cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9377
Views
4
Helpful
10
Replies

Unable to connect to internet from switch.

hawkeyeg
Level 1
Level 1

 I have a 3750v2 switch connected to a 3560 router and I cannot connect to the internet.  I can connect from the router to the internet with no problem but when I connect the router to the switch I lose access to the internet. My switch is connected to two computers one server and one Laptop.

port f1/0/1 router 192.168.10.2

port f1/0/2 Laptop 192.168.20.1

port f1/0/3 Server 192.168.30.1

the server can talk to the laptop and the laptop can connect to the server by way of a layer three switch 

but the router is not connected

any help would be appropriate 

1 Accepted Solution

Accepted Solutions

On the router - 

"ip route 192.168.20.0 255.255.255.0 192.168.10.2"

Jon

View solution in original post

10 Replies 10

Jon Marshall
Hall of Fame
Hall of Fame

A 3560 is a L3 switch, can you clarify.

Also please post the configurations.

Jon

the 3750 is a layer 3 switch

the router is 2821 sorry I have too many devices

Thanks for clarifying.

Can you post the configurations of both devices ?

Jon

Here is the Switch configuration

HawkSW1#sh startup-config
Using 2313 out of 524288 bytes
!
version 12.2
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname HawkSW1
!
boot-start-marker
boot-end-marker
!
enable secret 5 $1$v5IC$PM3NNLuy1VydFhPhHDxoX0
enable password p@ss1234
!
!
!
no aaa new-model
switch 1 provision ws-c3750v2-48ps
system mtu routing 1500
ip routing
!
!
!
!
!
!
!
!
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
!
!
interface FastEthernet1/0/1
!
interface FastEthernet1/0/2
!
interface FastEthernet1/0/3
!
interface FastEthernet1/0/4
!
interface FastEthernet1/0/5
!
interface FastEthernet1/0/6
!
interface FastEthernet1/0/7
!
interface FastEthernet1/0/8
!
interface FastEthernet1/0/9
!
interface FastEthernet1/0/10
!
interface FastEthernet1/0/11
!
interface FastEthernet1/0/12
!
interface FastEthernet1/0/13
!
interface FastEthernet1/0/14
!
interface FastEthernet1/0/15
!
interface FastEthernet1/0/16
!
interface FastEthernet1/0/17
!
interface FastEthernet1/0/18
!
interface FastEthernet1/0/19
!
interface FastEthernet1/0/20
!
interface FastEthernet1/0/21
!
interface FastEthernet1/0/22
!
interface FastEthernet1/0/23
!
interface FastEthernet1/0/24
!
interface FastEthernet1/0/25
!
interface FastEthernet1/0/26
!
interface FastEthernet1/0/27
!
interface FastEthernet1/0/28
!
interface FastEthernet1/0/29
!
interface FastEthernet1/0/30
!
interface FastEthernet1/0/31
!
interface FastEthernet1/0/32
!
interface FastEthernet1/0/33
!
interface FastEthernet1/0/34
!
interface FastEthernet1/0/35
!
interface FastEthernet1/0/36
!
interface FastEthernet1/0/37
!
interface FastEthernet1/0/38
!
interface FastEthernet1/0/39
!
interface FastEthernet1/0/40
!
interface FastEthernet1/0/41
!
interface FastEthernet1/0/42
!
interface FastEthernet1/0/43
!
interface FastEthernet1/0/44
!
interface FastEthernet1/0/45
!
interface FastEthernet1/0/46
!
interface FastEthernet1/0/47
!
interface FastEthernet1/0/48
!
interface GigabitEthernet1/0/1
!
interface GigabitEthernet1/0/2
!
interface GigabitEthernet1/0/3
!
interface GigabitEthernet1/0/4
!
interface Vlan1
ip address 192.168.50.1 255.255.255.0
!
ip classless
ip http server
ip http secure-server
!
!
!
line con 0
exec-timeout 0 0
line vty 0 4
password cisco
login
line vty 5 15
password cisco
login
!
end

and here the config of the router

HawkR1#sh running-config
Building configuration...


Current configuration : 3014 bytes
!
version 15.1
service config
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname HawkR1
!
boot-start-marker
boot-end-marker
!
!
enable secret 5 $1$1iDF$ZqUNjUxASMMrtIp2DXvB30
enable password p@ss1234
!
no aaa new-model
memory-size iomem 10
clock timezone PCTime -5 0
clock summer-time PCTime date Apr 6 2003 2:00 Oct 26 2003 2:00
!
dot11 syslog
ip source-route
!
!
ip cef
!
!
!
no ipv6 cef
multilink bundle-name authenticated
!
!
!
!
!
!
!
!
!
!
!
voice-card 0
!
crypto pki token default removal timeout 0
!
crypto pki trustpoint TP-self-signed-3419789487
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-3419789487
revocation-check none
!
!
crypto pki certificate chain TP-self-signed-3419789487
certificate self-signed 01
30820243 308201AC A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 33343139 37383934 3837301E 170D3137 30373038 30323235
31375A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 34313937
38393438 3730819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100BF2B F4921451 BFB9C777 9691D67A BC9E53DD 3A582389 A3646229 202B409B
1FA2B4B6 E4B9A2C9 95ABC7AC BFFB880D 210B1CBB ADDB92F7 A500F895 A9408FAC
DA7E27AD C9DD146A 693A6B4E 093AB9F9 917C08B7 854AA55D B0448F68 2C800C8D
994A54EB 2F5F202C 09A44891 963349EE ACD21454 91C39683 7144CAC7 439ED525
23630203 010001A3 6B306930 0F060355 1D130101 FF040530 030101FF 30160603
551D1104 0F300D82 0B486177 6B52312E 686F6D65 301F0603 551D2304 18301680
14BDD10A C1A39D15 8F9816D9 8EC697BC F0A1BE25 B7301D06 03551D0E 04160414
BDD10AC1 A39D158F 9816D98E C697BCF0 A1BE25B7 300D0609 2A864886 F70D0101
04050003 81810057 B8281BAF A11DC2A9 DA996126 E90C3E27 70070075 EB7AEAF2
9EDB4C95 200B6000 81121787 15D6DFC1 45EEA3B1 6A51413E 6D263369 83D8E927
E619C5FE 038C8875 1551D1C4 CB45DCBE 3D24CC30 F197FB43 6702F735 D73B6BC3
0ED17677 EDD66480 07D7266E D4D20D09 A88FF28F 489B820E E1DF2C6E DA923364
81C3AF24 509F83
quit
!
!
license udi pid CISCO2821 sn FTX0946A3NN
username admin privilege 15 password 0 cisco
!
!
!
!
!
!
!
interface GigabitEthernet0/0
ip address dhcp
ip nat outside
ip virtual-reassembly in
duplex auto
speed auto
!
interface GigabitEthernet0/1
ip address 192.168.10.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
duplex auto
speed auto
no mop enabled
!
ip forward-protocol nd
!
ip http server
ip http authentication local
ip http secure-server
!
ip nat inside source list 1 interface GigabitEthernet0/0 overload
!
access-list 1 remark CCP_ACL Category=2
access-list 1 permit 192.168.10.0 0.0.0.255
dialer-list 1 protocol ip permit
!
!
!
control-plane
!
!
!
!
!
!
!
line con 0
line aux 0
line 1/0 1/31
line vty 0 4
password cisco
login local
transport input telnet ssh
!
scheduler allocate 20000 1000
end

hope this help

All ports on the switch are in vlan 1 because you have not assigned them to any other ports. 

What exactly do you want to setup ie. do you want the laptop and server in different subnets and route on the switch and then also have internet access ?

Jon 

I sent the wrong startup file for the switch here is the correct one

HawkSW1#sh startup-config
Using 2776 out of 524288 bytes
!
version 12.2
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname HawkSW1
!
boot-start-marker
boot-end-marker
!
enable secret 5 $1$v5IC$PM3NNLuy1VydFhPhHDxoX0
enable password p@ss1234
!
!
!
no aaa new-model
switch 1 provision ws-c3750v2-48ps
system mtu routing 1500
ip routing
!
!
!
!
crypto pki trustpoint TP-self-signed-3401591680
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-3401591680
revocation-check none
rsakeypair TP-self-signed-3401591680
!
!
crypto pki certificate chain TP-self-signed-3401591680
certificate self-signed 01 nvram:IOS-Self-Sig#3030.cer
!
!
!
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
!
!
interface FastEthernet1/0/1
no switchport
ip address 192.168.10.2 255.255.255.0
!
interface FastEthernet1/0/2
no switchport
ip address 192.168.20.1 255.255.255.0
!
interface FastEthernet1/0/3
no switchport
ip address 192.168.30.1 255.255.255.0
!
interface FastEthernet1/0/4
!
interface FastEthernet1/0/5
!
interface FastEthernet1/0/6
!
interface FastEthernet1/0/7
!
interface FastEthernet1/0/8
!
interface FastEthernet1/0/9
!
interface FastEthernet1/0/10
!
interface FastEthernet1/0/11
!
interface FastEthernet1/0/12
!
interface FastEthernet1/0/13
!
interface FastEthernet1/0/14
!
interface FastEthernet1/0/15
!
interface FastEthernet1/0/16
!
interface FastEthernet1/0/17
!
interface FastEthernet1/0/18
!
interface FastEthernet1/0/19
!
interface FastEthernet1/0/20
!
interface FastEthernet1/0/21
!
interface FastEthernet1/0/22
!
interface FastEthernet1/0/23
!
interface FastEthernet1/0/24
!
interface FastEthernet1/0/25
!
interface FastEthernet1/0/26
!
interface FastEthernet1/0/27
!
interface FastEthernet1/0/28
!
interface FastEthernet1/0/29
!
interface FastEthernet1/0/30
!
interface FastEthernet1/0/31
!
interface FastEthernet1/0/32
!
interface FastEthernet1/0/33
!
interface FastEthernet1/0/34
!
interface FastEthernet1/0/35
!
interface FastEthernet1/0/36
!
interface FastEthernet1/0/37
!
interface FastEthernet1/0/38
!
interface FastEthernet1/0/39
!
interface FastEthernet1/0/40
!
interface FastEthernet1/0/41
!
interface FastEthernet1/0/42
!
interface FastEthernet1/0/43
!
interface FastEthernet1/0/44
!
interface FastEthernet1/0/45
!
interface FastEthernet1/0/46
!
interface FastEthernet1/0/47
!
interface FastEthernet1/0/48
!
interface GigabitEthernet1/0/1
!
interface GigabitEthernet1/0/2
!
interface GigabitEthernet1/0/3
!
interface GigabitEthernet1/0/4
!
interface Vlan1
ip address 192.168.50.1 255.255.255.0
!
ip classless
ip http server
ip http secure-server
!
!
!
line con 0
exec-timeout 0 0
line vty 0 4
password cisco
login
line vty 5 15
password cisco
login
!
end

hopefully this clear up the matter

On your switch -

"ip route 0.0.0.0 0.0.0.0 192.168.10.1"

and on your router -

"access-list 1 permit 192.168.20.0 0.0.0.255"
"access-list 1 permit 192.168.30.0 0.0.0.255"

"ip route 192.168.20.0 0.0.0.255 192.168.10.2"
"ip route 192.168.30.0 0.0.0.255 192.168.10.2"

note that for end devices such as your laptop and server you would normally create vlans, assign the ports into vlans and then create SVIs ("int vlan x") for those vlans which means you can have multiple devices in the same vlan.

However your setup should work.

Jon

The setup did not work so I change my switch config here is the updated files

for my router:

Building configuration...


