troubleshooting Question

CISCO 3560G switches allow Internet Gateways access across 2 seperate VLAN

Avatar of georgeong22
georgeong22 asked on
RoutersSwitches / HubsCisco
17 Comments2 Solutions655 ViewsLast Modified:
Hi Guys,

I have 2 CISCO 3560 switch which i need to configure 2 seperate VLAN,
i have configured 802.1q trunk for the connection between these 2 switch,
I have configured as follow for 3560 sw1:

Building configuration...

Current configuration : 3540 bytes
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log uptime
service password-encryption
!
no aaa new-model
!
ip subnet-zero
ip routing
!
!
!
no file verify auto
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
interface Port-channel1
 switchport trunk encapsulation dot1q
 switchport mode trunk
!
interface GigabitEthernet0/5
 switchport access vlan 5
!
interface Vlan1
 ip address 10.102.1.1 255.255.255.0
!
interface Vlan5
 ip address 10.102.2.1 255.255.255.0
!
interface GigabitEthernet0/52
 switchport trunk encapsulation dot1q
 switchport mode trunk
 channel-group 1 mode on
!
ip classless
ip route 0.0.0.0 0.0.0.0 10.102.1.254

The config for 3560 sw2 is only to enable 1 of the port for VLAN 5 as follow:
!
interface GigabitEthernet0/5
 switchport access vlan 5
!

My biggest problem is to enable internet access for users on VLAN 5.
As shown on the 3560 sw1 config - our gateway is 10.102.1.254.
users on VLAN 5 can access to each other machine & server on the 2 3560 switches.
But, they can't access internet through the gateway on VLAN 1.
 Is there any special routing rules to add for CISCO IOS to allow access to gateway bt at the same time preventing users from both VLAN to communicate?

Cheers





ASKER CERTIFIED SOLUTION
predragpetrovic

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 2 Answers and 17 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 2 Answers and 17 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros