02-28-2015 07:42 AM - edited 03-07-2019 10:53 PM
I have a Cisco 2851 and a 3750. At one point everything was fine and everything was working. I was able to access the internet from multiple vlans. Now for some reason, which i cant figure out, my switch will not ping my router. I cannot access the internet.
I have a cable modem which is DHCP, static IP is not an option. Modem>Router>Switch>Computers
My goal is
Vlan 10 for my internet acces
Vlan 20 for guest wifi
Vlan 30 for IP cameras
Any help would be appreciated.
Router config:
Current configuration : 1810 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname mikerorouter
!
boot-start-marker
boot-end-marker
!
logging message-counter syslog
no logging console
enable secret 5 $1$WC5M$b2bgySF8XI.MqeufJzi2O/
!
no aaa new-model
!
dot11 syslog
ip source-route
!
!
ip cef
ip dhcp excluded-address 10.10.17.1
ip dhcp excluded-address 10.10.17.2
ip dhcp excluded-address 10.10.17.3
ip dhcp excluded-address 10.10.17.4
ip dhcp excluded-address 10.10.17.5
!
ip dhcp pool mikero
import all
network 10.10.17.0 255.255.255.0
default-router 10.10.17.1
dns-server 68.105.28.12 68.105.29.12 68.105.28.11
!
ip domain name mikero.com
no ipv6 cef
!
multilink bundle-name authenticated
!
voice-card 0
!
username admin secret 5 $1$snHZ$/D6wf/iVK7ii6js.RloA80
archive
log config
hidekeys
!
ip ssh version 2
!
interface GigabitEthernet0/0
ip address dhcp
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
interface GigabitEthernet0/1
description LAN
no ip address
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
interface GigabitEthernet0/1.10
encapsulation dot1Q 10
ip address 10.10.17.1 255.255.255.0
ip nat inside
ip virtual-reassembly
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 GigabitEthernet0/0
no ip http server
no ip http secure-server
!
ip nat inside source list 101 interface GigabitEthernet0/0 overload
!
access-list 101 permit ip 10.10.17.0 0.0.0.255 any
!
control-plane
!
mgcp fax t38 ecm
mgcp behavior g729-variants static-pt
!
line con 0
line aux 0
line vty 0 4
login local
transport input ssh
line vty 5 15
login local
transport input ssh
!
scheduler allocate 20000 1000
end
Switch Config:
Current configuration : 3743 bytes
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname mikeroswitch
!
no logging console
enable secret 5 $1$q48p$GHvmx5zju53WBx/7UncGD.
!
username admin secret 5 $1$2dnq$aA2/XzzIatORrobHFoYzc0
no aaa new-model
switch 1 provision ws-c3750-48p
ip subnet-zero
ip domain-name mikero.com
!
ip ssh version 2
!
no file verify auto
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
interface FastEthernet1/0/1
shutdown
!
interface FastEthernet1/0/2
description DESKTOP MIKERO
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/3
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/4
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/5
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/6
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/7
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/8
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/9
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/10
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/11
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/12
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/13
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/14
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/15
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/16
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/17
shutdown
!
interface FastEthernet1/0/18
shutdown
!
interface FastEthernet1/0/19
shutdown
!
interface FastEthernet1/0/20
shutdown
!
interface FastEthernet1/0/21
shutdown
!
interface FastEthernet1/0/22
shutdown
!
interface FastEthernet1/0/23
shutdown
!
interface FastEthernet1/0/24
shutdown
!
interface FastEthernet1/0/25
shutdown
!
interface FastEthernet1/0/26
shutdown
!
interface FastEthernet1/0/27
shutdown
!
interface FastEthernet1/0/28
shutdown
!
interface FastEthernet1/0/29
shutdown
!
interface FastEthernet1/0/30
shutdown
!
interface FastEthernet1/0/31
shutdown
!
interface FastEthernet1/0/32
shutdown
!
interface FastEthernet1/0/33
shutdown
!
interface FastEthernet1/0/34
shutdown
!
interface FastEthernet1/0/35
shutdown
!
interface FastEthernet1/0/36
shutdown
!
interface FastEthernet1/0/37
shutdown
!
interface FastEthernet1/0/38
shutdown
!
interface FastEthernet1/0/39
shutdown
!
interface FastEthernet1/0/40
shutdown
!
interface FastEthernet1/0/41
shutdown
!
interface FastEthernet1/0/42
shutdown
!
interface FastEthernet1/0/43
shutdown
!
interface FastEthernet1/0/44
shutdown
!
interface FastEthernet1/0/45
shutdown
!
interface FastEthernet1/0/46
shutdown
!
interface FastEthernet1/0/47
shutdown
!
interface FastEthernet1/0/48
shutdown
!
interface GigabitEthernet1/0/1
description UPLINK
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface GigabitEthernet1/0/2
shutdown
!
interface GigabitEthernet1/0/3
description WAP
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface GigabitEthernet1/0/4
shutdown
!
interface Vlan1
no ip address
shutdown
!
interface Vlan10
description MIKERO
ip address 10.10.17.2 255.255.255.0
!
ip classless
ip http server
ip http secure-server
!
control-plane
!
line con 0
speed 115200
line vty 0 4
login local
transport input ssh
line vty 5 15
login local
transport input ssh
!
end
Solved! Go to Solution.
