cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
297
Views
0
Helpful
7
Replies

VLan on L2 Switches Cannot Get to Internet

pmac14
Level 1
Level 1

I have a 9200L as a core switch, with 5 other switches attached by 10GigEthernet cables.  I cannot seem to get to the internet for all but the primary VLan on any of the other 9200L switches.  Please help. 

7 Replies 7

Torbjørn
VIP
VIP

Hello @pmac14,

You will have to provide us with some more information:

  1. What does your topology look like?
  2. Can you show us the relevant device configurations? 
Happy to help! Please mark as helpful/solution if applicable.
Get in touch: https://torbjorn.dev

pieterh
VIP
VIP

as @Torbjørn already mentioned, more information about the topology will help!

that said, a question: has it worked before?
if not, first check if the other vlans'are routed correctly and included in NAT and ACL rules on the router/firewall connecting to the internet, especially does this router know the route back to these vlan's

>>> VLan on L2 Switches  <<<
if the switches really are L2 only then there is no routing between the vlan's and between vlan en interface connecting to the internet
-> you need to add routing configuration externally

Martin L
VIP
VIP

maybe for security reasons only primary VLan is allowed to go out on the Internet? what has changed recently ?

Regards, ML
**Have fun labbing!!!***
***Please Rate All Helpful Responses ***

Hello pmcbride,

    As some of the other user have mentioned more information would provide a better understanding of the issue. If only one switch is getting connected to the internet, and the others aren't, maybe they aren't trunked in their link back to the core switch? Or it could be a security issue as Martin L stated.

It seems we could only provide speculation with the current layout.

pmac14
Level 1
Level 1

We are currently running three Vlans.  Attached is drawing showing connection and ports connecting.  All those ports should be trunked, correct? 

Drawing.jpg

Correct, these ports should be Trunk ports. Trunk ports are used between switches to networking devices. 

Switch to switch

Or

Switch to router

Without Trunks configured on the connected interfaces, there won't be any communication through those interfaces.

pieterh
VIP
VIP

and what subnets are used for vlan 70,71,72 ?
and evenso important, who does the routing between those vlans and de vlan with subnet 192.168.0.0/24 ? (core or sophos?)