cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
615
Views
0
Helpful
0
Replies

Vlan segregation

jbrickley2006
Level 1
Level 1

Hi guys,

can you have a layer 3 vlans routing lan traffic, then have a layer 2 vlan connected to a router thats connected to the internet and have all internet desting traffic going to the layer 2 vlan. I heard you can have this kind of set up to secure the lan. I tried to lab this up but couldn't get it to work. I have created 3 layer 3 vlans with ip routing enabled,l am able to ping to all vlans. I;ve then created a layer 2 vlan and added an access port connecting to the internet router. i am unable to ping the router. i cannot add routes into the routing table as its a layer 2 interface so no routes are being displayed when i try, is this a possible scenario? if so what do i need to do to resolve this.

I did try adding the ip default-gateway but i still cant ping the router. do i need to bridge the layer 2 and layer 3 vlans somehow?

i do a lshow ip route and there is no default gateway set what ever i try. unless i make the interface layer 3, if i make it layer 3 routes will be injected into the route table.

i'm sure this is possible please help !

 

 

 

0 Replies 0