10-26-2013 04:13 AM - edited 03-04-2019 09:25 PM
hi
I have configured Core switch with different VLANs my VLAN 80 is created for UPLINK connectivity from Firewall (10.50.1.3) I am able to access internet from VLAN 80 access ports but not able to get internet access from other VLAN please check my configuration and give me solution for the same
Current configuration : 5733 bytes
!
version 15.0
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
service compress-config
!
hostname DC_CORE_SW01
!
boot-start-marker
boot-end-marker
!
enable secret 5 $1$ASxr$wV1aOTTf5F94nN.wAscMz/
!
!
!
no aaa new-model
ip subnet-zero
!
--More-- !
ip vrf mgmtVrf
!
vtp mode transparent
!
power redundancy-mode redundant
!
!
!
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
vlan 10
name DMZ_PRODUCTION_VLAN
!
vlan 20
name Management_VLAN
!
vlan 30
name ILOM_VLAN
!
vlan 40
name IPCAM_VLAN
!
vlan 50
name BUR_VLAN
!
vlan 60
name heartbeats_VLAN
!
vlan 70
name AccessCard_VLAN
!
vlan 80
name Connectivity_VLAN
!
vlan 100
name DATA_VLAN
!
vlan 200
name L3_Trunk_To_CoreSw_2
!
!
!
--More-- interface FastEthernet1
ip vrf forwarding mgmtVrf
no ip address
speed auto
duplex auto
!
interface GigabitEthernet1/1
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/2
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/3
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/4
description *******Connected to Dell Servers********
--More-- switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/5
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/6
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/7
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/8
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
--More-- interface GigabitEthernet1/9
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/10
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/11
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/12
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/13
description *******Connected to Dell Servers********
switchport access vlan 10
--More-- switchport mode access
!
interface GigabitEthernet1/14
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/15
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/16
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/17
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/18
--More-- description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/19
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/20
description *******Connected to Dell Servers********
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet1/21
description ************Connected to Management Port*****
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/22
description ************Connected to Management Port*****
switchport access vlan 20
switchport mode access
--More-- !
interface GigabitEthernet1/23
description ************Connected to Management Port*****
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/24
description ************Connected to Management Port*****
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/25
description ************Connected to Management Port*****
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/26
!
interface GigabitEthernet1/27
!
interface GigabitEthernet1/28
!
interface GigabitEthernet1/29
--More-- !
interface GigabitEthernet1/30
!
interface GigabitEthernet1/31
!
interface GigabitEthernet1/32
!
interface GigabitEthernet1/33
!
interface GigabitEthernet1/34
!
interface GigabitEthernet1/35
!
interface GigabitEthernet1/36
!
interface GigabitEthernet1/37
switchport access vlan 80
switchport mode access
!
interface GigabitEthernet1/38
!
interface GigabitEthernet1/39
!
--More-- interface GigabitEthernet1/40
!
interface GigabitEthernet1/41
!
interface GigabitEthernet1/42
!
interface GigabitEthernet1/43
!
interface GigabitEthernet1/44
!
interface GigabitEthernet1/45
!
interface GigabitEthernet1/46
!
interface GigabitEthernet1/47
!
interface GigabitEthernet1/48
description **********UPLINK to UTM-1*********
switchport access vlan 80
switchport mode access
!
interface TenGigabitEthernet1/49
!
interface TenGigabitEthernet1/50
--More-- !
interface TenGigabitEthernet1/51
!
interface TenGigabitEthernet1/52
!
interface Vlan1
no ip address
!
interface Vlan10
ip address 172.16.1.252 255.255.255.0
standby 2 ip 172.16.1.1
standby 2 timers 1 3
standby 2 priority 150
standby 2 preempt
!
interface Vlan80
ip address 10.50.1.8 255.255.255.240
standby 2 ip 10.50.1.10
standby 2 timers 1 3
standby 2 priority 150
standby 2 preempt
!
ip route 0.0.0.0 0.0.0.0 10.50.1.3
no ip http server
!
!
access-list 1 permit any
!
banner motd ^CWelcome Authorized Users Unauthorized access prohibited!^C
!
line con 0
--More-- stopbits 1
line vty 0 4
login
!
end
My Senario is I have two Firewall with two ISPs and have two Core switch Need to Configure HSRP in Switch
thanks
Sreejesh
10-26-2013 04:39 AM
What other vlans are you having issues with?
I see on this switch, you have the following vlans defined.
10,20,30,40,50,60,70,80,100 and 200
The only access ports on this switch that I see, have either VLAN 10 or VLAN 20 defined.
I only see two interface vlans as well
If you run a traceroute to 8.8.8.8 from a machine on a vlan you are having issues with, where does it stop?
Also, what is the IP configuration for one of these machines?
Could be, not having NAT setup, etc etc
10-26-2013 10:00 AM
John
if I am configured Vlan 80 on my pc and connected to ge1/37 I am able to access Internet
from vlan 10 not able to get internet but from VLAN 10 ip configured system I could be able to ping VLAN 10 interface IP and VLAN 80 Interface IP
this is core switch so server and managment port only directly connected to this switch thats why I just assigned 10 and 20 for ports
I on configuration part thats why I didnt configure other VLANs interface ip
NAT is done on my firewall so hope there is no need to configure NAT
10-26-2013 11:02 AM
I would imagine you will have to make changes on the firewall. Utm-1 im assuming is a checkpoint firewall. You have to define the subnets that are reachable on each interface of the firewall other than the default for the internet interface (anti-spoofing). You also have to define which subnets you are going to provide nat for on the checkpoint.
Sent from Cisco Technical Support iPad App
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide