cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2122
Views
0
Helpful
5
Replies

Cisco switch SG300 vlan configuration problem

Michael Nagy
Level 1
Level 1

Hello,

 

I have SG300 Cisco switch I configured it as Layer 3 switch which I created 3 Vlans

vlan 2: for network 192.168.1.0 its interface 192.168.1.1 for data

vlan 3: for network 192.168.3.0 its interface 192.168.3.1 for wifi

vlan 4: for network 192.168.4.0 its interface 192.168.4.1 for wifi2 

I have Linksys X3500 router its IP 192.168.1.5

I configured  intervlan on switch, default gateway is the router 192.168.1.5 and I configured static route for all subnets (192.168.1.0, 192.168.3.0 and 192.168.4.0) to router 192.168.1.5

I configured the router routes 192.168.3.0 and 192.168.4.0 to interface 192.168.1.1

 

Vlan 2 could access the internet but the other vlan couldn't

 

Kindly support me to find the solution.

 

Thank you.

5 Replies 5

Seb Rupik
VIP Alumni
VIP Alumni

Hi there,

I'd suggest removing the static routes from the SG300. It only requires a default route directing traffic to the  Linksys.

 

If after removing the routes, please post the running config.

 

cheers,

Seb.

Hello,
Kindly Note that the Linksys port is 49

switch237d91#show running-config
config-file-header
switch237d91
v1.4.0.88 / R800_NIK_1_4_194_194
CLI v1.0
set system mode router

file SSD indicator encrypted
@
ssd-control-start
ssd config
ssd file passphrase control unrestricted
no ssd file integrity control
ssd-control-end cb0a3fdb1f3a1af4e4430033719968c0
!
vlan database
vlan 2-4
exit
voice vlan oui-table add 0001e3 Siemens_AG_phone________
voice vlan oui-table add 00036b Cisco_phone_____________
voice vlan oui-table add 00096e Avaya___________________
voice vlan oui-table add 000fe2 H3C_Aolynk______________
voice vlan oui-table add 0060b9 Philips_and_NEC_AG_phone
voice vlan oui-table add 00d01e Pingtel_phone___________
voice vlan oui-table add 00e075 Polycom/Veritel_phone___
voice vlan oui-table add 00e0bb 3Com_phone______________
ip dhcp server
ip dhcp pool network Lan3
address low 192.168.3.11 high 192.168.3.250 255.255.255.0
default-router 192.168.3.1
dns-server 192.168.1.5
exit
bonjour interface range vlan 1
hostname switch237d91
username cisco password encrypted 21eedfdf3772d2a3c05790cab425c09333990510 privilege 15
clock timezone " " +3
ip telnet server
!
interface vlan 1
ip address 192.168.10.1 255.255.255.0
no ip address dhcp
!
interface vlan 2
name MAIN
ip address 192.168.1.1 255.255.255.0
!
interface vlan 3
name WIFI
ip address 192.168.3.1 255.255.255.0
!
interface vlan 4
name WIFI2
ip address 192.168.4.1 255.255.255.0
!
interface gigabitethernet1
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet2
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet3
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet4
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet5
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet6
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet7
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet8
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet9
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet10
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet11
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet12
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet13
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet14
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet15
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet16
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet17
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet18
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet19
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet20
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet21
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet22
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet23
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet24
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet25
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet26
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet27
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet28
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet29
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet30
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet31
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet32
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet33
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet34
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet35
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet36
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet37
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet38
switchport mode general
switchport general allowed vlan add 3-4 tagged
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet39
switchport mode general
switchport general allowed vlan add 3-4 tagged
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet40
switchport mode general
switchport general allowed vlan add 3-4 tagged
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet41
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet42
switchport mode general
switchport general allowed vlan add 3-4 tagged
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet43
switchport mode general
switchport general allowed vlan add 3-4 tagged
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet44
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet45
switchport mode general
switchport general allowed vlan add 3-4 tagged
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet46
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet47
switchport mode general
switchport general allowed vlan add 3-4 tagged
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet48
switchport mode general
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet49
switchport mode general
switchport general allowed vlan add 3-4 tagged
switchport general allowed vlan add 2 untagged
switchport general pvid 2
!
interface gigabitethernet50
storm-control broadcast enable
storm-control broadcast level 10
spanning-tree link-type point-to-point
switchport mode general
switchport general allowed vlan add 3-4 tagged
switchport general allowed vlan add 2 untagged
switchport general pvid 2
macro description router
!next command is internal.
macro auto smartport dynamic_type unknown
!
interface gigabitethernet52
switchport trunk allowed vlan add 2-4
switchport default-vlan tagged
switchport forbidden default-vlan
!
exit
macro auto processing type router enabled
ip default-gateway 192.168.1.5

On the SG300, what is the output of:

sh ip route

sh arp

 

I assume devices on VLAN3 are correctly receiving addresses via DHCP. Are they able to ping the VLAN3 SVI 192.168.3.1 ?

 

cheers,

Seb.

Yes, all devices receive correct addresses via DHCP and they able to ping 192.168.3.1 and the router 192.168.1.5

switch237d91#show ip route
Maximum Parallel Paths: 1 (1 after reset)
IP Forwarding: enabled
Codes: > - best, C - connected, S - static


S 0.0.0.0/0 [1/1] via 192.168.1.5, 21:50:45, vlan 2
C 192.168.1.0/24 is directly connected, vlan 2
C 192.168.3.0/24 is directly connected, vlan 3
C 192.168.4.0/24 is directly connected, vlan 4

switch237d91#show arp

Total number of entries: 77


VLAN Interface IP address HW address status
--------------------- --------------- ------------------- ---------------
vlan 2 gi49 192.168.1.5 c0:56:27:ea:24:7c dynamic
vlan 2 gi43 192.168.1.6 7c:1c:68:dd:93:5a dynamic
vlan 2 gi50 192.168.1.10 78:8a:20:42:ec:3c dynamic
vlan 2 192.168.1.11 90:06:28:a8:75:05 dynamic
vlan 2 gi43 192.168.1.16 7c:1c:68:dd:93:5a dynamic
vlan 2 gi52 192.168.1.25 40:a5:ef:60:51:f1 dynamic
vlan 2 gi39 192.168.1.26 78:8a:20:5c:13:a9 dynamic
vlan 2 gi43 192.168.1.27 78:8a:20:5c:12:49 dynamic
vlan 2 gi35 192.168.1.28 78:8a:20:5c:0b:94 dynamic
vlan 2 gi47 192.168.1.29 f0:9f:c2:6b:36:14 dynamic
vlan 2 gi45 192.168.1.30 78:8a:20:5c:17:3d dynamic
vlan 2 gi43 192.168.1.31 10:92:66:5f:88:93 dynamic
vlan 2 gi43 192.168.1.32 e0:2a:82:e4:e2:3b dynamic
vlan 2 192.168.1.33 90:06:28:a8:75:05 dynamic
vlan 2 gi43 192.168.1.34 90:e7:c4:c7:6f:a6 dynamic
vlan 2 192.168.1.35 50:04:b8:14:1c:c6 dynamic
vlan 2 192.168.1.36 50:04:b8:67:26:9d dynamic
vlan 2 192.168.1.37 50:04:b8:1b:0c:9b dynamic
vlan 2 gi40 192.168.1.38 f0:9f:c2:6b:37:28 dynamic
vlan 2 gi42 192.168.1.39 f0:9f:c2:6b:36:58 dynamic
vlan 2 192.168.1.40 68:64:4b:e5:d5:9b dynamic
vlan 2 192.168.1.41 3c:77:e6:78:90:1b dynamic
vlan 2 192.168.1.42 48:bf:6b:4c:23:a1 dynamic
vlan 2 192.168.1.43 30:07:4d:67:39:1c dynamic
vlan 2 gi43 192.168.1.44 7c:1c:68:dd:93:5a dynamic
vlan 2 192.168.1.47 b0:19:c6:d8:bb:cc dynamic
vlan 2 gi43 192.168.1.56 10:92:66:5f:88:93 dynamic
vlan 2 192.168.1.60 48:4b:aa:3f:a0:7c dynamic
vlan 2 192.168.1.72 50:04:b8:14:53:fd dynamic
vlan 2 192.168.1.76 48:8d:36:1f:82:96 dynamic
vlan 2 192.168.1.78 48:8d:36:1f:72:6a dynamic
vlan 2 192.168.1.79 48:8d:36:1f:84:6e dynamic
vlan 2 192.168.1.103 90:06:28:a8:75:05 dynamic
vlan 2 gi52 192.168.1.104 40:a5:ef:60:60:21 dynamic
vlan 2 gi52 192.168.1.105 40:a5:ef:60:55:61 dynamic
vlan 2 gi52 192.168.1.106 40:a5:ef:60:5b:41 dynamic
vlan 2 gi52 192.168.1.107 40:a5:ef:60:53:d1 dynamic
vlan 2 gi52 192.168.1.108 40:a5:ef:60:51:e1 dynamic
vlan 2 gi52 192.168.1.109 40:a5:ef:60:55:a1 dynamic
vlan 2 gi52 192.168.1.110 40:a5:ef:60:5d:81 dynamic
vlan 2 192.168.1.163 64:31:50:09:97:64 dynamic
vlan 2 gi43 192.168.1.170 e0:2a:82:e4:e2:3b dynamic
vlan 2 gi52 192.168.1.190 e0:07:1b:ff:3b:d9 dynamic
vlan 2 gi25 192.168.1.201 9c:f6:1a:84:95:8d dynamic
vlan 2 gi9 192.168.1.202 9c:f6:1a:84:93:dd dynamic
vlan 2 gi28 192.168.1.203 9c:f6:1a:84:93:fe dynamic
vlan 2 gi8 192.168.1.204 9c:f6:1a:83:ed:79 dynamic
vlan 2 gi31 192.168.1.205 9c:f6:1a:84:93:fd dynamic
vlan 2 gi1 192.168.1.206 9c:f6:1a:83:ed:68 dynamic
vlan 2 gi11 192.168.1.207 9c:f6:1a:83:ed:56 dynamic
vlan 2 gi7 192.168.1.208 9c:f6:1a:83:ed:82 dynamic
vlan 2 gi5 192.168.1.209 9c:f6:1a:84:94:72 dynamic
vlan 2 gi4 192.168.1.210 9c:f6:1a:83:ed:7d dynamic
vlan 2 gi29 192.168.1.211 9c:f6:1a:84:94:94 dynamic
vlan 2 gi22 192.168.1.212 9c:f6:1a:84:93:91 dynamic
vlan 2 gi41 192.168.1.213 9c:f6:1a:84:93:b8 dynamic
vlan 2 gi17 192.168.1.214 9c:f6:1a:83:ed:58 dynamic
vlan 2 gi10 192.168.1.215 9c:f6:1a:83:ed:51 dynamic
vlan 2 gi6 192.168.1.216 9c:f6:1a:83:ed:53 dynamic
vlan 2 gi27 192.168.1.217 9c:f6:1a:84:94:93 dynamic
vlan 2 gi3 192.168.1.218 9c:f6:1a:84:94:b2 dynamic
vlan 2 gi24 192.168.1.219 9c:f6:1a:84:94:2f dynamic
vlan 2 gi16 192.168.1.220 9c:f6:1a:84:93:ab dynamic
vlan 2 gi2 192.168.1.221 9c:f6:1a:84:94:03 dynamic
vlan 2 gi14 192.168.1.222 9c:f6:1a:84:94:b3 dynamic
vlan 2 gi19 192.168.1.223 9c:f6:1a:83:ed:59 dynamic
vlan 2 gi26 192.168.1.224 9c:f6:1a:84:95:ad dynamic
vlan 2 gi38 192.168.1.225 9c:f6:1a:83:ed:3c dynamic
vlan 2 gi32 192.168.1.226 9c:f6:1a:83:ed:46 dynamic
vlan 2 gi30 192.168.1.227 9c:f6:1a:84:93:90 dynamic
vlan 2 gi23 192.168.1.228 9c:f6:1a:83:ed:3a dynamic
vlan 2 gi20 192.168.1.229 9c:f6:1a:83:ed:61 dynamic
vlan 2 gi15 192.168.1.230 9c:f6:1a:83:ed:6e dynamic
vlan 3 gi50 192.168.3.10 78:8a:20:42:ec:3c dynamic
vlan 3 192.168.3.11 e0:2a:82:e4:e2:3b dynamic
vlan 3 192.168.3.14 7c:1c:68:dd:93:5a dynamic

OK, so if your SG300 clients are able to ping 192.168.1.5 then the SG300 config is good.

You should turn your attention to Linksys, in particular its NAT config.

It is possible that it is configured to NAT traffic sourced only from 192.168.1.0/24 . Looking through the configuration guide:

http://downloads.linksys.com/downloads/userguide/X-Series_UG_3425-01613B_Web.pdf

 

...I can't find anything which details NAT setup. It is possible that you will need to NAT your internal VLANs before they reach the linksys....something that the SG300 does not support. You will need to find another device (router/ FW) to place inline.

 

cheers,

Seb.