cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
649
Views
0
Helpful
2
Replies

Cisco Sg500X inter vlan routing - Cisco can you please help - holding up a project

dhumphries3
Level 1
Level 1

Hey guys

 

I am simply trying to get inter vlan routing working on an SG500X operating in standalone mode.

I have setup a couple of vlan interfaces on the switch which I assume are routed automatically when ip routing is enabled.

I can ping these vlan interfaces from a pc on the appropriate VLAN  (ie - I can ping what should be the default gateway and the gateway and IP are setup correctly on the pc's in question but no traffic will pass from pc to pc.

Have probably missed something obvious - any help would be greatly appreciated, config below:

 

skelta-dist#sh run
config-file-header
skelta-dist
v1.3.0.62 / R750_NIK_1_3_647_260
CLI v1.0
set system queues-mode 4

file SSD indicator encrypted
@
ssd-control-start
ssd config
ssd file passphrase control unrestricted
no ssd file integrity control
ssd-control-end cb0a3fdb1f3a1af4e4430033719968c0
!
vlan database
vlan 2000,3000,4092-4093
exit
voice vlan oui-table add 0001e3 Siemens_AG_phone________
voice vlan oui-table add 00036b Cisco_phone_____________
voice vlan oui-table add 00096e Avaya___________________
voice vlan oui-table add 000fe2 H3C_Aolynk______________
voice vlan oui-table add 0060b9 Philips_and_NEC_AG_phone
voice vlan oui-table add 00d01e Pingtel_phone___________
voice vlan oui-table add 00e075 Polycom/Veritel_phone___
voice vlan oui-table add 00e0bb 3Com_phone______________
bonjour interface range vlan 1
hostname skelta-dist
line console
exec-timeout 0
exit
line ssh
exec-timeout 0
exit
line telnet
exec-timeout 0
exit
logging console debugging
username admin password encrypted 54f0197510fc8f980214826ad98ecc0291956ebc privilege 15
username cisco password encrypted 007253f1436da456a0880a66bbcc7c1b4a3af284 privilege 15
username readonly password encrypted 9a27718297218c3757c365d357d13f49d0fa3065
snmp-server location "Skelta comms room"
snmp-server contact ithelp@vanderfield.com.au
ip http timeout-policy 0
!
interface vlan 1
 ip address 1.1.1.1 255.255.255.0
 no ip address dhcp
!
interface vlan 2000
 name backup
 ip address 192.168.50.241 255.255.255.0
!
interface vlan 3000
 name user
 ip address 10.129.53.241 255.255.254.0
!
interface vlan 4092
 name server
 ip address 10.129.38.241 255.255.255.0
!
interface vlan 4093
 ip address 10.129.100.241 255.255.255.0
!
interface gigabitethernet1/1
 switchport mode access
 switchport access vlan 3000
!
interface gigabitethernet1/2
 switchport mode access
 switchport access vlan 3000
!
interface gigabitethernet1/3
 switchport mode access
 switchport access vlan 3000
!
interface gigabitethernet1/4
 switchport mode access
 switchport access vlan 3000
!
interface gigabitethernet1/5
 switchport mode access
 switchport access vlan 3000
!
interface gigabitethernet1/6
 switchport mode access
 switchport access vlan 3000
!
interface gigabitethernet1/7
 switchport mode access
 switchport access vlan 4092
!
interface gigabitethernet1/8
 switchport mode access
 switchport access vlan 4092
!
interface gigabitethernet1/9
 switchport mode access
 switchport access vlan 4092
!
interface gigabitethernet1/10
 switchport mode access
 switchport access vlan 4092
!
interface gigabitethernet1/11
 switchport mode access
 switchport access vlan 4092
!
interface gigabitethernet1/12
 switchport mode access
 switchport access vlan 4092
!
interface gigabitethernet1/13
 switchport mode access
 switchport access vlan 4093
!
interface gigabitethernet1/14
 switchport mode access
 switchport access vlan 4093
!
interface gigabitethernet1/15
 switchport mode access
 switchport access vlan 4093
!
interface gigabitethernet1/16
 switchport mode access
 switchport access vlan 4093
!
interface gigabitethernet1/17
 switchport mode access
 switchport access vlan 4093
!
interface gigabitethernet1/18
 switchport mode access
 switchport access vlan 4093
!
interface gigabitethernet1/19
 switchport mode access
 switchport access vlan 2000
!
interface gigabitethernet1/20
 switchport mode access
 switchport access vlan 2000
!
interface gigabitethernet1/21
 switchport mode access
 switchport access vlan 2000
!
interface gigabitethernet1/22
 switchport mode access
 switchport access vlan 2000
!
interface gigabitethernet1/23
 switchport mode access
 switchport access vlan 2000
!
interface gigabitethernet1/24
 switchport mode access
 switchport access vlan 2000
!
interface tengigabitethernet1/1
 channel-group 1 mode on
!
interface tengigabitethernet1/2
 channel-group 1 mode on
!
exit
macro auto disabled
macro auto processing type host enabled
macro auto processing type ip_phone disabled
macro auto processing type ip_phone_desktop disabled
macro auto processing type router enabled
macro auto processing type ap disabled
ip helper-address all 0.0.0.0 7

 

skelta-dist#sh ip route
Maximum Parallel Paths: 1 (1 after reset)
IP Forwarding: enabled
Codes: > - best, C - connected, S - static,
       R - RIP


C   1.1.1.0/24 is directly connected, vlan 1
C   10.129.38.0/24 is directly connected, vlan 4092
C   10.129.52.0/23 is directly connected, vlan 3000

 

skelta-dist#sh arp

Total number of entries: 3


  VLAN    Interface     IP address        HW address          status
--------------------- --------------- ------------------- ---------------
vlan 3000  gi1/4      10.129.53.1     a4:5d:36:18:12:d6   dynamic
vlan 4092  gi1/12     10.129.38.1     04:7d:7b:5b:f1:1f   dynamic
vlan 4092             10.129.38.2     a4:5d:36:18:12:d6   dynamic

 

These are the two VLANs and above are the two ARP entries for the pc's.

 

and these are the default gateways:

 

skelta-dist#sh ip interface


    IP Address         I/F       Type     Directed   Precedence   Status
                                          Broadcast
------------------- --------- ----------- ---------- ---------- -----------
1.1.1.1/24          vlan 1    Static      disable    No         Valid
10.129.38.241/24    vlan 4092 Static      disable    No         Valid
10.129.53.241/23    vlan 3000 Static      disable    No         Valid
10.129.100.241/24   vlan 4093 Static      disable    No         Valid
192.168.50.241/24   vlan 2000 Static      disable    No         Valid

2 Replies 2

Rajeev Sharma
Cisco Employee
Cisco Employee

Hey,

Configure the command "ip routing" in global configuration mode.

HTH.

Regards,

RS.

Hi Rajeevsh

 

Ip routing is turned on, the correct connected routes are in the route table, I can see the arp entries for the two pc's but the two pc's cant ping each other (windows firewall is turned off).

 

I CAN ping the vlan interfaces from both pc's but the pc's cant talk to each other.

The ports are in untagged (switchport access) and obviously in the correct vlans

 

skelta-dist#sh ip route address 10.129.38.1
Maximum Parallel Paths: 1 (1 after reset)
IP Forwarding: enabled
Codes: > - best, C - connected, S - static,
       R - RIP


C   10.129.38.0/23 is directly connected, vlan 4092

skelta-dist#sh ip route address 10.129.53.1
Maximum Parallel Paths: 1 (1 after reset)
IP Forwarding: enabled
Codes: > - best, C - connected, S - static,
       R - RIP


C   10.129.53.0/24 is directly connected, vlan 1

skelta-dist#sh arp

Total number of entries: 2


  VLAN    Interface     IP address        HW address          status
--------------------- --------------- ------------------- ---------------
vlan 1     gi1/4      10.129.53.1     a4:5d:36:18:12:d6   dynamic
vlan 4092  gi1/12     10.129.38.1     04:7d:7b:5b:f1:1f   dynamic

 

skelta-dist#sh ip interface


    IP Address         I/F      I/F Status      Type     Directed   Precedence   Status
                                admin/oper               Broadcast
------------------- ---------- ------------- ----------- ---------- ---------- -----------
10.129.38.241/23    vlan 4092  UP/UP         Static      disable    No         Valid
10.129.53.241/24    vlan 1     UP/UP         Static      disable    No         Valid

Review Cisco Networking products for a $25 gift card