cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2220
Views
5
Helpful
6
Replies

Internet not working in Cisco 9300-24T switch

venky82ster
Level 1
Level 1

I have configured SVI vlan 50 and 51 in switch as gateway and 50.2 for firewall interface .

When i try access internet from vlan 50 i m not ableto access internet with 172.30.50.1 as PC gateway .

When I changed to 50.2 as PC gateway i m getting internet .

 

But same cannot be used for vlan 51 as 50.2 gateway is in different vlan .

 

Please help us

1 Accepted Solution

Accepted Solutions

Hello,

 

WingB_CoreSW#conf t

WingB_CoreSW(config)#ip routing

View solution in original post

6 Replies 6

Hello,

 

post the full config of your 9300 switch...

Please find SW config

#sh run
Building configuration...

Current configuration : 9734 bytes
!
! Last configuration change at 09:15:32 UTC Sat Oct 13 2018 by admin
!
version 16.8
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
no platform punt-keepalive disable-kernel-core
!
hostname WingB_CoreSW
!
!
vrf definition Mgmt-vrf
!
address-family ipv4
exit-address-family
!
address-family ipv6
exit-address-family
!
enable password 7 142017070F0B272E75
!
no aaa new-model
switch 1 provision c9300-24t
switch 2 provision c9300-24t
!
!
!
!
!
ip domain name lntinfotech.com
!
!
!
!
!
!
!
!
vtp mode transparent
cpp system-default
!
crypto pki trustpoint TP-self-signed-973789964
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-973789964
revocation-check none
rsakeypair TP-self-signed-973789964
!
!
crypto pki certificate chain TP-self-signed-973789964
certificate self-signed 01
3082032E 30820216 A0030201 02020101 300D0609 2A864886 F70D0101 05050030
30312E30 2C060355 04031325 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 39373337 38393936 34301E17 0D313831 30313030 38323532
385A170D 32303031 30313030 30303030 5A303031 2E302C06 03550403 1325494F
532D5365 6C662D53 69676E65 642D4365 72746966 69636174 652D3937 33373839
39363430 82012230 0D06092A 864886F7 0D010101 05000382 010F0030 82010A02
82010100 BCBE40D6 5673DA04 3960DFAB 7049EC5F 78F19631 E9AD33C7 90248DD0
72328541 85D714DD 44B57EEC 4D1F67D6 809A635C 0DC0454E 4850E367 626F8B01
38E2F474 9E8B1864 F06DE63A B6EC3912 EF0DFE17 E86863A7 7AC29746 3DBB833C
2B3AFAB0 55E0B61A 03192278 FC302EF0 87930FAD 3519360B 4DDB749E 21AB7E36
EAB62DF0 C1306F7F 10F149A9 048F86BA 6A92AEF5 E57144CB ADC2EA45 E6A68658
DEDF81F7 C4AEF63E 97B61ED4 E4F20888 12338DE4 E644990D 9D821010 F4042A42
07FD448A DDA8F112 C1972EDB 19575EB7 6EF6C007 9FDEEBB2 8863A0E4 168502A7
782C34B1 737C2C51 2A46CDF4 B50F3815 CF6886A1 E09C61E7 4E8796FB F5C28D99
BF6EA121 02030100 01A35330 51300F06 03551D13 0101FF04 05300301 01FF301F
0603551D 23041830 168014BF 947CE055 BE8A0820 2AA96C60 F1F74B09 744F1830
1D060355 1D0E0416 0414BF94 7CE055BE 8A08202A A96C60F1 F74B0974 4F18300D
06092A86 4886F70D 01010505 00038201 01000073 EE7B3AA3 68E5C475 14424743
514188F8 A6B2DBF2 887B1282 5E5A2D23 4FF94144 333E1646 06598B90 78A2F340
2D47E9E8 A134C47F 774AA6D9 B1042AFA 4F66A577 EE6A428F 217E974F 166A1A2C
551E12A0 7E5D3A2C 36BD91C4 92C5E636 BA35EF84 2B91A872 DCC9EA3E 1F72BB51
EF637148 D01DB8C0 1567606E D2F002EC 2A58C40D CF42DF23 4C34AB00 EA8F8110
7A142486 58DD0B28 061277A5 82B9FB95 94739B57 AD05FDCA 63D4A8F2 642144FD
7FE209F7 75F186D6 4632CD3C 93176275 750F5815 8F214779 6559A55E 181B3201
BB46EBD2 2C3795FF 2D8A24A1 872B4BAB 7B7D7A20 EF931B17 A37271EB 6E633BDD
45BBF38E 5D2E9486 861B86AC EF6166D6 B039
quit
!
!
!
diagnostic bootup level minimal
!
spanning-tree mode rapid-pvst
spanning-tree extend system-id
!
!
redundancy
mode sso
!
!
!
!
!
vlan 50
name Network Mgmt
!
vlan 51
name Lan_User
!
vlan 53
name LTI_Internet
!
vlan 54
name LTI_Guest_Internet
!
!
class-map match-any system-cpp-police-topology-control
description Topology control
class-map match-any system-cpp-police-sw-forward
description Sw forwarding, L2 LVX data, LOGGING
class-map match-any system-cpp-default
description EWLC control, EWLC data
class-map match-any system-cpp-police-sys-data
description Learning cache ovfl, Crypto Control, Exception, EGR Exception, NFL SAMPLED DATA, Gold Pkt, RPF Failed
class-map match-any system-cpp-police-punt-webauth
description Punt Webauth
class-map match-any system-cpp-police-l2lvx-control
description L2 LVX control packets
class-map match-any system-cpp-police-forus
description Forus Address resolution and Forus traffic
class-map match-any system-cpp-police-multicast-end-station
description MCAST END STATION
class-map match-any system-cpp-police-multicast
description Transit Traffic and MCAST Data
class-map match-any system-cpp-police-l2-control
description L2 control
class-map match-any system-cpp-police-dot1x-auth
description DOT1X Auth
class-map match-any system-cpp-police-data
description ICMP redirect, ICMP_GEN and BROADCAST
class-map match-any system-cpp-police-control-low-priority
description General punt
class-map match-any non-client-nrt-class
class-map match-any system-cpp-police-routing-control
description Routing control and Low Latency
class-map match-any system-cpp-police-protocol-snooping
description Protocol snooping
class-map match-any system-cpp-police-dhcp-snooping
description DHCP snooping
!
policy-map system-cpp-policy
class system-cpp-police-data
class system-cpp-police-sys-data
class system-cpp-police-sw-forward
class system-cpp-police-multicast
class system-cpp-police-multicast-end-station
class system-cpp-police-punt-webauth
class system-cpp-police-l2-control
class system-cpp-police-routing-control
class system-cpp-police-control-low-priority
class system-cpp-police-l2lvx-control
class system-cpp-police-topology-control
class system-cpp-police-dot1x-auth
class system-cpp-police-protocol-snooping
class system-cpp-police-dhcp-snooping
class system-cpp-police-forus
class system-cpp-default
!
!
!
!
!
!
!
!
!
!
interface Port-channel10
description "Connected to POE SW"
switchport mode trunk
!
interface Port-channel20
description "Connected to Wing B Stack_SW"
switchport mode trunk
!
interface GigabitEthernet0/0
vrf forwarding Mgmt-vrf
no ip address
speed 1000
negotiation auto
!
interface GigabitEthernet1/0/1
description "connected Wing A FW"
no switchport
no ip address
!
interface GigabitEthernet1/0/2
!
interface GigabitEthernet1/0/3
!
interface GigabitEthernet1/0/4
!
interface GigabitEthernet1/0/5
!
interface GigabitEthernet1/0/6
!
interface GigabitEthernet1/0/7
!
interface GigabitEthernet1/0/8
!
interface GigabitEthernet1/0/9
!
interface GigabitEthernet1/0/10
!
interface GigabitEthernet1/0/11
!
interface GigabitEthernet1/0/12
!
interface GigabitEthernet1/0/13
!
interface GigabitEthernet1/0/14
!
interface GigabitEthernet1/0/15
!
interface GigabitEthernet1/0/16
!
interface GigabitEthernet1/0/17
!
interface GigabitEthernet1/0/18
!
interface GigabitEthernet1/0/19
!
interface GigabitEthernet1/0/20
!
interface GigabitEthernet1/0/21
!
interface GigabitEthernet1/0/22
!
interface GigabitEthernet1/0/23
description "Connected Wing C FW"
switchport access vlan 50
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet1/0/24
description "Connected to POE SW"
switchport mode trunk
channel-group 10 mode active
!
interface GigabitEthernet1/1/1
!
interface GigabitEthernet1/1/2
!
interface GigabitEthernet1/1/3
!
