Unable to access web or internal IMAP from VLAN 2 on Cisco Catalyst Switches

Posted on 2008-10-20
Last Modified: 2012-06-21
We recently reconfigured our network with 2 VLANS for our new VoIP system.  We installed the voicemail server on the voice VLAN, VLAN 2, and we are unable to telnet to IMAP on the internal Exchange server for integrated messaging from this voicemail server.  In addition, we are unable to access the web from machines on VLAN 2.  We appear to have inter-VLAN routing setup correctly, though I am not sure.

We are able to ping everything from every network just fine.  Even a tracert to works from VLAN 2, however, the web page is never returned to the browser following the DNS request.  If we put the voicemail server onto VLAN 1, it can telnet the IMAP on the Exchange server fine.

Any ideas?

Netscreeen SSG140 -->  Cisco Catalyst 3560 G (Acting as L3 router)

Default GW:  VLAN 1:

                       VLAN 2:

                       ip route

-->  2nd Cisco Catalyst 3560  VLAN 1:

                              VLAN 2:

                              ip default-gateway:

Open in new window

Question by:wega1985
  • 3
  • 3
LVL 10

Accepted Solution

kyleb84 earned 500 total points
ID: 22763825
I'm guessing the Netscreeen is

The "3560G" should have this route:
ip route

And this command should be present:
ip routing

The Netscreen should have this route:
Network: via

The 2nd 3560 shouldn't be doing VLAN routing at all, and it's Vlan2 interface needs a 10.0.1.X/24 ip address - not a address that belong one Vlan1 VLAN

Every device on the Vlan1 VLAN should have a Default Gateway of
Every device on the Vlan2 VLAN should have a Default Gateway of

Only the 1st 3560G should have a ip route of as mentioned above.

The uplink between these two switches should be a trunk on both sides:

interface XXX
 switchport mode trunk
 switchport trunk allowed vlan 1,2
 switchport trunk encapsulation dot1q
 switchport trunk native vlan 1

Where XXX is the switches uplink interface to the other switch, this applies to both switches.


Author Comment

ID: 22766482
Great answer.  I double checked my configs and all looked good except for some trunk commands.  I forgot to change the default gateway on the Exchange server to, so now the IMAP issue is resolved.
However, I still can't access the Internet from VLAN 2.  IE is stuck on "connecting to [IP address of site]"
LVL 10

Expert Comment

ID: 22782936
So on that VLAN 2 PC:
- It's IP address is 10.0.1.X, netmask of
- It's default gateway is
- It has a DNS server configured?
- It can ping
- It can ping
- It can ping
- It can ping it's DNS server?
Zoho SalesIQ

Hassle-free live chat software re-imagined for business growth. 2 users, always free.


Author Comment

ID: 22785215
Yes to all.
LVL 10

Expert Comment

ID: 22791128
Ok, weird...

- Does it resolve DNS properly?
- Can you ping the ISP's default gateway (or any other internet IP)?
- Can it ping

If all the internal routing is ok (as you've confirmed above). I'm wondering whether its a DNS issue or a problem with your Netscreen....

Author Comment

ID: 22811614
Yes again.  I suspect the issue is with some blocking in the Netscreen, though I'm not sure what.  Possibly an additional policy is needed.

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Hello to you all, I hear of many people congratulate AWS (Amazon Web Services) on how easy it is to spin up and create new EC2 (Elastic Compute Cloud) instances, but then fail and struggle to connect to them using simple tools such as SSH (Secure…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

911 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now