?
Solved

Firewall training lab with layer 3 switch

Posted on 2012-12-26
5
Medium Priority
?
565 Views
Last Modified: 2013-08-16
Hello all,

I would like to set a firewall training lab in my lab environment.
Materials i have ;
2 Fortinet 60C utm device
1 HP 2910al switch
2 PC with 2 Network Card

The Internet gateway will be 172.16.20.1

switch config
============
hostname "utm_lab"
module 1 type J9145A
ip routing   >>>>>>>> i have to run this command for inter vlan comm ?
vlan 1
   name "DEFAULT_VLAN"
   untagged 6-24
   no untagged 1-5
   no ip address
   exit
vlan 10
   name "VLAN10"
   untagged 1
   ip address 10.0.10.254 255.255.255.0
   exit
vlan 20
   name "VLAN20"
   untagged 2
   ip address 10.0.20.254 255.255.255.0
   exit
vlan 30
   name "VLAN30"
   untagged 3
   ip address 10.0.30.254 255.255.255.0
   exit
vlan 40
   name "VLAN40"
   untagged 4
   ip address 10.0.40.254 255.255.255.0
   exit
vlan 50
   name "VLAN50"
   untagged 5
   ip address 172.16.20.254 255.255.255.0
   exit
ip route 0.0.0.0 0.0.0.0 172.16.20.1  >>> any dest. if  dont know the route


UTM 1
======
wan1 : 10.0.10.1/24
wan2 : 10.0.20.1/24
int     : 10.0.100.1 / 24

UTM 2
=====
wan1 : 10.0.30.1 /24
wan2 : 10.0.40.1 /24
int     : 10.0.200.1 /24

From 10.0.100.254 ( windows2008r2 ) PC i can reach to all vlan (10-50) but can't reach to 172.16.20.1 , what is wrong in this config ? any idea
How can i use my device to create a useful lab area in other way ?
Thanks
0
Comment
Question by:ata1915
  • 4
5 Comments
 
LVL 1

Author Comment

by:ata1915
ID: 38720841
0
 
LVL 9

Expert Comment

by:Sandeep Gupta
ID: 38721065
can you please put your default route like:

ip route 0.0.0.0 0.0.0.0 vlan 50 172.16.20.1

also do you see your gateway ip 172.16.20.1 in arp table ?
0
 
LVL 1

Author Comment

by:ata1915
ID: 38729987
I was testing this lab with HP 2620 and wrote <ip routing> command
but i didnt get any vlan interface ip add. on the  arp table with this switch.
Then changed it to HP2910al and again write the <ip routing> command and it works now.
I didnt figure out why this lab didnt worked with HP2620 switch.
0
 
LVL 1

Accepted Solution

by:
ata1915 earned 0 total points
ID: 39401119
i have achievement this task with  opensource switch :)
http://openvswitch.org/
0
 
LVL 1

Author Closing Comment

by:ata1915
ID: 39413899
easy to deploy
0

Featured Post

Free Tool: ZipGrep

ZipGrep is a utility that can list and search zip (.war, .ear, .jar, etc) archives for text patterns, without the need to extract the archive's contents.

One of a set of tools we're offering as a way to say thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

WARNING:   If you follow the instructions here, you will wipe out your VTP and VLAN configurations.  Make sure you have backed up your switch!!! I recently had some issues with a few low-end Cisco routers (RV325) and I opened a case with Cisco TA…
How to fix a SonicWall Gateway Anti-Virus firewall blocking automatic updates to apps like Windows, Adobe, Symantec, etc.
Is your data getting by on basic protection measures? In today’s climate of debilitating malware and ransomware—like WannaCry—that may not be enough. You need to establish more than basics, like a recovery plan that protects both data and endpoints.…
When cloud platforms entered the scene, users and companies jumped on board to take advantage of the many benefits, like the ability to work and connect with company information from various locations. What many didn't foresee was the increased risk…
Suggested Courses
Course of the Month16 days, 7 hours left to enroll

862 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question