cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1248
Views
0
Helpful
9
Replies

Enrutamiento entre Vlans Switch 3750

TI Almacontact
Level 1
Level 1

Hola

necesito colaboracion con el siguiente inconveniente que estoy presentando al configurar un switch CIsco Catalyst Capa 3 C3750-48TS-S

 

realice la creacion de 5 vlans: Vlan2, Vlan3, Vlan4, Vlan10, Vlan11

configuré el VTP, switch 3750 en modo server y 3 Switchs 2960 en modo cliente

Habilité el ip routing 

 

los equipos conectados a los switch 2960 todos tienen IP statica, 

 

la falla que presento es que no tengo conectividad entre ninguna de las vlans, puedo dar ping a los switch 2960 y al switch core 3750 pero al darle ping a un equipo que esta en otra vlan no me responde

 

dejo las configuraciones que he realizado en el switch 3750 (core) 

 

CO0002CL0001#show ip route
Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route

Gateway of last resort is not set

10.0.0.0/24 is subnetted, 4 subnets
C 10.97.19.0 is directly connected, Vlan11
C 10.97.18.0 is directly connected, Vlan4
C 10.97.17.0 is directly connected, Vlan3
C 10.97.16.0 is directly connected, Vlan2
105.0.0.0/24 is subnetted, 1 subnets
C 105.114.20.0 is directly connected, Vlan10

CO0002CL0001#show running-config
Building configuration...

Current configuration : 8922 bytes
!
version 12.2
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname CO0002CL0001
!
boot-start-marker
boot-end-marker
!
no logging console
enable secret 5 $1$PJMH$Se5U9oA8YsMeNl5ddCRGz/
!
username administrador privilege 15 password 0 Snhinit78
no aaa new-model
switch 1 provision ws-c3750-48ts
system mtu routing 1500
vtp interface vlan3
ip subnet-zero
ip routing
!
!
!
!
crypto pki trustpoint TP-self-signed-1666020352
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1666020352
revocation-check none
rsakeypair TP-self-signed-1666020352
!
!
crypto pki certificate chain TP-self-signed-1666020352
certificate self-signed 01
30820245 308201AE A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31363636 30323033 3532301E 170D3933 30333031 30303030
35345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 36363630
32303335 3230819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100BA8B 102499E3 A4ED9DF1 BE151C42 B795B11F AEDA4176 25E1C474 5A4528FA
BC858A23 76EA86D7 7DAF8B33 6946EC9B F0D6B7BC B2186911 B55E1FA2 554060D9
E8C36248 76E22BD0 30D154F2 440AA923 A0BC893D 4EBBB1A1 8EEBCC14 F9821DFE
AE175BA7 2ABFD6C3 E9F67004 75BC640F D540AC04 5C149AF3 DF8068C2 959B8221
1F430203 010001A3 6D306B30 0F060355 1D130101 FF040530 030101FF 30180603
551D1104 11300F82 0D434F30 30303243 4C303030 312E301F 0603551D 23041830
168014B7 47E4248E 17154229 1C8E101B E5F1E9FE 41C17130 1D060355 1D0E0416
0414B747 E4248E17 1542291C 8E101BE5 F1E9FE41 C171300D 06092A86 4886F70D
01010405 00038181 0078A384 2A011D63 5774DD83 31FA52A1 709121A7 E8210958
A0EA9ADD F059D39D 65E5B3DF D3155A34 8DBBEB57 A5D087C9 594BD0FB 775589FC
E09A40FD E1BEBDCB D14F0F9A 52D92BEF C223B00E ECAB5B7F A3CF3905 393D7016
B10AC001 BBE33A93 52429FE2 B07C0C65 9955BC10 E5A63AB2 064F6824 A2D72554
1A1DD7DA B524B78E EA
quit
!
!
!
!
!
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
!
!
!
interface Port-channel10
description CO0002AL0101
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
load-interval 30
!
interface Port-channel11
description CO0002AL0102
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
load-interval 30
!
interface Port-channel12
description CO0002AL0103
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
load-interval 30
!
interface Port-channel20
description CO0002FW0001
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
load-interval 30
!
interface FastEthernet1/0/1
description CO0002FW0001
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
logging event bundle-status
load-interval 30
channel-protocol pagp
channel-group 20 mode desirable

!
interface FastEthernet1/0/46
description CO0002AL0103
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
logging event bundle-status
load-interval 30
duplex full
channel-protocol pagp
channel-group 12 mode desirable
!
interface FastEthernet1/0/47
description CO0002AL0101
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
logging event bundle-status
load-interval 30
duplex full
channel-protocol pagp
channel-group 10 mode desirable
!
interface FastEthernet1/0/48
description CO0002AL0102
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
logging event bundle-status
load-interval 30
duplex full
channel-protocol pagp
channel-group 11 mode desirable

interface Vlan1
no ip address
!
interface Vlan2
description Data Center
ip address 10.97.16.1 255.255.255.0
ip access-group 120 in
!
interface Vlan3
description REDES
ip address 10.97.17.1 255.255.255.0
ip access-group 130 in
!
interface Vlan4
description TI
ip address 10.97.18.1 255.255.255.0
ip access-group 140 in
!
interface Vlan10
description LAN_SAMSUNG
ip address 105.114.20.1 255.255.255.0
ip access-group 110 in
!
interface Vlan11
description STAFF
ip address 10.97.19.1 255.255.255.0
ip access-group 150 in
!
ip classless
ip http server
ip http secure-server
!
!
access-list 110 permit ip any any
access-list 120 permit ip any any
access-list 130 permit ip any any
access-list 140 permit ip any any
access-list 150 permit ip any any
!
!
control-plane
!
!
line con 0
line vty 0 4
login local
transport input telnet
line vty 5 15
login
!
ntp source Vlan3
end

 

CO0002CL0001#show vtp status
VTP Version : running VTP1 (VTP2 capable)
Configuration Revision : 9
Maximum VLANs supported locally : 1005
Number of existing VLANs : 10
VTP Operating Mode : Server
VTP Domain Name : adc
VTP Pruning Mode : Enabled
VTP V2 Mode : Disabled
VTP Traps Generation : Disabled
MD5 digest : 0x26 0xAF 0x09 0xCD 0x25 0x49 0x6F 0x37
Configuration last modified by 10.97.17.1 at 4-15-93 13:36:40
Local updater ID is 10.97.17.1 on interface Vl3 (preferred interface)
Preferred interface name is vlan3

 

1 Accepted Solution

Accepted Solutions

Ok perfecto, 3 preguntas:

- Se observan las VLANs aprendidas por VTP y comparten la misma version de VTP (show vtp status) 

- Pueden las computadoras hace ping a sus gateways y a los de las otras VLANs.

- Las computadoras tienen algun antivirus activado o si puedes deshabilitar el firewall de window.

 

Saludos




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

View solution in original post

9 Replies 9

Mark Malone
VIP Alumni
VIP Alumni

Hi

I translated the below so hopefully it reads ok , check the l3 routing locally between vlans remove the acls for now , check the switch has correct default gateway and check the sh int trunk that all vlans are allowed and not blocked

 

 
si elimina las listas de acceso en las interfaces de vlan, puede hacer ping entre las interfaces de vlan ejemplo ping 10.97.16.1 fuente 10.97.17.1, eso es lo primero que debe verificarse es que el enrutamiento de IP funcione correctamente en el conmutador L3
si es así, compruebe las puertas de enlace y las subredes predeterminadas que se han asignado a las PC locales y asegúrese de que el conmutador tenga una puerta de enlace predeterminada para

¿Puedes publicar la configuración del interruptor? ¿Todos los vlans están 

When I Ping from the 3750 switch to the gateway, it responds ok
the configuration in the network card of the computer is correct
I eliminated the ACL from the vlan interfaces and I still have no answer between the different vlan

 

CO0002CL0001#ping 10.97.17.1

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.97.17.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
CO0002CL0001#ping 10.97.16.1

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.97.16.1, timeout is 2 seconds:
!!!!!

 

CO0002CL0001#sh int trunk

Port Mode Encapsulation Status Native vlan
Fa1/0/1 on 802.1q trunking 1
Po10 on 802.1q trunking 1
Po11 on 802.1q trunking 1
Po12 on 802.1q trunking 1

Port Vlans allowed on trunk
Fa1/0/1 1-4094
Po10 1-4094
Po11 1-4094
Po12 1-4094

Port Vlans allowed and active in management domain
Fa1/0/1 1-4,10-11
Po10 1-4,10-11
Po11 1-4,10-11
Po12 1-4,10-11

Port Vlans in spanning tree forwarding state and not pruned
Fa1/0/1 1-4,10-11
Po10 1,3
Po11 1,3,10
Po12 1,3
CO0002CL0001#

 

 

on the l3 switch ping 10.97.16.1 source 10.97.17.1
if that's working its not an intervlan routing issue as the switch is processing between the vlan interfaces

Not all your vlans are being forwarded in STP either on the last output of the sh int trunk , only fa1/0/1 is , is STP blocking those vlans on the ports

I removed STP from the configuration of the ports

I ping all the gateways from a computer and they answer ok
I also ping the IP addresses of the switches and the core switch and they respond well

but when I ping from a computer in vlan 11 (10.97.19.10) to another computer that is in vlan 4 (10.97.18.10) it does not respond

the configuration in the network cards of the computers is as follows:

Vlan11
IP: 10.97.19.10
MK: 255.255.255.0
DG: 10.97.19.1


Vlan4
IP: 10.97.18.10
MK: 255.255.255.0
DG: 10.97.18.1

 

The following is the configuration on the c3750 core switch:

CO0002CL0001#show interfaces trunk

Port Mode Encapsulation Status Native vlan
Fa1/0/1 on 802.1q trunking 1
Po10 on 802.1q trunking 1
Po11 on 802.1q trunking 1
Po12 on 802.1q trunking 1

Port Vlans allowed on trunk
Fa1/0/1 1-4094
Po10 1-4094
Po11 1-4094
Po12 1-4094

Port Vlans allowed and active in management domain
Fa1/0/1 1-4,10-11
Po10 1-4,10-11
Po11 1-4,10-11
Po12 1-4,10-11

Port Vlans in spanning tree forwarding state and not pruned
Fa1/0/1 1-4,10-11
Po10 1-4,10-11
Po11 1-4,10-11

Port Vlans in spanning tree forwarding state and not pruned
Po12 1-4,10-11
CO0002CL0001#

 

CO0002CL0001#show running-config
Building configuration...

Current configuration : 8802 bytes
!
version 12.2
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname CO0002CL0001
!
boot-start-marker
boot-end-marker
!
no logging console
enable secret 5 $1$PJMH$Se5U9oA8YsMeNl5ddCRGz/
!
username administrador privilege 15 password 0 Snhinit78
no aaa new-model
switch 1 provision ws-c3750-48ts
system mtu routing 1500
vtp interface vlan3
ip subnet-zero
ip routing
!
!
!
!
crypto pki trustpoint TP-self-signed-1666020352
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-1666020352
revocation-check none
rsakeypair TP-self-signed-1666020352
!
!
crypto pki certificate chain TP-self-signed-1666020352
certificate self-signed 01
30820245 308201AE A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31363636 30323033 3532301E 170D3933 30333031 30303030
35345A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D31 36363630
32303335 3230819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100BA8B 102499E3 A4ED9DF1 BE151C42 B795B11F AEDA4176 25E1C474 5A4528FA
BC858A23 76EA86D7 7DAF8B33 6946EC9B F0D6B7BC B2186911 B55E1FA2 554060D9
E8C36248 76E22BD0 30D154F2 440AA923 A0BC893D 4EBBB1A1 8EEBCC14 F9821DFE
AE175BA7 2ABFD6C3 E9F67004 75BC640F D540AC04 5C149AF3 DF8068C2 959B8221
1F430203 010001A3 6D306B30 0F060355 1D130101 FF040530 030101FF 30180603
551D1104 11300F82 0D434F30 30303243 4C303030 312E301F 0603551D 23041830
168014B7 47E4248E 17154229 1C8E101B E5F1E9FE 41C17130 1D060355 1D0E0416
0414B747 E4248E17 1542291C 8E101BE5 F1E9FE41 C171300D 06092A86 4886F70D
01010405 00038181 0078A384 2A011D63 5774DD83 31FA52A1 709121A7 E8210958
A0EA9ADD F059D39D 65E5B3DF D3155A34 8DBBEB57 A5D087C9 594BD0FB 775589FC
E09A40FD E1BEBDCB D14F0F9A 52D92BEF C223B00E ECAB5B7F A3CF3905 393D7016
B10AC001 BBE33A93 52429FE2 B07C0C65 9955BC10 E5A63AB2 064F6824 A2D72554
1A1DD7DA B524B78E EA
quit
!
!
!
!
!
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
!
!
!
interface Port-channel10
description CO0002AL0101
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
load-interval 30
!
interface Port-channel11
description CO0002AL0102
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
load-interval 30
!
interface Port-channel12
description CO0002AL0103
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
load-interval 30
!
interface Port-channel20
description CO0002FW0001
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
load-interval 30
!
interface FastEthernet1/0/1
description CO0002FW0001
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
logging event bundle-status
load-interval 30
channel-protocol pagp
channel-group 20 mode desirable
!
interface FastEthernet1/0/2
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/3
switchport mode access
!
interface FastEthernet1/0/4
switchport access vlan 2
switchport mode access
!
interface FastEthernet1/0/5
switchport access vlan 2
switchport mode access
!
interface FastEthernet1/0/6
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/7
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/8
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/9
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/10
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/11
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/12
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/13
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/14
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/15
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/16
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/17
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/18
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/19
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/20
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/21
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/22
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/23
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/24
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/25
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/26
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/27
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/28
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/29
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/30
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/31
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/32
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/33
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/34
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/35
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/36
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/37
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/38
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/39
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/40
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/41
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/42
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/43
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/44
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface FastEthernet1/0/45
switchport trunk encapsulation dot1q
switchport mode trunk
channel-protocol pagp
!
interface FastEthernet1/0/46
description CO0002AL0103
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
logging event bundle-status
load-interval 30
duplex full
channel-protocol pagp
channel-group 12 mode desirable
!
interface FastEthernet1/0/47
description CO0002AL0101
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
logging event bundle-status
load-interval 30
duplex full
channel-protocol pagp
channel-group 10 mode desirable
!
interface FastEthernet1/0/48
description CO0002AL0102
switchport trunk encapsulation dot1q
switchport mode trunk
logging event trunk-status
logging event bundle-status
load-interval 30
duplex full
channel-protocol pagp
channel-group 11 mode desirable
!
interface GigabitEthernet1/0/1
!
interface GigabitEthernet1/0/2
!
interface GigabitEthernet1/0/3
!
interface GigabitEthernet1/0/4
!
interface Vlan1
no ip address
!
interface Vlan2
description Data Center
ip address 10.97.16.1 255.255.255.0
!
interface Vlan3
description REDES
ip address 10.97.17.1 255.255.255.0
!
interface Vlan4
description TI
ip address 10.97.18.1 255.255.255.0
!
interface Vlan10
description LAN_SAMSUNG
ip address 105.114.20.1 255.255.255.0
!
interface Vlan11
description STAFF
ip address 10.97.19.1 255.255.255.0
!
ip classless
ip http server
ip http secure-server
!
!
access-list 110 permit ip any any
access-list 120 permit ip any any
access-list 130 permit ip any any
access-list 140 permit ip any any
access-list 150 permit ip any any
!
!
control-plane
!
!
line con 0
line vty 0 4
login local
transport input telnet
line vty 5 15
login
!
ntp source Vlan3
end

CO0002CL0001#

 

 

Hola, buenos dias,

Tienen las computadoras configurados default gateway?




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

los computadores si tienen configurado el Default Gateway

la tarjeta de red en el computador la configuro de la siguiente manera de acuerdo a la vlan configurada en el puerto del switch l2 2960

 

Vlan11
IP: 10.97.19.10
MK: 255.255.255.0
DG: 10.97.19.1


Vlan4
IP: 10.97.18.10
MK: 255.255.255.0
DG: 10.97.18.1

Ok perfecto, 3 preguntas:

- Se observan las VLANs aprendidas por VTP y comparten la misma version de VTP (show vtp status) 

- Pueden las computadoras hace ping a sus gateways y a los de las otras VLANs.

- Las computadoras tienen algun antivirus activado o si puedes deshabilitar el firewall de window.

 

Saludos




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

Deshabilité el firewall de windows en los equipos y ya me reponden a ping

 

no había caído en cuenta que el firewall de windows activado en los computadores bloquea el ping

 

ya tengo ping entre los equipos en diferentes vlan 

 

agradezco mucho por la ayuda 

 

saludos 

Fue un gusto mi amigo, ten un excelente dia.

 

Saludos 

:-)




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<
Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card