[Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

Cisco VLANS not quite seeing each other

Posted on 2011-04-25
4
Medium Priority
?
344 Views
Last Modified: 2012-05-11
I have 2 VLANS on a Cisco 881 and a Sonicwall TZ210.

Vlan A is 10.0.7.0

VLAN B is 10.0.8.0

Cisco 881:

VLAN A: 10.0.7.10

VLAN B: 10.0.8.11

Sonicwall

VLAN A: 10.0.7.249

VLAN B: 10.0.8.249

In between is 2950 Switches.  Both routers are configured as Trunks on the Switch.

Both subnets can ping each other usign all four IPs as gateways.

However, on both VLANS, we have a few webservers.  When connected to VLAN A as gateway (either the Sonicwall or Cisco) we can see everything we need to only on VLAN A but nothing on VLAN B.  I can ping VLAN B without any issue.

When I try VNC, RDP, or HTTP from VLAN A to B, I get timeout.  It works the same from VLAN B to VLAN A.

I think I may have an ACL issue, but I am not sure.

Thoughts on this?
0
Comment
Question by:rvdsabu4life
  • 2
  • 2
4 Comments
 
LVL 26

Expert Comment

by:Soulja
ID: 35459636
If you think it may be an acl issues. Please post a sanitized version so we can see, or remove it from the interfaces you have it applied to and see if you get communication. If so, then we know for sure it's the ACL. If not, then it is another configuration issue.
0
 

Author Comment

by:rvdsabu4life
ID: 35460167

!
!
!
!
!
!
interface FastEthernet0
 !
!
interface FastEthernet1
 !
!
interface FastEthernet2
 !
!
interface FastEthernet3
 switchport mode trunk
 !        
!
interface FastEthernet4
 description $ES_WAN$$ETH-WAN$
 ip address XXXWAN
 ip access-group 102 out
 ip nat outside
 ip virtual-reassembly
 duplex auto
 speed auto
 !
!
interface Vlan1
 description $ETH-SW-LAUNCH$$INTF-INFO-HWIC 4ESW$
 ip address 10.0.7.10 255.255.255.0
 ip nat inside
 ip virtual-reassembly
 ip tcp adjust-mss 1452
 !
!
interface Vlan2
 ip address 10.0.8.11 255.255.255.0
 ip nat inside
 ip virtual-reassembly
 !
!
ip default-gateway XXXWAN GATEWAY
no ip forward-protocol nd
ip http server
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
!
!
ip nat inside source list 1 interface FastEthernet4 overload
ip route 0.0.0.0 0.0.0.0 FastEthernet4
!
access-list 1 permit 10.0.7.0 0.0.0.255
access-list 2 permit 10.0.8.0 0.0.0.255
access-list 102 remark CCP_ACL Category=1
access-list 102 permit ip any any
no cdp run

0
 
LVL 26

Accepted Solution

by:
Soulja earned 2000 total points
ID: 35460294
Based on this:

access-list 1 permit 10.0.7.0 0.0.0.255
access-list 2 permit 10.0.8.0 0.0.0.255


You're only natting 10.0.7.0 network, because your nat overload command only references access list 1. Also, because you are using a standard acl, you can't specify what not to nat. Currenty if 10.0.7.0 tries to access 10.0.8.0 it will be natted out the wan interface.

Do the following:

ip access-list extended NAT
deny ip 10.0.7.0 0.0.0.255 10.0.8.0 0.0.0.255
deny ip 10.0.8.0 0.0.0.255 10.0.7.0 0.0.0.255
permit ip 10.0.7.0 0.0.0.255 any
permit ip 10.0.8.0 0.0.0.255 any

no ip nat inside source list 1 interface FastEthernet4 overload
ip nat inside source list NAT interface FastEthernet4 overload

no access-list 1 permit 10.0.7.0 0.0.0.255
no access-list 2 permit 10.0.8.0 0.0.0.255

0
 

Author Comment

by:rvdsabu4life
ID: 35688888
OK that worked from the Cisco gateway to the Sonicwall gateway.  

How do I configure the above in the Sonicwall?
0

Featured Post

Veeam and MySQL: How to Perform Backup & Recovery

MySQL and the MariaDB variant are among the most used databases in Linux environments, and many critical applications support their data on them. Watch this recorded webinar to find out how Veeam Backup & Replication allows you to get consistent backups of MySQL databases.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

How to set-up an On Demand, IPSec, Site to SIte, VPN from a Draytek Vigor Router to a Cyberoam UTM Appliance. A concise guide to the settings required on both devices
This article will show how Aten was able to supply easy management and control for Artear's video walls and wide range display configurations of their newsroom.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

865 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question