• Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 2732
  • Last Modified:

Configuring two vlans on Cisco 877w router

Hi,

Can anyone explain step-by-step how to configure two vlans on cisco 877w router, and be able to ping between hosts on both vlans, and be able too, to ping between vlans interfaces on the router?.

Cisco IOS Software, C870 Software (C870-ADVIPSERVICESK9-M), Version 15.1(2)T1, R

Appreciate your help.
0
arefone
Asked:
arefone
  • 14
  • 10
  • 3
1 Solution
 
fgasimzadeCommented:
0
 
arefoneAuthor Commented:
Those instructions are not good for the router I mentioned.
0
 
fgasimzadeCommented:
why?
0
VIDEO: THE CONCERTO CLOUD FOR HEALTHCARE

Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

 
arefoneAuthor Commented:
Because my router is a SOHO one, I got this error:

SOHO-R1(config)#interface FastEthernet 3.1
                                               ^
% Invalid input detected at '^' marker.
0
 
arefoneAuthor Commented:
the "^" is located under the "F" of FastEthernet
0
 
fgasimzadeCommented:
Do

Show run

See what kind of interfaces you have
0
 
arefoneAuthor Commented:
Interface                  IP-Address      OK? Method Status                Protocol
ATM0                       unassigned      YES NVRAM  administratively down down
BVI1                       xxx.xxx.xxx.xxx   YES NVRAM  up                    up
Dialer1                    unassigned      YES NVRAM  up                    up
Dot11Radio0                unassigned      YES NVRAM  up                    up
FastEthernet0              unassigned      YES unset  up                    up
FastEthernet1              unassigned      YES unset  up                    down
FastEthernet2              unassigned      YES unset  up                    down
FastEthernet3              unassigned      YES unset  up                    down
NVI0                       xxx.xxx.xxx.xxx   YES unset  up                    up
Virtual-Access1            unassigned      YES unset  up                    up
Vlan1                      unassigned      YES NVRAM  up                    up
0
 
Syed_M_UsmanCommented:
Dear,

try this

logon to cisco 877 with FULL ACCESS

877>
enable
877#config terminal

(config)# vlan database
(config-vlan)# vlan 10 name Server
(config-vlan)# vlan 20 name Client
(config-vlan)# exit

877#config terminal
(config)# interface FastEthernet1
(config-if)# switchport mode access
 (config-if)# switchport access vlan 10
 (config-if)# exit
exit


877#config terminal
(config)# interface FastEthernet2
(config-if)# switchport mode access
 (config-if)# switchport access vlan 20
 (config-if)# exit

exit

test and if you want to save simply type below

877#wr mem
0
 
arefoneAuthor Commented:
Hi Syed,

Thats it! it worked!

Should I configure a trunk port on the router to make the two vlans on the switch to comunicate between them?
0
 
Syed_M_UsmanCommented:
Thanks for the comments....
better to Make trunk...
0
 
arefoneAuthor Commented:
one more question Syed, can you explain how to apply access lists between the vlans on the router?
0
 
Syed_M_UsmanCommented:
post you VLAN number and IP Address, i will try to post full configuration for you....
0
 
arefoneAuthor Commented:
VLAN10 - 192.168.0.253
VLAN20 - 192.168.20.253
0
 
arefoneAuthor Commented:
I am confused in the directions, for example, if I want to block the access to the VLAN10 to all except one host, have I apply the access list in the "in" or "out" direction?
0
 
Syed_M_UsmanCommented:
please send me "SANITIZED" configuration...
and let me know what you want...
Cisco 877 support web interface... try to put https://yourcisco877vlan1ip in your browser.
0
 
arefoneAuthor Commented:
Ok,

I want to block hosts on VLAN20 from accessing to VLAN10, as I told you, I am confused about the direction in which I have to apply the acls.

What sanitized configuration do you need ya basha?
0
 
Syed_M_UsmanCommented:
Dear,

VLANs provide communication to HOST and not the ACL/FW....
ACL are used to provide limited access from WAN>LAN or LAN to WAN.
0
 
arefoneAuthor Commented:
But you can use then even between vlans, isn't?
0
 
Syed_M_UsmanCommented:
once you enable ip routing or INTER VLAN ROUTING all vlans are accesable... this is why SA use VLAN...
0
 
arefoneAuthor Commented:
Hi Syed, its all clearer now, thanks again.

Ps: enta men ay balad?, ana 3arabi men felesteen!
0
 
Syed_M_UsmanCommented:
You are welcome...
apart from your ACL question i was doing a test in my LAB... you can put ACL with VLANS also from LAN to LAN but you may need to open ports eg...

DNS
HTTPS
HTTP
ICMP
..........
0
 
arefoneAuthor Commented:
What I'm trying to do is:
1. Block any traffic from VLAN B to VLAN A
2. Block any traffic except http, https, messengers app from VLAN B to internet

I think I'm at a good point right now.
0
 
Syed_M_UsmanCommented:
Dear,
you are right...
http://www.cisco.com/en/US/tech/tk648/tk361/technologies_configuration_example09186a0080100548.shtml

if you need more help please make new question so other Experts can also participate.
0
 
arefoneAuthor Commented:
Great link thank you.

Shukran Syed.
0
 
Syed_M_UsmanCommented:
You are Welcome.....:)
0
 
arefoneAuthor Commented:
Syed, may I ask you your email address?
0
 
Syed_M_UsmanCommented:
smusman@alubafbank.com
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

  • 14
  • 10
  • 3
Tackle projects and never again get stuck behind a technical roadblock.
Join Now