Having Two Defualt gateways ???

Posted on 2009-02-12
Last Modified: 2012-06-27
Ok please bear with me here.

At the moment I have a single flat network as in the digram. What I would like to do is split it in to three seperate subnets. however my problem is that the Default gate way for the network currently is the router sitting off to the left of the digram.

Splitting up the networks is stright forward enough, and I now have three seperate networks as shown by the circles.

Red -
Green -
Blue -

However the router must stay on the same network (for the time being as the red network) so must have an address of for instance

All devices on the network currently use the switch in buildign 63, 142 or 153 as there default gateway. and can all happly talk to each other.

what I want to know is what settigns do i need to set on these switchs, so that they route any non site data to the WAN router on

Is this possible and if so how, I am just looking for a generic way to do this, If a core switch can't find a route to an IP address to forward it to the router.

We only need to do this as an intermediate step during the upgrade as we can't change the routers IP address, and some devices on the range need to keep there static IP address.

The idea is to segment the network, then sort out the servers and the last step will be sorting out the WAn routers.

I hope I have made it all clear but please ask if you need any more info.

Thank you Aaron
Question by:Aaron Street
    LVL 5

    Expert Comment

    are you using vlans to segregate the network? if yes then the router can hold sub interfaces and act as a gateway for all devices... no need to do any routing from the switches.

    or if you would really like to do routing functions on the switches, set each core switch to have an ip and set the hosts default gateway to be the switches (depending on which circle the host is in)- and then put static routes on the switches to go to the router for any and all traffic..

    this way all routing between networks is controlled via the router and all inter vlan communication get controlled by the router.

    is this sort of what your asking? im not totally sure thats what you meant!

    let me know..
    LVL 5

    Expert Comment

    fyi when i said "set each core switch" i was meaning each of the switches in the triangle is a core switch...

    i guess the main thing we need to know is how are you segregating the 3 ip ranges? are you actually using vlans?
    LVL 16

    Author Comment

    by:Aaron Street
    No I am not usign VLan's

    the links between buildings 63, 142 and 153 are seperate ip ranges,, and each Core switch is the default gate way for its own segment.

    I have set it up so that vlan 1 interface in the switch holds the Default gateway ip addess for that segment. then each have two ports that have an IP address assigened from the ranges, and each switch is running Eigrp for routing purposes.

    The digram I have show is only a small part of the network. in reality we will end up with about 15 - 20 segments and possible a lot more. So I want to keep routing local at the core switchs, rather than have one central router handeling it all.

    Also I can't make any changes to the router (we are a agency company and the router is managed externaly, it also has to meet very tight security and control, so making changes to it can take a long time and lots of paper work)

    the idea is to subnet up the network with out touching the router settings.

    basical if i gave the Router a new ipaddress say (out side of any current ranges) then this would be easy to set up, as I can set it on the routers as a gateway of last resort.

    however this does not seem to want to work if it is in the same range as the current switches..
    LVL 5

    Expert Comment


    if the switches are layer 3 switches or support vlan routing you could:

    set each core switch to have an ip on say vlan 1 (as you have done) lets say 192.168.x.10 / 24

    then add a vlan on each switch (lets say vlan 10) and give it ip range same as router, and (for each switch).

    if not i cant think of anything else... because each network segment, MUST have a default gateway residing on its subnet to get outside its own subnet and it must live on the same vlan too, as switches cant perfrom vlan routing between the .1.0 network and say the .3.0 network (unless theyre pretty decent switches)....

    i would strongly reccommend using vlans as this woudl give you more security and better segmentation and decrease network broadcasts...

    LVL 16

    Author Comment

    by:Aaron Street
    All network segment do have a Default gate way on its own subnet?

    And I dont want to do vlan here becasue of the number of them I would need to set up. We are looking at 100+ Cisco 3750 switchs and I will be using VLANS lower down to further devide the segments. But for the core links accross site I want to use pure ip routes.

    But you can set up routers with a gateway of last resort.

    I have done this before so that if the switch for building 63 for example does not have a route for a packet, rather than dropping it, it forwards it to the core switch in 142.

    now if I change the routers IP to an address that is not on the network I can set this as the gate way of last resort for the 142 switch all devices on the networrk can talk off site.

    however as soon as i try to do it with the router having the same IP range as the core switch in 142 it stops working.

    I fail to see how using vlans and a single router will reduce site traffic. By only using one router all traffic has to trave to the router and back to be routed. In my set up, traffic is routed at each of the core switchs and only travels the links it needs to.  Broadcast traffic is also limited to the indvual segments, and security is by far tight enough.

    The whole idea behind this is to get all client machines to have a local Default gateway (that of the core switch of there segment), and those core switchs need to be able to contact the router only if needed.

    I can't make a overnight change. so the ideas is to set this up on the core switchs and slowly move each building/segment over.

    The rest of the site works ok. all i need is how to make the core switch in the red segment (142) see the router as the destination for all packets that it dose not have a valid next hop address in its routing table?

    LVL 5

    Assisted Solution

    ok forget all the vlan stuff.. if you dont see the benfit i wont try and sell it to you...if you have designed the segments correctly the router wont be doing alot of routing but lets not go there...

    is the ip of the red switch 192.168.3.x /24 and does it have a static route (

    note that this default route will only apply if a more specifc route isnt available.

    LVL 16

    Accepted Solution


    Its ok I worked this out :) It was me being stupid!! I don't know how as I have removed and re-added the static route a number of time, but I noticed last night that i had one of the octect wrong!! Corrected that and it started working stright away!


    Cheers for all the ideas though, much appricated
    LVL 5

    Expert Comment

    ah so my static route above was incorrect then?

    Write Comment

    Please enter a first name

    Please enter a last name

    We will never share this with anyone.

    Featured Post

    Free camera licenses with purchase of My Cloud NAS

    Milestone Arcus software is compatible with thousands of industry-leading cameras for added flexibility. Upon installation on your My Cloud NAS, you will receive two (2) camera licenses already enabled in the software. And for a limited time, get additional camera licenses FREE.

    SSL is a very common protocol used these days when browsing the web.  The purpose is to provide security to communication, but how does it do it?  There are several pieces at work that have to be setup before SSL will even work and it requires both …
    Outsource Your Fax Infrastructure to the Cloud (And come out looking like an IT Hero!) Relative to the many demands on today’s IT teams, spending capital, time and resources to maintain physical fax servers and infrastructure is not a high priority.
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
    After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

    759 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    11 Experts available now in Live!

    Get 1:1 Help Now