02-09-2019 02:51 AM
Hello Guys,
I have a SG300-10 and I am trying to route 2 vlans, I was using layer 2 SW's and both my Firewalls to route them and all was working but I want the SW to do it now.
I'll try to explain my network as best as I can.
So I have 2 L2 SW's and 1 L3 SW in the middle 1 with LAG and the other trunked, connected to my L2 SW's are 2 different networks 10.1.1.0 and 172.16.1.0 they are NAT by the firewalls to 10.110.1.0 and 192.168.5.0 these 2 addresses are my router lan's and gateway
I have setup the VLANS and both firewalls get Ip addresses from the router but my question is how do I route the traffic between both 172 and 10 lans?
If I create both vlan interfaces on the L3 SW for 10 or 172 they also get ip's (DHCP) and the routes are created automatically but I still can't ping them both from 10 to 172 and 172 to 10.
Do I have to create a static route on the firewalls?
Sorry I'm not a network expert and all this is being done just by reading and testing but I do understand some concepts.
Cheers
02-09-2019 05:00 AM
02-09-2019 05:45 AM
The SW is already operating as L3 IP routing is active
02-09-2019 05:50 AM
02-09-2019 06:23 AM
02-09-2019 07:06 AM
There, my goal is to make both lans talk to each other
Any help would be great
02-09-2019 07:16 AM
02-09-2019 07:19 AM
Hi Thanks, do you mean assign vlan 10 and vlan 500 interfaces on the Switch and give them the firewalls LAN ip gateway's?
Thanks
02-09-2019 07:25 AM
if you assigned the gatwayes already to Firewall, then firewall can route traffic to l3 sw. im not sure why you are having 2 firewalls inside the LAN.
if you want to keep firewalls as it is, you can add static routes in firewall.
if not, tou can remove firewall and add LAN gateway to L3 sw.
ex.
option 1 >
PC > FW 1(gateway for VLAN 10) > L3 SW > FW 2(gateway for VLAN 500) > PC
if so you need to have same subnet IP addresses for each VLAN (10 and 500) created in L3 sw and add respective routes in FW and L3 sw.
option 2 >
PC > L3 SW (gateway for both vlan 10 and 500) > PC
02-09-2019 07:29 AM
Thanks! I have 2 firewalls as 1 is my home lab and the other my home network I usually shutdown the first
I'll try option 1
Thanks
02-10-2019 04:10 AM
Hi Guys,
Something REALLY weird is happening, and I hope you guys can help me.
I'm having a response from a 10.1.1.1 and 10.1.1.3 ip address's even when everything is disconnected from the network.
If I connect to my router wireless network I still get a reply from those 2 addresses, I have already reset my router and it's still there again nothing is connected to my router just my laptop. I can also ping those addresses from my phone.
This is weird as one of my lan networks is 10. but nothing is up or connected...
If I hotspot to my phone then they are gone which means this is on my vdsl2 isp network
What is going on??
02-10-2019 06:54 AM
02-10-2019 10:35 AM
thanks Jaderson, It's working now with 2 static routes 1 on each firewall however performance is very poor.
And I can't find the problem.. well poor network design perhaps :(
A vpn between them?
02-10-2019 11:06 AM
02-10-2019 11:11 AM
No, routes are on both lan interfaces and pointing to my L3 as gateway all works but very very slow
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide