12-27-2006 09:13 AM - edited 03-05-2019 01:30 PM
Hi friends,
Just some basic questions on the network setup that I have (diagram attached).
As you will see on the diagram, there are two networks (wired and wireless). The users to both the networks are on the same building and floor. But the wireless network is an external network to the 3560 switch and hence is only reachable through the firewall.
The 3560 switch has a static route to reach the wireless network through the firewall's inside Ip. The route is as follows:
ip route 10.81.65.0 255.255.255.0 10.81.64.13
But I am not able to reach the 10.81.65.0 network though I have the route. Do I need to create a Layer 3 VLAN interface (whose IP is in the 10.81.65.0 segment) on the 3560 to reach the wireless network? But doing that makes the 10.81.65.0 network a local network, right? The static route created above then becomes pointless.
Also, I enabled DHCP server on the PIX's wireless interface (less secure). But client's are not able to get an IP from the PIX. I am enclosing the configuration of the PIX as well. Please let me know if there is anything wrong in this config.
The access point and the wireless client's default gateway is the firewall's IP address (10.81.65.1).
Thanks a lot
Gautam
12-27-2006 09:29 AM
Hi Gautam,
Can you confirm if "ip routing" is enabled and you see your static route in ip routing table.
By default ip routing is disabled on switches so it will not route.
Ankur
12-27-2006 10:11 AM
Hi Ankur,
Thanks a lot for your quick response.
The static route was not visible in routing table. As you said correctly, I had to enable ip routing to see the static route in routing table.
After that, I still see dots while pinging to PIX's interface or the devices connected to its interface (in 10.81.65.0) network.
When I try to ping from my PC, after giving switches IP as default gateway, I get the message "Destination host unreachable from switches IP". So pings dont work either from switch or the PC.
Thanks a lot
Gautam
12-27-2006 12:21 PM
If its going thru a firewall then pings are more than likely blocked at the firewall , you should be talking to the firewall folks to make sure you are not being blocked from the subnet you are trying to come from .
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide