Solved

Inter Vlan routing

Posted on 2008-10-20
5
292 Views
Last Modified: 2008-10-21
ok..heres my prob.
i have a block of public IP's from the ISP(naturally)  i was wondering if there was a way i could possibly block like 15 ports off and put them in a vlan specifically for these IP's and then allow access to that Vlan from other vlans?  How would i go about that..thanks again in advance
0
Comment
Question by:jasonmichel
  • 3
  • 2
5 Comments
 
LVL 10

Expert Comment

by:kyleb84
ID: 22763699
Um, my crystal ball is out of batteries :P

What brand/model switch/router have you got?
0
 
LVL 1

Author Comment

by:jasonmichel
ID: 22763745
dell 6200 switches stacked with 10g kit and cisco router with 12.4 ios..
0
 
LVL 10

Accepted Solution

by:
kyleb84 earned 500 total points
ID: 22763928
Say you've already got 2 VLANs VLAN 1 (Data) and VLAN 2 (Voice), and you want grab 15 ports and chuck em in a new VLAN (Lets call it 3, Public).

VLAN 1 - 10.1.0.0/24
VLAN 2 - 10.2.0.0/24
VLAN 3 - 210.200.30.X/27 (For example)

Dell 6200 - Example config:
- Ports 1 - 15 are VLAN 3 only
- Ports 16-23 are in VLAN 1 only
- Port 24 is the uplink to the Cisco
- Just apply the port 24 setting to the 10g uplinks for inter-switch connectivity.

vlan database
 vlan 1,2,3
exit
interface ethernet 1/g24
 switchport mode general
 switchport general allowed vlan add 2,3 tagged
 switchport general pvid 1
 exit
interface range Ethernet 1/g1-1/g15
 switchport access vlan 3
 exit
interface range Ethernet 1/g16-1/g23
 switchport access vlan 1
 exit

Cisco uplink to the switch:
interface XXX
 switchport mode trunk
 switchport trunk encapsulation dot1q
 switchport trunk native 1
!
interface Vlan1
 ip address 10.1.0.1/24
interface Vlan2
 ip address 10.2.0.1/24
interface Vlan3
 ip address 210.200.30.x/27
!
ip routing
!

The default gateway for VLAN1 is 10.1.0.1
The default gateway for VLAN2 is 10.2.0.1
The default gateway for VLAN3 is (The Cisco Router's VLAN 3 interface)

----------------------------

You could make the Dell's do the routing instead if you wish, but that's as far as I go with Dell, the rest I'm is basically Web config, and cannot be shown easily with words.

Try here: http://support.dell.com/support/edocs/network/pc62xx/en/UG/HTML/configue.htm#wp1185290

0
 
LVL 1

Author Comment

by:jasonmichel
ID: 22764037
would there have to be some type of default route statement so that the other 2 vlans know that vlan 3 is the exit destination for 0.0.0.0 (or in this case inet?)
0
 
LVL 10

Expert Comment

by:kyleb84
ID: 22764080
If your Cisco was doing the routing, it would have a:

 ip route 0.0.0.0 0.0.0.0 [ISP's GW IP]

As long as each device on each VLAN had a default gateway of the Cisco, they all would have internet access, and they (each VLAN) all could talk to each other.

0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

9 Experts available now in Live!

Get 1:1 Help Now