Current configuration : 3366 bytes
!
! Last configuration change at 19:21:36 PCTime Sun Jul 9 2017
! NVRAM config last updated at 20:05:46 PCTime Sun Jul 9 2017
!
version 15.1
service config
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname HawkR1
!
boot-start-marker
boot-end-marker
!
!
logging buffered 4096
enable secret 5 $1$1iDF$ZqUNjUxASMMrtIp2DXvB30
enable password 7 12092504015A5E577E
!
no aaa new-model
memory-size iomem 10
clock timezone PCTime -5 0
clock summer-time PCTime date Apr 6 2003 2:00 Oct 26 2003 2:00
!
dot11 syslog
ip source-route
!
!
ip cef
!
!
!
no ipv6 cef
multilink bundle-name authenticated
!
!
!
!
!
!
!
!
!
!
!
voice-card 0
!
crypto pki token default removal timeout 0
!
crypto pki trustpoint TP-self-signed-3419789487
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-3419789487
revocation-check none
!
!
crypto pki certificate chain TP-self-signed-3419789487
certificate self-signed 01
30820243 308201AC A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 33343139 37383934 3837301E 170D3137 30373038 30323235
31375A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 34313937
38393438 3730819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100BF2B F4921451 BFB9C777 9691D67A BC9E53DD 3A582389 A3646229 202B409B
1FA2B4B6 E4B9A2C9 95ABC7AC BFFB880D 210B1CBB ADDB92F7 A500F895 A9408FAC
DA7E27AD C9DD146A 693A6B4E 093AB9F9 917C08B7 854AA55D B0448F68 2C800C8D
994A54EB 2F5F202C 09A44891 963349EE ACD21454 91C39683 7144CAC7 439ED525
23630203 010001A3 6B306930 0F060355 1D130101 FF040530 030101FF 30160603
551D1104 0F300D82 0B486177 6B52312E 686F6D65 301F0603 551D2304 18301680
14BDD10A C1A39D15 8F9816D9 8EC697BC F0A1BE25 B7301D06 03551D0E 04160414
BDD10AC1 A39D158F 9816D98E C697BCF0 A1BE25B7 300D0609 2A864886 F70D0101
04050003 81810057 B8281BAF A11DC2A9 DA996126 E90C3E27 70070075 EB7AEAF2
9EDB4C95 200B6000 81121787 15D6DFC1 45EEA3B1 6A51413E 6D263369 83D8E927
E619C5FE 038C8875 1551D1C4 CB45DCBE 3D24CC30 F197FB43 6702F735 D73B6BC3
0ED17677 EDD66480 07D7266E D4D20D09 A88FF28F 489B820E E1DF2C6E DA923364
81C3AF24 509F83
quit
!
!
license udi pid CISCO2821 sn FTX0946A3NN
username admin privilege 15 password 7 121A0C041104
username Hawk privilege 15 password 7 1511021F0725
!
!
!
!
!
!
!
interface GigabitEthernet0/0
ip address dhcp
ip nat outside
ip virtual-reassembly in
duplex auto
speed auto
!
interface GigabitEthernet0/1
description $ETH-LAN$
ip address 192.168.10.1 255.255.255.0
ip nat inside
ip virtual-reassembly in
duplex auto
speed auto
no mop enabled
!
ip forward-protocol nd
!
ip http server
ip http authentication local
ip http secure-server
!
ip nat inside source list 1 interface GigabitEthernet0/0 overload
!
logging 192.168.10.1
access-list 1 remark CCP_ACL Category=2
access-list 1 permit 192.168.30.0 0.0.0.255
access-list 1 permit 192.168.20.0 0.0.0.255
access-list 1 permit 192.168.10.0 0.0.0.255
dialer-list 1 protocol ip permit
!
!
!
control-plane
!
!
!
!
!
!
!
line con 0
logging synchronous
line aux 0
line 1/0 1/31
line vty 0 4
login local
transport input telnet ssh
!
scheduler allocate 20000 1000
end

for my switch


Building configuration...

Current configuration : 4160 bytes
!
version 12.2
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
service password-encryption
!
hostname HawkSW1
!
boot-start-marker
boot-end-marker
!
enable secret 5 $1$v5IC$PM3NNLuy1VydFhPhHDxoX0
enable password 7 13153701185D56797F
!
!
!
no aaa new-model
switch 1 provision ws-c3750v2-48ps
system mtu routing 1500
ip routing
!
!
!
!
crypto pki trustpoint TP-self-signed-3401591680
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-3401591680
revocation-check none
rsakeypair TP-self-signed-3401591680
!
!
crypto pki certificate chain TP-self-signed-3401591680
certificate self-signed 01
30820240 308201A9 A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 33343031 35393136 3830301E 170D3933 30333031 30303032
34395A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 34303135
39313638 3030819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100BB9E 33E3EAA0 4D42C9E8 509A363E 53868A8C 7480E631 A89BCE0D A62AE650
3902B2FE E5ACCFC3 7FD575B3 CE51D608 59FD1E21 FD545B48 F873D164 D0F60D28
98DCFBC1 C7AA810F 5F23C8A5 AE7B6C90 4AD96470 06669F0F 04523E36 F9C9302B
7D4E4470 6ABDBCB5 17AC6706 FF8D2D5D EF558E40 F7A5056B FFBE3398 A438D589
1A6F0203 010001A3 68306630 0F060355 1D130101 FF040530 030101FF 30130603
551D1104 0C300A82 08486177 6B535731 2E301F06 03551D23 04183016 80149786
416FC7BC 0D944DC7 525B5A9E F936BF7D 8331301D 0603551D 0E041604 14978641
6FC7BC0D 944DC752 5B5A9EF9 36BF7D83 31300D06 092A8648 86F70D01 01040500
03818100 22014DC4 F431FD36 9B0F4ECA D9DDB4F1 749E43C5 6F01049C C9DA9427
2FFE6EC2 EF351B6E 7D7901FD 52F7EE23 B1CA1C09 169D5F25 BCCBE170 25296A8E
F6AD7C5C A1BDF533 9F45CE10 0ED52E89 B83BCFD3 62B8AF8A F7224DC8 7A62B6E2
BE409930 995FA889 EF77AE88 802FCBB4 88C2E052 AA1D4F55 275D996E 611D73B4 852663D0
quit
!
!
!
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
!
!
interface FastEthernet1/0/1
!
interface FastEthernet1/0/2
switchport access vlan 20
!
interface FastEthernet1/0/3
switchport access vlan 20
!
interface FastEthernet1/0/4
!
interface FastEthernet1/0/5
!
interface FastEthernet1/0/6
!
interface FastEthernet1/0/7
!
interface FastEthernet1/0/8
!
interface FastEthernet1/0/9
!
interface FastEthernet1/0/10
!
interface FastEthernet1/0/11
!
interface FastEthernet1/0/12
!
interface FastEthernet1/0/13
!
interface FastEthernet1/0/14
!
interface FastEthernet1/0/15
!
interface FastEthernet1/0/16
!
interface FastEthernet1/0/17
!
interface FastEthernet1/0/18
!
interface FastEthernet1/0/19
!
interface FastEthernet1/0/20
!
interface FastEthernet1/0/21
!
interface FastEthernet1/0/22
!
interface FastEthernet1/0/23
!
interface FastEthernet1/0/24
!
interface FastEthernet1/0/25
!
interface FastEthernet1/0/26
!
interface FastEthernet1/0/27
!
interface FastEthernet1/0/28
!
interface FastEthernet1/0/29
!
interface FastEthernet1/0/30
!
interface FastEthernet1/0/31
!
interface FastEthernet1/0/32
!
interface FastEthernet1/0/33
!
interface FastEthernet1/0/34
!
interface FastEthernet1/0/35
!
interface FastEthernet1/0/36
!
interface FastEthernet1/0/37
!
interface FastEthernet1/0/38
!
interface FastEthernet1/0/39
!
interface FastEthernet1/0/40
!
interface FastEthernet1/0/41
!
interface FastEthernet1/0/42
!
interface FastEthernet1/0/43
!
interface FastEthernet1/0/44
!
interface FastEthernet1/0/45
!
interface FastEthernet1/0/46
!
interface FastEthernet1/0/47
!
interface FastEthernet1/0/48
!
interface GigabitEthernet1/0/1
!
interface GigabitEthernet1/0/2
!
interface GigabitEthernet1/0/3
!
interface GigabitEthernet1/0/4
!
interface Vlan1
ip address 192.168.10.2 255.255.255.0
!
interface Vlan20
ip address 192.168.20.1 255.255.255.0
!
ip classless
ip route 0.0.0.0 0.0.0.0 192.168.10.1
ip http server
ip http secure-server
!
!
!
line con 0
exec-timeout 0 0
password 7 121A0C041104
login
line vty 0 4
password 7 121A0C041104
login
line vty 5 15
password 7 121A0C041104
login
!
end

my Laptop IP is 192.168.20.2 255.255.255.0

my Server IP is  192.168.20.11 255.255.255.0

default gate is  192.168.20.1

I can access the internet from the router and when on the switch I can ping the router, the laptop, the server, and the internet but I cannot access the internet from the server or laptop I am able to ping the laptop from the server and the other way also.

On the router - 

"ip route 192.168.20.0 255.255.255.0 192.168.10.2"

Jon

It work I am connected thanks for all your help.