Highlighted
FamousRuler
Silver

Route problem with PC6248

Jump to solution

Hi

I have a PC6248 running with 4 vlans. Routing is enabled globally on the switch and on the vlan interfaces. All ports are access ports.

vlan 2 ip 192.192.168.2.2 /24
vlan 3 ip 192.192.168.3.1 /24
vlan 4 ip 192.192.168.4.1 /24
vlan 5 ip 172.16.22.2 /24

I'm not using vlan 1. All vlans talk to each other. Vlan 2 is connected to the firewall (192.168.2.1)  and vlan 3 and 4 routes to the firewall with the default route. Vlan 2,3 and 4 have internet connection. Vlan 5 is connected to a router (172.16.22.1 /24) that connects to a foreign network (172.16.33.0 /24).

computers belonging to vlan 5 have no problem accessing the foreign network since I added a static route to that network on the PC6248

ip route 172.16.33.0 255.255.255.0 172.16.22.1

The question is how do I get the other computers on the other three vlans to access the 172.16.33.0 network. I thought, since the clients on vlans 2,3,4 all have the PC6248 as their gateway and the PC6248 knows the way to the 172.16.33.0 network, they could access it but that is not the case. The PC6248 seems to only route for the clients residing in vlan 5. Why?

0 Kudos
14 Replies
Moderator
Moderator

Re: Route problem with PC6248

Jump to solution

VLAN 5 is able to access the other network because of the static route you gave it. With VLAN routing enabled the VLANs can communicate with each other on the 6248, but that does not mean that it will carry over the static route from VLAN 5 to the other VLANs.

In order to get all VLANs on the 6248 to traverse over the connection to the other devices, you will need to either continue adding static routes for each VLAN. Or change the switchport mode for the connection to the other networking devices to a Trunk mode, and allow those VLANs across the Trunk.

So you would want to navigate to the interface for the port that uplinks to the other router. Then set that interface to a Trunk mode and allow the VLANs across that Trunk.

console(config-if)# switchport mode trunk

console(config-if)# switchport trunk allowed vlan add 2,3,4,5

On the other router you will need to ensure it has these VLANs in it's VLAN database.

Here are some whitepages that do a good job of describing this some more and show some examples on how it could be setup.

www.dell.com/.../app_note_38.pdf

www.dell.com/.../app_note_4.pdf

Keep us updated,

Thanks

Daniel Covey
Dell EMC | Enterprise Support Services
Get support on Twitter: @DellCaresPRO

Download our QRL app: iOSAndroidWindows

0 Kudos
FamousRuler
Silver

Re: Route problem with PC6248

Jump to solution

Thanks for the reply. My idea was to let the PC6248 handle the vlans because it routes between vlans faster than the firewall would (ASA 5520).

How do I add static routes to the 172.16.33.0 network on each vlan?

0 Kudos
Moderator
Moderator

Re: Route problem with PC6248

Jump to solution

Page 725 starts the explanation of static route, what the command is and how to use it.

support.dell.com/.../cli_en.pdf

For the static routes to be visible, you must:

• Enable ip routing globally.

• Enable ip routing for the interface.

• Confirm that the associated link is also up.

Example

The following example identifies the ip-address subnet-mask, next-hop-ip

and a preference value of 200.

console(config)#ip route 192.168.10.10 255.255.255.0 192.168.20.1 metric 200

Daniel Covey
Dell EMC | Enterprise Support Services
Get support on Twitter: @DellCaresPRO

Download our QRL app: iOSAndroidWindows

0 Kudos
FamousRuler
Silver

Re: Route problem with PC6248

Jump to solution

Hi Daniel

I know how to enter a static route. I just didn't understand your statement and was hoping you could clarify it.

"In order to get all VLANs on the 6248 to traverse over the connection to the other devices, you will need to either continue adding static routes for each VLAN."

Does this mean I can enter specific routes to specific vlan interfaces? If so how do I do that?

Thanks

0 Kudos
Moderator
Moderator

Re: Route problem with PC6248

Jump to solution

Each VLAN has an IP address, so when you add a static route you are defining the next hop for a specific IP address.  Which in this case you are wanting to be the other router.

• console(config)#ip route (Enter IP address of VLAN) (Subnet ) (The next hop you want the traffic to take)

So with the static route in place if the switch cannot resolve the request coming from a VLAN it looks at that static route that is in place and forwards it.

Daniel Covey
Dell EMC | Enterprise Support Services
Get support on Twitter: @DellCaresPRO

Download our QRL app: iOSAndroidWindows

0 Kudos
FamousRuler
Silver

Re: Route problem with PC6248

Jump to solution

Either you are not understanding my question or I am not understanding you..

The problem is that the switch only forward the traffic for the clients that resides on the vlan that is physically connected to the next hop router. In my case that is vlan 5

E.g.  a client PC from vlan 4 trying to reach a host on 172.16.33.0 with ping command gets "destination host unreacheable" as an answer from the PC6248

So my conclusion is that the switch do NOT look in it's routing table when traffic coming from vlans other than vlan 5 which is physically connected to the router. It just drops the packets.

Or am I wrong here?

0 Kudos
Moderator
Moderator

Re: Route problem with PC6248

Jump to solution

I apologize for any misunderstanding or miscommunication. VLAN 5 is able to communicate because of the direct connection you have made with the static route. That static route is just for VLAN 5, and is not going to carry any other VLAN traffic across it.

So right now any client connected to VLAN 2,3,4, sends out a request for the 172 network, and since there is no Trunk or Static route set for those VLANs, you will not be able to access that network, because the VLAN does not know where to send the request.

Clients on VLAN 5 send out a request for the 172 network, and if VLAN 5 cannot find it, the VLAN then looks at it's default route and sends the unknown traffic to that pre set route, which gets you the connection you need.

To allow VLAN 2,3,4 to communicate to the 172 network you would generally setup a Trunk link between the switch and the other VLAN aware device. You set the Trunk on the physical port connecting the two devices. So if port 5 on the 6248 is physically connected to the other network devices, you would set that port to Trunk modes, and allow VLAN 2,3,4,5 across the trunk. Set the other network device to Trunk mode as well.

With the Trunk set, when any of those VLANs  request access to a location the 6248 is not able to resolve, it will forward those packets across the Trunk to the other device. Then that device knows where that request should go, because it has those network destinations on it.

If you do not want to do the Trunk, then you need to enter the Static routes for each of the VLANs. Once set each VLAN will know where to forward unresolved requests.

Daniel Covey
Dell EMC | Enterprise Support Services
Get support on Twitter: @DellCaresPRO

Download our QRL app: iOSAndroidWindows

0 Kudos
FamousRuler
Silver

Re: Route problem with PC6248

Jump to solution

Thanks for your clear answer.

Could you enlight me on how to enter static routes for each of the VLANs?

Thank you

0 Kudos
Moderator
Moderator

Re: Route problem with PC6248

Jump to solution

The following examples should work.

VLAN 2

ip route 192.168.2.2 255.255.255.0 172.16.22.1

VLAN 3

ip route 192.168.3.1 255.255.255.0 172.16.22.1

VLAN 4

ip route 192.168.4.1 255.255.255.0 172.16.22.1

If they do not, then you may change it up and do something more like this.

VLAN 2

ip route 192.168.2.0 255.255.255.0 172.16.22.1

VLAN 3

ip route 192.168.3.0 255.255.255.0 172.16.22.1

VLAN 4

ip route 192.168.4.0 255.255.255.0 172.16.22.1

Keep us updated.

Thanks.

Daniel Covey
Dell EMC | Enterprise Support Services
Get support on Twitter: @DellCaresPRO

Download our QRL app: iOSAndroidWindows

0 Kudos