Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Difficulty setting up VLANs with SG300-28 and ISA550

I am trying to do the following:

SG300-20 segmented into 4 VLANs - call them "clients", "servers" and "printers" along with the default VLAN that already exists on the SG300 at startup. SG300 is already in Layer 3 mode with a virgin (reset) configuration. ISA550 is running perfectly with 3 VLANs - default and two client VLANs dedicated to wireless devices and MOCA devices.

The ISA550 is already configured for its VLANs, all of them have internet connectivity, working VLAN DHCP, etc.

I want the SG300 to handle DHCP for all three of the VLANs located on the switch, and for the SG300 to have a single connection to the ISA550. All three VLANs on the SG300 will need internet connectivity. My initial thought was to have the SG300 connected to the ISA550 through the default SG300 VLAN as a trunk on a single port (one cable connecting the two devices). The SG300 would then handle the routing between the VLANs which are located on it as well as route externally directed traffic to the ISA550.

Ideally, I will be able to ping any device located on any of these subnets (ISA550 or SG300) from a workstation located on the "clients" VLAN on the SG300.

My difficulty is that in order to activate DHCP on the SG300, I have to change the default VLAN to a static IP address, and when I do, every VLAN on the SG300 loses connectivity to other SG300 VLANs. No VLAN that I have set up on the SG300 has ever gotten internet connectivity through the ISA550.

I've read every guide that I can find, including the discussions on here, and tried to set this up about 12 times, to no avail. I get VLANs that can not talk to one another, and all of them can't see the internet. I'm a noob at this, so any help is hugely appreciated, but bear in mind that I'll need to be spoon fed / handheld through setting this up as much as possible.


Hi Dww, please check this

Hi Dww, please check this post


This will show you how to correctly configure your VLANS and IP addresses for the switch. If you follow the switch configuration in the order presented, you will have the switch configured correctly. In addition, you shouldn't have to worry about any static routes considering the ISA supports trunks (the document outlines static routes since the router in the example doesn't support VLAN).


Once you set up the VLANS and IP addresses (following the order on the document), determine what will be your uplink port then you can tag all the VLAN to that port which then should connect to the ISA. I think you're familiar with the trunks considering you mentioned it on your above post.

-Tom Please mark answered for helpful posts
New Member

This is excellent information

This is excellent information, Tom, but my ISA550 doesn't have those options, or at least they are labeled differently and I can't translate. This is what I see on my router. I am assuming that I have to set up static routing on the router back to the swtich VLANs?


I followed your directions with regard to the SG300 down through creating the DHCP pool. Second VLAN created, one port assigned to it, etc. A client plugged into that port correctly obtains an IP address from the pool that I created, but it can not connect to the internet / can't resolve hosts.


Status quo:

I now have two VLANS on my switch - the default one, which now has a static address of on the port connected to the ISA550. The corresponding port on the ISA550 has an address of

second VLAN which has an address of One port is assigned to this VLAN. A client is connected to this port which obtained the address via DHCP. (Note that I set the domain name in the pool to as shown in your example).

The client on the second VLAN can ping hosts on the first (default) VLAN, it can ping the gateway for that VLAN (, but it can NOT ping the other side of that connection on the ISA550 (

Clients conected to the first VLAN (default) retain internet connectivity and CAN ping on the ISA550

Where do we go from here?

Cisco Employee

Hello, You may need to



You may need to configure static routes on the ISA. Also make sure that the default route on the switch points to the corresponding IP on the ISA.


Alternatively, you can also configure the ISA to do all the routing and assign DHCP address. The following link provides an example configuration with RV320.


The following two links may help with configuring the ISA500:


Make sure to configure the link connecting to the switch as a trunk with apprpriate VLAN's included.


Hope this helps.



New Member

I did configure static routes

I did configure static routes on the ISA550 for the VLANs which are configured on / DHCP'ed on the SG300 just now.



Clients connected to VLANs located on the SG300 can now ping clients on any other subnet, including those located on VLANs located on the ISA550, so traffic is moving as it should between all local subnets.


Clients connected to the default VLAN on the SG300 (this is the one that is connected to the ISA550) have internet connectivity as well.

Clients connected to other VLANs (other than the default VLAN) located on the SG300 can now resolve internet addresses (for example: ping, but the replies are 100% loss. These clients still have no internet connectivity. They can resolve external IP addresses, but no traffic sent to those addresses is returned to the client.


This leads me to believe that another static route needs to be created on the ISA550 to point traffic coming in from the internet to its originating client. Alternatively, could this be a firewall problem?



Cisco Employee

Seems like ISA is not doing

Seems like ISA is not doing NAT for the internal subnets. Please go ahead and add an advanced NAT rule on the ISA.

Create a new address group for the original source address (this should match the subnet on the SG300 switch), and choose the WAN1_IP for the translated source address and save the setting. Leave all other fields at their default settings. This should help.



New Member

That was the final piece. All

That was the final piece. All VLANs are working and have internet connectivity now. Thank you guys for all the help!


This question can be marked as answered. Not sure if I do that or an admin does.

Cisco Employee

You can mark the question as

You can mark the question as answered.