Problem Routing to VLANS to get Internet Access

bigdog5150
bigdog5150 used Ask the Experts™
on
Good Morning,

I was tasked with setting up a QA lab with two vlans.VLAN 190: 10.201.1.0/24 and 10.201.2.0/24. There is a Domain Controller in each vlan (Please see attached Visio diagram). Each VLAN has its' own dedicated switch that connects to a port on the Cisco 3560G, each configured with a gateway address for each subnet. The 3560G also serves as the default gateway, forwarding requests to the ASA. Here is the problem. Neither VLAN can hit the internet.

Attached, find:
- A Visio diagram of the basic connectivity
- Core Switch Config
- ASA Firewall Config

Thanks in advance for your assistance.

Jim
Qalab.vsd
ASA-Config.txt
Switch01-Config.txt
Comment
Watch Question

Do more with

Expert Office
EXPERT OFFICE® is a registered trademark of EXPERTS EXCHANGE®
Head of IT Security Division
Top Expert 2010
Commented:
Hi,

This lines aree need on ASA:

access-list nat-acls extended permit ip 10.201.0.0 255.255.255.0 any
access-list nat-acls extended permit ip 10.202.0.0 255.255.255.0 any
no route inside 10.201.1.0 255.255.255.0 172.16.30.1 1
route inside 10.201.1.0 255.255.255.0 172.16.30.254 1
route inside 10.202.1.0 255.255.255.0 172.16.30.254 1

Author

Commented:
Thanks I will give that a shot this afternoon.

Jim

Author

Commented:
ikalmar,

Had to make some changes to your solution, but it works fine! Thank you!

Jim

Author

Commented:
Just a couple of changes to the subnets. The theory was complete and it makes perfect sense.
Istvan KalmarHead of IT Security Division
Top Expert 2010

Commented:
Your welcome:)

Do more with

Expert Office
Submit tech questions to Ask the Experts™ at any time to receive solutions, advice, and new ideas from leading industry professionals.

Start 7-Day Free Trial