 255.255.255.0 192.168.1.254
no ip route 192.168.5.0 255.255.255.0 192.168.2.2
no ip route 192.168.6.0 255.255.255.0 192.168.2.2
no access-list 1 permit any
no ip source-route
no router eigrp 10
no ip route 0.0.0.0 0.0.0.0 192.168.1.254

access-list 1 permit 192.168.2.0 0.0.0.255
access-list 1 permit 192.168.3.0 0.0.0.255
access-list 1 permit 192.168.4.0 0.0.0.255
access-list 1 permit 192.168.5.0 0.0.0.255
access-list 1 permit 192.168.6.0 0.0.0.255

ip nat inside source list 1 interface GigabitEthernet0/0 overload
ip route 0.0.0.0 0.0.0.0 GigabitEthernet0/0 192.168.1.254


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

ip address 192.168.2.1 255.255.255.0<- this IP assign to main interface, please add sub interface and assign this ip to it instead assign ip to main interface.

Just a remark: untagged traffic for Vlan 1 typically actually DOES go on the physical interface. 

 

In this case, this is also the only traffic that DOES work, so it is definitely no misconfiguration.

You are right @Georg Pauwen It works fine. Sorry for the confusion.

as I can see there is two L3 connect to each other,

SW have SVI for native VLAN only and it connect to L3 route-port and hence the connection is OK 
SW have not SVI for other VLAN and hence the connection to internet is failed ?

only 
NO ip routing in SW solve this, 

and also make sub-interface for active to check.

Where do you see IP routing enabled on the switch ? Interface GigabitEthernet1/0/1 is trunked to the router for a router-on-a-stick setup. The switch does not do any routing.

suriya7
Level 1
Level 1

Thanks Everyone for your reply and time   Sorry the above config works perfectly, It was not tested properly, because this setup I did in remote on the other end the person who done testing had some issues with his laptop used to test with other vlans   

I will do the best practices said above. Once again thanks everyone for your valuable time

Thanks
Suriya