04-29-2015 04:22 PM - edited 03-07-2019 11:48 PM
Hello Guys,
I am configuring a cisco 4507 catalyst switch and have managed to create a few vlans for testing and i also have connectivity between the vlans and also the access switches. I have internet on the cisco 4507 and am able to ping outside too, but when i connect to a particular vlan, i am able to ping the vlan gateway and also all other vlans but i do not get internet. Hope someone can assist me in this. Attached is the configs.
Regards.
Navin
Solved! Go to Solution.
05-04-2015 06:52 PM
Hi. Your router does not have a route back to your plans. Add the following route to your router.
ip route 10.0.0.0 255.255.0.0 10.2.5.55
Or you can just enable EIGRP to share routes between your router and core switch by adding the following to your router
router eigrp 1
network 10.2.5.1 0.0.0.255
no auto-summary
and also add no auto-summary to your core switch.
04-29-2015 05:56 PM
Where are the configs...
04-29-2015 09:16 PM
Hello charles, thanks for your response, i have uploaded the configs.
04-29-2015 09:18 PM
04-29-2015 10:43 PM
HI Navin ,
kindly can you make tracert 8.8.8.8 from the host and send the results !!!!!
04-30-2015 04:57 PM
tracert just falls at the gateway of the vlan. What i assume is that we need natting to be done, so i put a router in the middle and connected it to the core switch. I am getting internet on the core switch but still not on the vlans. Attached is the internet router configs and the tracert results.
04-30-2015 03:24 AM
What we really need is some detail of what is next up in the chain (i.e. your internet gateway). It may well be that gateway device does not have a route back to your separate VLANs..
04-30-2015 04:17 AM
Good day. Where are you doing NAT for the network? And what type of device is it?
04-30-2015 05:01 PM
04-30-2015 09:16 PM
Hi. You need to add all your VLAN subnets to the NAT acl. Permit any will not work. what are you vlan subnets. You could add the entire 10.x.x.x to your NAT acl. I see you are using the 10 private subnet range. You could try access-list 1 permit 10.0.0.0 0.255.255.255
05-01-2015 01:07 AM
You also need to sort out your routing between the core and the router. From what you have posted regarding your router config it has no way of learning the subnets that sit on the core switch. So even if traffic from the core reaches the gateway the return traffic would be dropped because the router does not know where to send it.
Is the core connected directly to this router? Your LAN interface on the router is 10.2.5.1 and the core switch has no interface in this subnet.
05-03-2015 08:07 PM
Thank your for your response, yes the core is connected directly to the router. The core switch does have an interface on that subnet and it is working fine.
interface GigabitEthernet5/48
no switchport
ip address 10.2.5.55 255.255.255.0
I have also added an access list on the router and still i cannot get internet on any vlans.
access-list 1 permit 10.0.0.0 0.255.255.255
05-03-2015 08:45 PM
Hi. Van you please post both current configs? What are you using for dhcp? What are your clients' default gateway?
05-04-2015 05:55 PM
05-03-2015 10:48 PM
can you add this command
ip nat pool ANYNAME X.X.X.X X.X.X.X prefix-length 30
And send us simple network diagram
thanks
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: