Solved

VLAN Routing

Posted on 2011-03-23
5
648 Views
Last Modified: 2012-05-11
I have a Cisco 3550 router that is connected to a pix 515e that provides internet access.  
Pix 515e 10.39.128.1 inside interface connects to fastethernet0/17on my cisco 3550 switch.  II can ping the internet from a console cable attached to my switch throuh the pix but when I connect a PC to fastethernet0/17 of vlan 10 I cannot ping anything with my default gateway set to 10.39.129.9.  If I plug into a port in vlan1 I can ping all over the 10.39.127.x .  

Here is the topology, the customer ran out of ip addresses so we had to bring in another dsl connection.  I have two firewalls and am trying to tie the two networks together using the 3550 using vlans.  

pix 506e  (10.39.127.1)                  pix515e (10.39.128.1)
               |                                                     |
catalyst 2950 (10.39.127.8)          catalyst 3550 vlan1 10.39.127.6
                                                                             vlan 10 10.39.129.8
                                                                             fe 0/1 goes to Catalyst 2950 port fe0/22
                                                                             fe 0/17 goes to inside int pix515e

I' ve set my default gateway to the devices I want to access the internet via pix515e to 10.39.129.8 but I can't get outside.  The config for the Catalyst 2950 is as follows:
ip subnet-zero
!
!
spanning-tree mode pvst
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
!
!
!
interface FastEthernet0/1
!
interface FastEthernet0/2
!
interface FastEthernet0/3
!
interface FastEthernet0/4
!
interface FastEthernet0/5
!
interface FastEthernet0/6
!
interface FastEthernet0/7
!
interface FastEthernet0/8
!
interface FastEthernet0/9
!
interface FastEthernet0/10
!
interface FastEthernet0/11
!
interface FastEthernet0/12
!
interface FastEthernet0/13
!
interface FastEthernet0/14
!
interface FastEthernet0/15
!
interface FastEthernet0/16
!
interface FastEthernet0/17
 switchport access vlan 10
 switchport mode access
 switchport port-security
 switchport port-security aging time 2
 switchport port-security violation restrict
 switchport port-security aging type inactivity
 mls qos cos override
 macro description cisco-desktop
 spanning-tree portfast
 spanning-tree bpduguard enable
!
interface FastEthernet0/18
 switchport access vlan 10
 switchport mode access
 switchport port-security
 switchport port-security aging time 2
 switchport port-security violation restrict
 switchport port-security aging type inactivity
 mls qos cos override
 macro description cisco-desktop
 spanning-tree portfast
 spanning-tree bpduguard enable
!
interface FastEthernet0/19
 switchport access vlan 10
 switchport mode access
 switchport port-security
 switchport port-security aging time 2
 switchport port-security violation restrict
 switchport port-security aging type inactivity
 mls qos cos override
 macro description cisco-desktop
 spanning-tree portfast
 spanning-tree bpduguard enable
!
interface FastEthernet0/20
 switchport access vlan 10
 switchport mode access
 switchport port-security
 switchport port-security aging time 2
 switchport port-security violation restrict
 switchport port-security aging type inactivity
 mls qos cos override
 macro description cisco-desktop
 spanning-tree portfast
 spanning-tree bpduguard enable
!
interface FastEthernet0/21
 switchport access vlan 10
 switchport mode access
 switchport port-security
 switchport port-security aging time 2
 switchport port-security violation restrict
 switchport port-security aging type inactivity
 mls qos cos override
 macro description cisco-desktop
 spanning-tree portfast
 spanning-tree bpduguard enable
!
interface FastEthernet0/22
!
interface FastEthernet0/23
!
interface FastEthernet0/24
!
interface Vlan1
 ip address 10.39.127.8 255.255.255.0
 no ip route-cache
!
interface Vlan10
 no ip address
 no ip route-cache
 shutdown
!
ip http server




The config for the Cisco 3550 is as follows:

ip subnet-zero
ip routing
!
!
spanning-tree mode pvst
no spanning-tree optimize bpdu transmission
spanning-tree extend system-id
!
!
!
interface FastEthernet0/1
 description to 2950 switch
 switchport trunk encapsulation dot1q
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/2
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/3
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/4
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/5
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/6
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/7
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/8
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/9
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/10
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/11
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/12
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/13
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/14
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/15
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/16
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/17
 no switchport
 ip address 10.39.128.8 255.255.255.0
 mls qos cos override
 macro description cisco-desktop
 spanning-tree portfast
 spanning-tree bpduguard enable
!
interface FastEthernet0/18
 switchport access vlan 10
 switchport mode access
 switchport port-security
 switchport port-security aging time 2
 switchport port-security violation restrict
 switchport port-security aging type inactivity
 no ip address
 mls qos cos override
 macro description cisco-desktop
 spanning-tree portfast
 spanning-tree bpduguard enable
!
interface FastEthernet0/19
 switchport access vlan 10
 switchport mode access
 switchport port-security
 switchport port-security aging time 2
 switchport port-security violation restrict
 switchport port-security aging type inactivity
 no ip address
 mls qos cos override
 macro description cisco-desktop
 spanning-tree portfast
 spanning-tree bpduguard enable
!
interface FastEthernet0/20
 switchport access vlan 10
 switchport mode access
 switchport port-security
 switchport port-security aging time 2
 switchport port-security violation restrict
 switchport port-security aging type inactivity
 no ip address
 mls qos cos override
 macro description cisco-desktop
 spanning-tree portfast
 spanning-tree bpduguard enable
!
interface FastEthernet0/21
 switchport access vlan 10
 switchport mode access
 switchport port-security
 switchport port-security aging time 2
 switchport port-security violation restrict
 switchport port-security aging type inactivity
 no ip address
 mls qos cos override
 macro description cisco-desktop
 spanning-tree portfast
 spanning-tree bpduguard enable
!
interface FastEthernet0/22
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/23
 switchport mode dynamic desirable
 no ip address
!
interface FastEthernet0/24
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 1,10
 switchport mode trunk
 no ip address
!
interface GigabitEthernet0/1
 switchport mode dynamic desirable
 no ip address
!
interface GigabitEthernet0/2
 switchport mode dynamic desirable
 no ip address
!
interface Vlan1
 ip address 10.39.127.6 255.255.255.0
 no ip route-cache
 no ip mroute-cache
!
interface Vlan10
 ip address 10.39.129.8 255.255.255.0
!
ip classless
ip route 0.0.0.0 0.0.0.0 10.39.128.1
ip http server
!
I'm way over my head on this one and not sure what I need to do to go forward.  The goal is to communicate to the internet via the pix515e and allow specific traffic from the 10.39.127.x network access through that device
0
Comment
Question by:rogue028
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 2

Accepted Solution

by:
mwblsz earned 500 total points
ID: 35200289
ok, here is what I think:

you should use a seperate vlan to connect your asa515 to your sw3550. say vlan 10, then there is only two ports in this vlan10, ASA internal port and sw port that goes to ASA. the ip can be any internal ip like 10.39.128.x
then you can set up a new vlan, say vlan 11 to carry 10.39.129.x computers. and use interface vlan11 as the gateway, say 10.39.129.1.
on the sw, add a default route "ip route 0.0.0.0 0.0.0.0 10.39.128.1" if 10.39.128.1 is the internal port on asa515, this way, all internet traffic goes to ASA511, and all internal traffic will be inter-vlan traffic.

sincerely
0
 

Author Comment

by:rogue028
ID: 35200432
so change vlan 10 to be something like 10.39.128.x and set up a new vlan 11 and give it an ip like 1.39.129.x?  If I try to change vlan 10 it gives me an overlap with fe 0/17.  
0
 

Author Comment

by:rogue028
ID: 35201504
The    pix 506e provides internet access to the network .  I'm trying to get some devices to access the internet via the internet connection on the pix 515e.  
0
 

Author Comment

by:rogue028
ID: 35201736
found the issue.  I needed a route on my 515e back to my internal nework.  
0
 
LVL 2

Expert Comment

by:mwblsz
ID: 35201749
set up a new vlan, say vlan 11
and assign fe 0/17 to vlan 11
assign IP 10.39.128.2 to interface vlan 11

about two ASA, do you have 3550 connected to 2950? I did not see such connection on your topology. Please confirm

sincerely
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

In the world of WAN, QoS is a pretty important topic for most, if not all, networks. Some WAN technologies have QoS mechanisms built in, but others, such as some L2 WAN's, don't have QoS control in the provider cloud.
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Suggested Courses

726 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question