02-28-2015 08:56 AM
ok, I don't see a default-gateway on the switch
config t
ip default-gateway 10.10.17.1
and test from the switch.
HTH
02-28-2015 08:50 AM
The config looks correct.
Can you ping 8.8.8.8 from the router?
HTH
02-28-2015 08:54 AM
Yes. Router gets IP from isp and is able to ping outside world. I have tried this same config on the 2851 i and a 2811. I have also tried multiple ports for my trunk.
02-28-2015 08:56 AM
ok, I don't see a default-gateway on the switch
config t
ip default-gateway 10.10.17.1
and test from the switch.
HTH
02-28-2015 09:03 AM
No workie.
02-28-2015 09:08 AM
From the switch can you ping the next hop 10.10.17.1?
Can you post the output of traceroute 8.8.8.8 from the switch?
02-28-2015 09:22 AM
Ok. So now my question is what about my other vlans? Will i have a default gateway for each vlan or will i only need the one 10.10.17.1?
02-28-2015 09:28 AM
You just need one default gateway for the switch (10.10.17.1)
If you want the other vlans to talk to Internet, you need to create a sub-interface (just like the one for vlan 10) on the router. You also need to add the NAT statements for those vlans to the router.
HTH
02-28-2015 09:42 AM
So that should work with with the one default gateway?
interface GigabitEthernet0/1
description LAN
no ip address
ip nat inside
ip virtual-reassembly in
duplex auto
speed auto
no shut
!
interface GigabitEthernet0/1.10
encapsulation dot1Q 10
ip address 10.10.17.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
!
interface GigabitEthernet0/1.20
encapsulation dot1Q 20
ip address 10.12.15.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
!
interface GigabitEthernet0/1.30
encapsulation dot1Q 30
ip address 10.10.10.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
02-28-2015 09:46 AM
Correct. You also need to add the NAT statements
access-list 101 permit ip 10.10.10.0 0.0.0.255 any
access-list 101 permit ip 10.12.15.0 0.0.0.255 any
02-28-2015 11:30 AM
10.10.10.0 network wont access the internet. 10.12.15.0 doesnt need to as its just the cameras and my computer has 2 ether net cards.
I am getting IP's from 10.10.10.0 but cant access the internet. I cannot ping 10.10.17.1 from a 10.10.10.0 network.
02-28-2015 11:32 AM
Can you post the latest config from both the switch and the router?
02-28-2015 11:53 AM
Switch:
mikeroswitch#sho run
Building configuration...
Current configuration : 4747 bytes
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname mikeroswitch
!
no logging console
enable secret 5 $1$q48p$GHvmx5zju53WBx/7UncGD.
!
username admin secret 5 $1$2dnq$aA2/XzzIatORrobHFoYzc0
no aaa new-model
switch 1 provision ws-c3750-48p
ip subnet-zero
ip domain-name mikero.com
!
ip ssh version 2
!
!
!
!
!
no file verify auto
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
interface FastEthernet1/0/1
shutdown
!
interface FastEthernet1/0/2
description DESKTOP MIKERO
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/3
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/4
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/5
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/6
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/7
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/8
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/9
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/10
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/11
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/12
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/13
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/14
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/15
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/16
switchport access vlan 10
switchport mode access
!
interface FastEthernet1/0/17
switchport access vlan 20
switchport mode access
!
interface FastEthernet1/0/18
switchport access vlan 20
switchport mode access
!
interface FastEthernet1/0/19
switchport access vlan 20
switchport mode access
shutdown
!
interface FastEthernet1/0/20
switchport access vlan 20
switchport mode access
shutdown
!
interface FastEthernet1/0/21
switchport access vlan 20
switchport mode access
shutdown
!
interface FastEthernet1/0/22
switchport access vlan 20
switchport mode access
shutdown
!
interface FastEthernet1/0/23
switchport access vlan 20
switchport mode access
shutdown
!
interface FastEthernet1/0/24
switchport access vlan 20
switchport mode access
shutdown
!
interface FastEthernet1/0/25
switchport access vlan 20
switchport mode access
shutdown
!
interface FastEthernet1/0/26
switchport access vlan 20
switchport mode access
shutdown
!
interface FastEthernet1/0/27
switchport access vlan 20
switchport mode access
shutdown
!
interface FastEthernet1/0/28
switchport access vlan 20
switchport mode access
shutdown
!
interface FastEthernet1/0/29
switchport access vlan 20
switchport mode access
shutdown
!
interface FastEthernet1/0/30
switchport access vlan 20
switchport mode access
shutdown
!
interface FastEthernet1/0/31
switchport access vlan 20
switchport mode access
shutdown
!
interface FastEthernet1/0/32
switchport access vlan 20
switchport mode access
!
interface FastEthernet1/0/33
shutdown
!
interface FastEthernet1/0/34
shutdown
!
interface FastEthernet1/0/35
shutdown
!
interface FastEthernet1/0/36
shutdown
!
interface FastEthernet1/0/37
shutdown
!
interface FastEthernet1/0/38
shutdown
!
interface FastEthernet1/0/39
shutdown
!
interface FastEthernet1/0/40
shutdown
!
interface FastEthernet1/0/41
shutdown
!
interface FastEthernet1/0/42
shutdown
!
interface FastEthernet1/0/43
shutdown
!
interface FastEthernet1/0/44
shutdown
!
interface FastEthernet1/0/45
shutdown
!
interface FastEthernet1/0/46
shutdown
!
interface FastEthernet1/0/47
shutdown
!
interface FastEthernet1/0/48
switchport access vlan 30
shutdown
!
interface GigabitEthernet1/0/1
description UPLINK
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface GigabitEthernet1/0/2
shutdown
!
interface GigabitEthernet1/0/3
description WAP
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface GigabitEthernet1/0/4
shutdown
!
interface Vlan1
no ip address
shutdown
!
interface Vlan10
description MIKERO
ip address 10.10.17.2 255.255.255.0
!
interface Vlan20
description CAMERAS
ip address 10.12.15.2 255.255.255.240
!
interface Vlan30
description MIKERO_GUEST
ip address 10.10.10.2 255.255.255.0
!
ip default-gateway 10.10.17.1
ip classless
ip http server
ip http secure-server
!
!
control-plane
!
!
line con 0
speed 115200
line vty 0 4
login local
transport input ssh
line vty 5 15
login local
transport input ssh
!
end
Router:
mikerorouter#sho run
Building configuration...
Current configuration : 2342 bytes
!
version 12.4
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname mikerorouter
!
boot-start-marker
boot-end-marker
!
logging message-counter syslog
no logging console
enable secret 5 $1$WC5M$b2bgySF8XI.MqeufJzi2O/
!
no aaa new-model
!
dot11 syslog
ip source-route
!
!
ip cef
ip dhcp excluded-address 10.10.17.1
ip dhcp excluded-address 10.10.17.2
ip dhcp excluded-address 10.10.17.3
ip dhcp excluded-address 10.10.17.4
ip dhcp excluded-address 10.10.17.5
!
ip dhcp pool mikero
import all
network 10.10.17.0 255.255.255.0
default-router 10.10.17.1
dns-server 68.105.28.12 68.105.29.12 68.105.28.11
!
ip dhcp pool mikero_guest
import all
network 10.10.10.0 255.255.255.0
default-router 10.10.10.1
dns-server 68.105.28.12 68.105.29.12 68.105.28.11
!
!
ip domain name mikero.com
no ipv6 cef
!
multilink bundle-name authenticated
voice-card 0
!
!
!
!
!
username admin secret 5 $1$snHZ$/D6wf/iVK7ii6js.RloA80
archive
log config
hidekeys
!
!
!
!
!
ip ssh version 2
!
!
!
!
interface GigabitEthernet0/0
ip address dhcp
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
interface GigabitEthernet0/1
description LAN
no ip address
ip nat inside
ip virtual-reassembly
duplex auto
speed auto
!
interface GigabitEthernet0/1.10
encapsulation dot1Q 10
ip address 10.10.17.1 255.255.255.0
ip nat inside
ip virtual-reassembly
!
interface GigabitEthernet0/1.20
encapsulation dot1Q 20
ip address 10.12.15.1 255.255.255.240
ip nat inside
ip virtual-reassembly
!
interface GigabitEthernet0/1.30
encapsulation dot1Q 30
ip address 10.10.10.1 255.255.255.0
ip nat inside
ip virtual-reassembly
!
ip forward-protocol nd
ip route 0.0.0.0 0.0.0.0 GigabitEthernet0/0
no ip http server
no ip http secure-server
!
!
ip nat inside source list 101 interface GigabitEthernet0/0 overload
!
access-list 101 permit ip 10.10.17.0 0.0.0.255 any
access-list 102 permit ip 10.12.15.0 0.0.0.255 any
access-list 103 permit ip 10.10.10.0 0.0.0.255 any
!
!
!
!
!
!
control-plane
!
!
!
!
mgcp fax t38 ecm
mgcp behavior g729-variants static-pt
!
!
!
!
!
!
line con 0
line aux 0
line vty 0 4
login local
transport input ssh
line vty 5 15
login local
transport input ssh
!
scheduler allocate 20000 1000
end
02-28-2015 09:40 AM
Try adding this to the switch:
ip 0.0.0.0/0.0.0.0 10.10.17.1
ip default-gateway statement is for the switch only.
02-28-2015 11:22 AM
i get invalid input at the first 0.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide