cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
571
Views
5
Helpful
3
Replies

Inter VLAN routing help

MarkFarber61778
Level 1
Level 1

I am trying to get my Sg300-28 to work as L3 and intervlan routing except for VLAN22 which I want isolated. .I think I have this correct as defined below except that VLAN22 is not isolated I only give VLAN22 access to the internet but not the other devices on the network (VLAN1 and VLAN2). When I plug in a device on GE6 22UP (ie VLAN22) it still has access to everything. 

 

2 Questions?????

1. WHAT IS WRONG WITH MY SETUP??. I must have VLAN22 as interVLAN routing somehow to allowed access over VLAN. Need to disable that and if so how do I do that?

2. If I want to change my other switch (Switch2) to L3 also is there anything that I need to do to create L3 commiuncation between the two switches?

Thanks in advance.

 

Connect Switch L3 (192.168.1.6) Port GE1 into Port of Switch L2 (192.168.1.2) Port GE7 on L2 switch is Trunk 1UP,2T,22T. L2 switch is connected to router thru Trunk connection 1UP, 2T, 22

 

Setup is as follows

Router (192.168.1.1)-->L2 Swtich (192.168.1.2) --> L3 switch (192.168.1.6)

 

1. L2 switch and router have VLAN 1, 2 and 22 defined and are working without issues. Devices on VLAN22 do not have access to the network devices just the internet. All ports work as expected.

 

2. Setup for L3 switch

    a. Put in L3 mode

    b. Define VLAN 2, and 22

Screen Shot 2020-05-02 at 6.19.46 PM.png

c. Define Port GE1 Trunk 1UP, 2T, 22T

d. Define Port GE2 Trunk 1T, 2UP, 22T

c. Define Port GE3 Trunk 1T, 2T, 22UP

d. Define Port GE4 Access 1UP

e Define Port GE5 Access 2UP

f Define Port GE6 Access 22UP

 

3. Set IP config to add VLAN2 and 22

Screen Shot 2020-05-02 at 6.23.26 PM.png

 

4. Set IPv4 Routes to Router (192.168.1.1) fro each VLAN. These are autocreated when VLAN created

Screen Shot 2020-05-02 at 6.25.32 PM.png

 

5. Set DHCP Relay from Router including server table

Screen Shot 2020-05-02 at 6.30.38 PM.png

6. Set DHCP Interface Settings

Screen Shot 2020-05-02 at 6.30.47 PM.png 

3 Replies 3

balaji.bandi
Hall of Fame
Hall of Fame

Here is my answeres :

 

2 Questions?????

1. WHAT IS WRONG WITH MY SETUP??. I must have VLAN22 as interVLAN routing somehow to allowed access over VLAN. Need to disable that and if so how do I do that?

 

BB - If  you like to restrict VLAN 22 not to communicate with other VLAN, you need VLAN ACL

chapter 24

 

http://www.cisco.com/c/dam/en/us/td/docs/switches/lan/csbms/sf30x_sg30x/administration_guide/78-19308-01.pdf

 

2. If I want to change my other switch (Switch2) to L3 also is there anything that I need to do to create L3 commiuncation between the two switches?

 

BB - you can build Trunk port between switches, so VLAN extended to other switch.

same above admin guide cover this config.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thanks BB. I have a few more questions if you do not mind.

 

1. DHCP - I have set as Relay on the switches so I get this from the router. Is that ok or do I need to turn on DHCP server for each switch

2. How did my setup look. I do not see a default 0.0.0.0 IP routes. Should there be one there?

3. About ACL. I need to create two ACE's on to exclude VLAN22 from VLAN2 and another to exclude VLAN22 from VLAN1. Does it matter which VLAN I apply it to because it will not let me do them both to VLAN22, so I applied one to VLAN1 and the other to VLAN2... I assume this is correct.

 

Screen Shot 2020-05-03 at 9.28.23 AM.pngScreen Shot 2020-05-03 at 9.26.30 AM.png

 

 

Screen Shot 2020-05-03 at 9.31.04 AM.png

1. DHCP - I have set as Relay on the switches so I get this from the router. Is that ok or do I need to turn on DHCP server for each switch

 

BB - DHCP relay should be good, But if you Isolating VLAN 22, you need to add ACL for that to communcate with DHCP Server to get DHCP IP address for the end device.

 

2. How did my setup look. I do not see a default 0.0.0.0 IP routes. Should there be one there?

 

BB - as per your orginal post, you have not mentioned any routing issue, so assumed here all working, except VLAN 22 ACL required,. you need to have static routes where required.

 

3. About ACL. I need to create two ACE's on to exclude VLAN22 from VLAN2 and another to exclude VLAN22 from VLAN1. Does it matter which VLAN I apply it to because it will not let me do them both to VLAN22, so I applied one to VLAN1 and the other to VLAN2... I assume this is correct.

 

BB -Create an ACE and apply to respected VLAN to take effect, your understand is correct.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help