Solved

IRB and VLANS on Cisco 3600 router and 3550 Switch

Posted on 2004-04-08
15
703 Views
Last Modified: 2012-05-04
Communications between VLANS is not working correctly...  Please look at this config and tell me if there is anything wrong?  Here is a diagram of the network..  http://www.aclod.com/ourlab2.doc

Router config:

no service config
service timestamps debug uptime
service timestamps log uptime
service password-encryption
!
hostname LAB_Router_1
!
boot system flash c3620-is-mz.122-5d.bin
no logging console
enable secret 5
!
ip subnet-zero
!
!
!
call rsvp-sync
!
interface FastEthernet0/0
 no ip address
 shutdown
!
interface Serial0/0
 no ip address
 shutdown
 clockrate 2000000
!
interface FastEthernet0/1
 no ip address
 speed auto
 full-duplex
!
!
interface FastEthernet0/1.2
 encapsulation isl 2
 ip address 192.168.90.2 255.255.255.128
 no ip redirects
!
interface FastEthernet0/1.3
 encapsulation isl 3
 ip address 192.168.90.129 255.255.255.224
 no ip redirects
!
interface FastEthernet0/1.4
 encapsulation isl 4
 ip address 192.168.90.193 255.255.255.240
 no ip redirects
!
interface FastEthernet0/1.5
 encapsulation isl 5
 ip address 192.168.90.209 255.255.255.240
 no ip redirects
!
interface FastEthernet0/1.6
 encapsulation isl 6
 ip address 192.168.90.225 255.255.255.240
 no ip redirects
!
interface FastEthernet0/1.7
 encapsulation isl 7
 ip address 192.168.90.241 255.255.255.240
 no ip redirects
!
interface Serial0/1
 no ip address
 shutdown
 clockrate 2000000
!
interface FastEthernet1/0
 no ip address
 shutdown
!
interface Serial1/0
 no ip address
 shutdown
 clockrate 2000000
!
interface FastEthernet1/1
 no ip address
 shutdown
!
interface Serial1/1
 no ip address
 shutdown
 clockrate 2000000
!
ip classless
ip route 0.0.0.0 0.0.0.0 192.168.90.1
ip http server
ip pim bidir-enable
!
snmp-server community Secomp RO
!
dial-peer cor custom
!
!
!
!
line con 0
line aux 0
line vty 0 4
 password
 login
!
end

Switch Config:

Lab_Switch_1#show config
Using 2592 out of 393216 bytes
!
version 12.1
no service single-slot-reload-enable
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname Lab_Switch_1
!
no logging console
enable secret  
enable password
!
!
vlan 2
!
vlan 3
!
vlan 4
!
vlan 5
!
vlan 6
!
vlan 7
ip subnet-zero
!
vtp mode transparent
!
spanning-tree portfast default
spanning-tree extend system-id
!
!
!
interface FastEthernet0/1
 switchport access vlan 2
 no ip address
!
interface FastEthernet0/2
 switchport access vlan 2
 no ip address
!
interface FastEthernet0/3
 switchport access vlan 2
 no ip address
!
interface FastEthernet0/4
 switchport access vlan 2
 no ip address
!
interface FastEthernet0/5
 switchport access vlan 2
 no ip address
!
interface FastEthernet0/6
 switchport access vlan 2
 no ip address
!
interface FastEthernet0/7
 switchport access vlan 2
 no ip address
!
interface FastEthernet0/8
 switchport access vlan 2
 no ip address
!
interface FastEthernet0/9
 switchport access vlan 2
 no ip address
!
interface FastEthernet0/10
 switchport access vlan 2
 no ip address
!
interface FastEthernet0/11
 switchport access vlan 2
 no ip address
!
interface FastEthernet0/12
 switchport access vlan 4
 no ip address
!
interface FastEthernet0/13
 switchport access vlan 4
 no ip address
!
interface FastEthernet0/14
 switchport access vlan 4
 no ip address
!
interface FastEthernet0/15
 switchport access vlan 5
 no ip address
!
interface FastEthernet0/16
 switchport access vlan 5
 no ip address
!
interface FastEthernet0/17
 switchport access vlan 5
 no ip address
!
interface FastEthernet0/18
 switchport access vlan 6
 no ip address
!
interface FastEthernet0/19
 switchport access vlan 6
 no ip address
!
interface FastEthernet0/20
 switchport access vlan 6
 no ip address
!
interface FastEthernet0/21
 switchport access vlan 7
 no ip address
!
interface FastEthernet0/22
 switchport access vlan 7
 no ip address
!
interface FastEthernet0/23
 switchport access vlan 7
 no ip address
!
interface FastEthernet0/24
 switchport trunk encapsulation isl
 switchport mode trunk
 no ip address
!
interface GigabitEthernet0/1
 no ip address
!
interface GigabitEthernet0/2
 no ip address
!
interface Vlan1
 no ip address
 shutdown
!
interface Vlan2
 ip address 192.168.90.3 255.255.255.128
!
ip default-gateway 192.168.90.1
ip classless
ip http server
!
!
!
line con 0
line vty 0 4
 password
 login
line vty 5 15
 password
 login
!
!
monitor session 1 source interface Fa0/9
monitor session 1 destination interface Fa0/16
end

Some example of problems are?:  90.243 PC cannot ping switch 90.3 but can ping 90.1 and 90.2.  
0
Comment
Question by:sbender99
  • 8
  • 7
15 Comments
 

Author Comment

by:sbender99
ID: 10784122
bump
0
 
LVL 28

Expert Comment

by:mikebernhardt
ID: 10785001
What exactly isn't working? 2 things I see though...
1. no switch ports are configured for vlan 3
2. Maybe the trunk isn't configured correctly- type "sho interface trunk" and make sure that all vlans are allowed on the trunk port of the 2950.
3. Just for cleanup, type "no full duplex" on router interface f0/1 so that it will properly auto-negotiate with the switch.
0
 

Author Comment

by:sbender99
ID: 10785059
90.194 cannot ping 90.210 and vice versa...

90.3 cannot be pinged from any vlan other than its own...

P.s. no ports are alotted to vlan 3 on purpose...no use for it yet...

Results from Show Interface Trunk command:

Lab_Switch_1#show interface trunk

Port      Mode         Encapsulation  Status        Native vlan
Fa0/24    on           isl            trunking      1

Port      Vlans allowed on trunk
Fa0/24    1-4094

Port      Vlans allowed and active in management domain
Fa0/24    1-7

Port      Vlans in spanning tree forwarding state and not pruned
Fa0/24    1-7
Lab_Switch_1#
0
Portable, direct connect server access

The ATEN CV211 connects a laptop directly to any server allowing you instant access to perform data maintenance and local operations, for quick troubleshooting, updating, service and repair.

 
LVL 28

Expert Comment

by:mikebernhardt
ID: 10785153
Dumb question, but are the subnet masks of the hosts set correctly?
0
 
LVL 28

Expert Comment

by:mikebernhardt
ID: 10785182
Oh- you will need to set the default gateway of the switch to 192.168.90.2 if you want to ping it from other subnets. The router will forward traffic out of your lab from the switch.
0
 

Author Comment

by:sbender99
ID: 10785185
set correctly where so I can verify?  As far as I know they are set correctly..but if you can think of somewhere I need to check I will...
0
 
LVL 28

Expert Comment

by:mikebernhardt
ID: 10785198
And... you're not using port 16 on the switch for a host, are you? It's set to monitor port 5
0
 
LVL 28

Expert Comment

by:mikebernhardt
ID: 10785230
On the hosts you are pinging from, check the IP configuration for correct subnet mask and default gateway. where depends on the operating system. You can use ipconfig on windows or ifconfig -a on unix to look at the current configuration. If the subnet mask is too big then they may not leave their subnet when you expect them to.
0
 

Author Comment

by:sbender99
ID: 10785279
the first vlan has their default gateway as 90.1
0
 

Author Comment

by:sbender99
ID: 10785282
or second in this case i guess
0
 
LVL 28

Expert Comment

by:mikebernhardt
ID: 10785377
All hosts need to be set with default gateway as the router interface they connect to. Then the router can route the traffic between them. Nobody but the router and the switch knows where 90.1 is. And 90.1 doesn't know where anyone but the router and switch and the outside world are.

If you want hosts to be able to talk to the outside world, set a route on the firewall pointing  to the router:
192.168.90.0 255.255.255.0 192.168.90.2

And make sure the world outside the firewall has a route to 192.168.9.0/24 pointing to the firewall's outside interface.
0
 

Author Comment

by:sbender99
ID: 10785404
so i should have all hosts on the VLAN2 network change their dfeault gateway to 90.2

and switch defualt gateway set to 90.2

and router default gateway set to 90.1
0
 
LVL 28

Accepted Solution

by:
mikebernhardt earned 500 total points
ID: 10785450
Yes.
0
 

Author Comment

by:sbender99
ID: 10785563
you da MAN!
0
 
LVL 28

Expert Comment

by:mikebernhardt
ID: 10785905
You're welcome!
0

Featured Post

Connect further...control easier

With the ATEN CE624, you can now enjoy a high-quality visual experience powered by HDBaseT technology and the convenience of a single Cat6 cable to transmit uncompressed video with zero latency and multi-streaming for dual-view applications where remote access is required.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
SIP / Streaming - real time communications testing 8 91
Home wifi - Does it matter what router? 9 54
Cisco ASA 5512-X Active/Standby HA 4 25
Dlink-DIR 816 router 4 20
We've been using the Cisco/Linksys RV042 for years as: - an internet Gateway - a site-to-site VPN device - a leased line site-to-site subnet-to-subnet interface (And, here I'm assuming that any RV0xx behaves the same way as an RV042.  So that's …
The Cisco RV042 router is a popular small network interfacing device that is often used as an internet gateway. Network administrators need to get at the management interface to make settings, change passwords, etc. This access is generally done usi…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question