cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1933
Views
0
Helpful
8
Replies

Vlans routing to internet

mburguk1000
Level 1
Level 1

I have a scenario where I have created seperate vlans and using my switch as the default gateway. all vlans can route between each other but one vlan cant reach internet. The vlans are 1 and 3 and the address scheme is 10.0.35.0 on vlan 1 which can reach internet. The secondary vlan is 10.0.40.0 and cant reach internet. The firewall is on vlan 1

Any help would be greatly appreciated

8 Replies 8

Jon Marshall
Hall of Fame
Hall of Fame

Hi

Is there a route on your firewall to get back to Vlan 3 subnet 10.0.40.0 via the switch vlan 1 interface.

Your switch is definitely routing - yes ??

Jon

yes there is, everything from the 10.0.40 network cant hit the internal interface of the firewall which is 10.0.35.243

there is a default route for 0.0.0.0 0.0.0.0 via 10.0.35.243

We have a another firwall, is there a chance i can set up policy based routing or access to route internet traffice via that firewall

thanks

Hi

Could you send a copy of the switch config and the firewall ( with any sensitive info removed ).

Jon

switch config attached

mark

I have looked at the config that you posted. since you posted only part of the config there is a possibility that there is something in the part that you did not post that is influencing this behavior.

I note this in the config which I do not understand:

ip route 10.0.40.0 255.255.255.0 Vlan1

why do you have a static route for the address space of VLAN 3 pointing to VLAN 1?

Perhaps the larger question is why you have static routes defined for the address space of any of the VLANs?

I also note this in the config which seems incorrect:

access-list 100 permit tcp host 10.0.40.0 eq www host 10.0.36.4

this specifies the source address as host 10.0.40.0 which is the subnet address. So it is logically inconsistent. And since this appears to be the only statement in the access list, the access list would not permit any traffic through. Since you do not show how the access list is used we can not tell whether this is impacting your problem or not.

Based on the config it does look like VLAN 3 should be able to get to the firewall. If it can not get through the firewall then it looks like the issue may be on the firewall. As Jon suggested it may be an issue of whether the firewall has a route back to the 10.0.40.0 subnet. It might also be a question of the firewall rules and whether the firewall is permitting the traffic from VLAN 3 to go through, whether it is properly translating the traffic from VLAN 3, or some other similar issue.

Perhaps you can provide some more information about the firewall setup.

HTH

Rick

HTH

Rick

The firewall is a checkpoint nokia and i have checked the logs and a host from the 10.0.40 is hitting the firewall ist just the addressspoofing that is coming up in the logs

Mark

Do I understand your post correctly that the firewall is denying the traffic from 10.0.40.x because of anti-spoofing? Have you figured out why the firewall thinks that these addresses are spoofed?

HTH

Rick

HTH

Rick

ciscopower
Level 1
Level 1

You need a default route pointing at the network that the firewall is connected to. You will also need routes back to the VLAN interfaces from the firewall.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: