Solved

Firewall training lab with layer 3 switch

Posted on 2012-12-26
5
522 Views
Last Modified: 2013-08-16
Hello all,

I would like to set a firewall training lab in my lab environment.
Materials i have ;
2 Fortinet 60C utm device
1 HP 2910al switch
2 PC with 2 Network Card

The Internet gateway will be 172.16.20.1

switch config
============
hostname "utm_lab"
module 1 type J9145A
ip routing   >>>>>>>> i have to run this command for inter vlan comm ?
vlan 1
   name "DEFAULT_VLAN"
   untagged 6-24
   no untagged 1-5
   no ip address
   exit
vlan 10
   name "VLAN10"
   untagged 1
   ip address 10.0.10.254 255.255.255.0
   exit
vlan 20
   name "VLAN20"
   untagged 2
   ip address 10.0.20.254 255.255.255.0
   exit
vlan 30
   name "VLAN30"
   untagged 3
   ip address 10.0.30.254 255.255.255.0
   exit
vlan 40
   name "VLAN40"
   untagged 4
   ip address 10.0.40.254 255.255.255.0
   exit
vlan 50
   name "VLAN50"
   untagged 5
   ip address 172.16.20.254 255.255.255.0
   exit
ip route 0.0.0.0 0.0.0.0 172.16.20.1  >>> any dest. if  dont know the route


UTM 1
======
wan1 : 10.0.10.1/24
wan2 : 10.0.20.1/24
int     : 10.0.100.1 / 24

UTM 2
=====
wan1 : 10.0.30.1 /24
wan2 : 10.0.40.1 /24
int     : 10.0.200.1 /24

From 10.0.100.254 ( windows2008r2 ) PC i can reach to all vlan (10-50) but can't reach to 172.16.20.1 , what is wrong in this config ? any idea
How can i use my device to create a useful lab area in other way ?
Thanks
0
Comment
Question by:ata1915
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
5 Comments
 
LVL 1

Author Comment

by:ata1915
ID: 38720841
0
 
LVL 9

Expert Comment

by:Sandeep Gupta
ID: 38721065
can you please put your default route like:

ip route 0.0.0.0 0.0.0.0 vlan 50 172.16.20.1

also do you see your gateway ip 172.16.20.1 in arp table ?
0
 
LVL 1

Author Comment

by:ata1915
ID: 38729987
I was testing this lab with HP 2620 and wrote <ip routing> command
but i didnt get any vlan interface ip add. on the  arp table with this switch.
Then changed it to HP2910al and again write the <ip routing> command and it works now.
I didnt figure out why this lab didnt worked with HP2620 switch.
0
 
LVL 1

Accepted Solution

by:
ata1915 earned 0 total points
ID: 39401119
i have achievement this task with  opensource switch :)
http://openvswitch.org/
0
 
LVL 1

Author Closing Comment

by:ata1915
ID: 39413899
easy to deploy
0

Featured Post

Is your NGFW recommended by NSS Labs?

Ours is! NSS Labs Next Generation Firewall Test gives the WatchGuard Firebox M4600 a "Recommended" rating! Curious where your NGFW landed on the  Security Value Map? See the map and download the full report today!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This article will step through configuring a SonicWALL appliance to utilize an internal DHCP server for Global VPN Client (GVC) hosts.  There are times when using an external (external to the SonicWALL) DHCP server, such as Windows Servers, isn’t pr…
I found an issue or “bug” in the SonicOS platform (the firmware controlling SonicWALL security appliances) that has to do with renaming Default Service Objects, which then causes a portion of the system to become uncontrollable and unstable. BACK…
This is a high-level webinar that covers the history of enterprise open source database use. It addresses both the advantages companies see in using open source database technologies, as well as the fears and reservations they might have. In this…
In this video, viewers are given an introduction to using the Windows 10 Snipping Tool, how to quickly locate it when it's needed and also how make it always available with a single click of a mouse button, by pinning it to the Desktop Task Bar. Int…

695 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question