?
Solved

vlan issue

Posted on 2008-10-21
3
Medium Priority
?
246 Views
Last Modified: 2011-09-20
i have done vlan using cisco router and a cisco switch
encapsulation dot1.q used
vlan1, 192.168.1.1
vlan2, 192.168.2.1


i have linux firewall
eth1, 192.168.1.2

i added virtual ip to eth1.1 interface, 192.168.2.2

users can ping to 192.168.1.2, but cannot ping to 192.168.2.2

what might be the problem

i want to give access to vlan ip ranges using my linux box

i blv the issue is encapsulation issue
any ideas how to fix this?



0
Comment
Question by:ammadeyy2020
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 
LVL 16

Accepted Solution

by:
btassure earned 1000 total points
ID: 22765604
You need to configure the interface as a trunk and/or configure the subinterfaces into the vlans they represent.
See this article for more info:
http://www.linuxjournal.com/article/7268
0
 
LVL 5

Assisted Solution

by:sharedit
sharedit earned 1000 total points
ID: 22778529
Can I ask why you are not using the router to route between the two vlans?

I lack experience with this Linux Firewall Software, but typically Firewalls forward traffic through itself, they do not route back out the same interface packets come in on.

The Router is where i would be setting up traffic between the two Vlans. The firewall Isn't really going to do any routing for you, it is probably just going to be the default route for unknown traffic on your network.

I may be unclear as to how your network is setup.

On the switch port connected to router
config t
int f0/x
switchport mode trunk
switchport trunk encapsulation dot1q
switchport trunk native vlan 1
switchport trunk allowed vlan add 1,2
switchport nonegotiate

on the router port connected to the switch
config t
int e0/x.2  <------ i usually make the .x the number of the VALN. ie vlan2=.2 vlan20=.20 vlan34=.34 makes it less confusing
encapsulation dot1q 2
ip add x.x.x.x x.x.x.x (this should be the default route for Vlan 2)

where is dhcp coming from?

with that, if you put a port on the switch to access vlan2 an appropriately ip configured pc, in that port should be able to ping vlan 1

0
 

Author Closing Comment

by:ammadeyy2020
ID: 31508187
i added static route to firewall, and default route to router, it works fine
0

Featured Post

Efficient way to get backups off site to Azure

This user guide provides instructions on how to deploy and configure both a StoneFly Scale Out NAS Enterprise Cloud Drive virtual machine and Veeam Cloud Connect in the Microsoft Azure Cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This tutorial will go through the steps required to write a script that will back up the configuration settings of a HP-ProCurve switch. You will need to get the following things to follow this tutorial: Telnet Scripting Tool e.g. TST10.exe …
The DROP (Spamhaus Don't Route Or Peer List) is a small list of IP address ranges that have been stolen or hijacked from their rightful owners. The DROP list is not a DNS based list.  It is designed to be downloaded as a file, with primary intention…
If you're a developer or IT admin, you’re probably tasked with managing multiple websites, servers, applications, and levels of security on a daily basis. While this can be extremely time consuming, it can also be frustrating when systems aren't wor…
Michael from AdRem Software explains how to view the most utilized and worst performing nodes in your network, by accessing the Top Charts view in NetCrunch network monitor (https://www.adremsoft.com/). Top Charts is a view in which you can set seve…
Suggested Courses
Course of the Month15 days, 14 hours left to enroll

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question