Showing results for 
Search instead for 
Did you mean: 

Routing Between VLANS on Layer 3 Switch

Community Manager
Community Manager

Good morning everyone!

I have "one" Cisco Layer 3 Catalyst 2960-X Series Switch for backbone and "two" Cisco Layer 2 Business 220 Series Switches as the access switch.

I am working with 3 different VLANs: VLAN-1, VLAN-2, and VLAN-100.

However, when I configure the switch interface in VLAN-2 or VLAN-100, and the end device in these two bands, I do not have access to the internet. I wonder how I would create a routing for all VLANS/lanes to have internet access.

VLAN-1 -

VLAN-2 -

VLAN-100 -

Note: I have a pfSense as the default gateway ( I don't know if you can influence anything.

Thank you in advance.

4 Replies 4

Hall of Fame
Hall of Fame

Make sure VLAN is allowed in the Trunk going from the core switch to the access switch

on Pfsense you need to add the new IP address to NAT for the internet to work. also from pfsense you need a static route back for that IP address towards vlan 100 IP configured on Core switch


***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Level 3
Level 3


I think more information is needed about your configuration to give you some advice. pfSense and a L3 switch can be configured in a couple of ways.

Kris K

I assume the PfSence rtr/fw will be performing Nat for subnet

So what you need to do is to append the nat policy on that rtr/fw to accommodate the two other vlans you have created on the switch (vlan 2 &100)

Then add two static routes for those subnets pointing to the switches vlan 1 interface On the switch enable ip routing and add a default route pointing to the pfSence rtr/fw

Example Sw:
ip routing
ip route vlan 1 192.168.1.X name pfsence_nexthop

Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards

The static route for VLAN-1 was created by following this command: "ip route 0.0.0 vlan 1 name pfSense".

For VLAN-2 and VLAN-100 this would be:

"ip route vlan 100 name pfSense".

"ip route vlan 2 name pfSense".


Review Cisco Networking for a $25 gift card