Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Vlans routing to internet

I have a scenario where I have created seperate vlans and using my switch as the default gateway. all vlans can route between each other but one vlan cant reach internet. The vlans are 1 and 3 and the address scheme is 10.0.35.0 on vlan 1 which can reach internet. The secondary vlan is 10.0.40.0 and cant reach internet. The firewall is on vlan 1

Any help would be greatly appreciated

8 REPLIES
Hall of Fame Super Blue

Re: Vlans routing to internet

Hi

Is there a route on your firewall to get back to Vlan 3 subnet 10.0.40.0 via the switch vlan 1 interface.

Your switch is definitely routing - yes ??

Jon

New Member

Re: Vlans routing to internet

yes there is, everything from the 10.0.40 network cant hit the internal interface of the firewall which is 10.0.35.243

there is a default route for 0.0.0.0 0.0.0.0 via 10.0.35.243

We have a another firwall, is there a chance i can set up policy based routing or access to route internet traffice via that firewall

thanks

Hall of Fame Super Blue

Re: Vlans routing to internet

Hi

Could you send a copy of the switch config and the firewall ( with any sensitive info removed ).

Jon

New Member

Re: Vlans routing to internet

switch config attached

Hall of Fame Super Silver

Re: Vlans routing to internet

mark

I have looked at the config that you posted. since you posted only part of the config there is a possibility that there is something in the part that you did not post that is influencing this behavior.

I note this in the config which I do not understand:

ip route 10.0.40.0 255.255.255.0 Vlan1

why do you have a static route for the address space of VLAN 3 pointing to VLAN 1?

Perhaps the larger question is why you have static routes defined for the address space of any of the VLANs?

I also note this in the config which seems incorrect:

access-list 100 permit tcp host 10.0.40.0 eq www host 10.0.36.4

this specifies the source address as host 10.0.40.0 which is the subnet address. So it is logically inconsistent. And since this appears to be the only statement in the access list, the access list would not permit any traffic through. Since you do not show how the access list is used we can not tell whether this is impacting your problem or not.

Based on the config it does look like VLAN 3 should be able to get to the firewall. If it can not get through the firewall then it looks like the issue may be on the firewall. As Jon suggested it may be an issue of whether the firewall has a route back to the 10.0.40.0 subnet. It might also be a question of the firewall rules and whether the firewall is permitting the traffic from VLAN 3 to go through, whether it is properly translating the traffic from VLAN 3, or some other similar issue.

Perhaps you can provide some more information about the firewall setup.

HTH

Rick

New Member

Re: Vlans routing to internet

The firewall is a checkpoint nokia and i have checked the logs and a host from the 10.0.40 is hitting the firewall ist just the addressspoofing that is coming up in the logs

Hall of Fame Super Silver

Re: Vlans routing to internet

Mark

Do I understand your post correctly that the firewall is denying the traffic from 10.0.40.x because of anti-spoofing? Have you figured out why the firewall thinks that these addresses are spoofed?

HTH

Rick

New Member

Re: Vlans routing to internet

You need a default route pointing at the network that the firewall is connected to. You will also need routes back to the VLAN interfaces from the firewall.

326
Views
0
Helpful
8
Replies
CreatePlease to create content