interface GigabitEthernet1/1/4
!
interface TenGigabitEthernet1/1/1
!
interface TenGigabitEthernet1/1/2
!
interface TenGigabitEthernet1/1/3
!
interface TenGigabitEthernet1/1/4
!
interface TenGigabitEthernet1/1/5
!
interface TenGigabitEthernet1/1/6
!
interface TenGigabitEthernet1/1/7
!
interface TenGigabitEthernet1/1/8
switchport mode trunk
channel-group 20 mode active
!
interface FortyGigabitEthernet1/1/1
!
interface FortyGigabitEthernet1/1/2
!
interface TwentyFiveGigE1/1/1
!
interface TwentyFiveGigE1/1/2
!
interface GigabitEthernet2/0/1
description "connected Wing A FW"
no switchport
no ip address
!
interface GigabitEthernet2/0/2
!
interface GigabitEthernet2/0/3
!
interface GigabitEthernet2/0/4
!
interface GigabitEthernet2/0/5
!
interface GigabitEthernet2/0/6
!
interface GigabitEthernet2/0/7
!
interface GigabitEthernet2/0/8
!
interface GigabitEthernet2/0/9
!
interface GigabitEthernet2/0/10
!
interface GigabitEthernet2/0/11
!
interface GigabitEthernet2/0/12
!
interface GigabitEthernet2/0/13
!
interface GigabitEthernet2/0/14
!
interface GigabitEthernet2/0/15
!
interface GigabitEthernet2/0/16
!
interface GigabitEthernet2/0/17
!
interface GigabitEthernet2/0/18
!
interface GigabitEthernet2/0/19
!
interface GigabitEthernet2/0/20
!
interface GigabitEthernet2/0/21
shutdown
!
interface GigabitEthernet2/0/22
!
interface GigabitEthernet2/0/23
description "Connected Wing C FW"
switchport access vlan 50
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet2/0/24
description "Connected to POE SW"
switchport mode trunk
channel-group 10 mode active
!
interface GigabitEthernet2/1/1
!
interface GigabitEthernet2/1/2
!
interface GigabitEthernet2/1/3
!
interface GigabitEthernet2/1/4
!
interface TenGigabitEthernet2/1/1
!
interface TenGigabitEthernet2/1/2
!
interface TenGigabitEthernet2/1/3
!
interface TenGigabitEthernet2/1/4
!
interface TenGigabitEthernet2/1/5
!
interface TenGigabitEthernet2/1/6
!
interface TenGigabitEthernet2/1/7
!
interface TenGigabitEthernet2/1/8
switchport mode trunk
channel-group 20 mode active
!
interface FortyGigabitEthernet2/1/1
!
interface FortyGigabitEthernet2/1/2
!
interface TwentyFiveGigE2/1/1
!
interface TwentyFiveGigE2/1/2
!
interface Vlan1
no ip address
shutdown
!
interface Vlan50
ip address 172.30.50.1 255.255.255.128
!
interface Vlan51
ip address 172.30.51.1 255.255.255.0
!
interface Vlan53
ip address 172.30.53.1 255.255.255.0
!
interface Vlan54
ip address 172.30.54.1 255.255.255.0
!
ip forward-protocol nd
ip http server
ip http authentication local
ip http secure-server
ip route 0.0.0.0 0.0.0.0 172.30.50.2
!
!
!
!
control-plane
service-policy input system-cpp-policy
!
!
line con 0
stopbits 1
line vty 0 4
login local
transport input ssh
line vty 5 15
login local
transport input ssh
!
!
mac address-table notification mac-move
wsma agent exec
!
wsma agent config
!
wsma agent filesys
!
wsma agent notify
!
!
end

johnd2310
Level 8
Level 8

Hi,

  • Have you  enabled routing on the switch?
  • Do you have a default route on the switch pointing to 50.2
  • 51 can use 50.2 if you have enabled routing on the switch and configured a default route pointing to 50.2 On 50.2 you will need a static route for 51 pointing to 50.1

 

Thanks

John

**Please rate posts you find helpful**

I have connected my PC directly to 9300 switch and in vlan 50 .
I have default route pointing to firewall 50.2 .
But when I use 50.1 as a gateway in my PC not getting internet but when I use 50.2 as a gateway getting internet .

Regards,
Venkatesh

Hello,

 

WingB_CoreSW#conf t

WingB_CoreSW(config)#ip routing

Thanks Georg
Review Cisco Networking products for a $25 gift card