Unsolved

This post is more than 5 years old

2 Posts

1872

October 11th, 2017 11:00

7048P Inter-Vlan routing

Hi I have three PowerConnect 7048p layer 3 switches that I recently set up VLANs on. The VLANS are 1,30,40,50,60,70, and 80 respectively. The three switches are connected over fiber and the ports connecting them are trunked. Devices on their respective VLANS are verified to able to communicate with each other. I want to enable communications from VLAN 1 to VLANs 40 and 50.

I have entered "ip routing" in the (config)# command line to enable global routing and routing is enabled for each VLAN. The GUI menu description in the user manual shows a subcategory called "VLAN ROUTING" under the Routing menu. The GUI on my switches does not show this subcategory at all. It should be right between the Routing subcategories "Router" and "VVRP" I am running the latest 5.1.11.1 firmware image. How can I make these VLANs communicate with each other?

Here is the config for one of my switches:


!Current Configuration:
!System Description "PowerConnect 7048P, 5.1.11.1, VxWorks 6.6"
!System Software Version 5.1.11.1
!System Operational Mode "Normal"
!
configure
vlan 30,40,50,60,70,80
exit
vlan 1
vlan association subnet 10.0.0.0 255.255.0.0
exit
vlan 30
name "BYOD"
vlan association subnet 10.3.0.0 255.255.0.0
exit
vlan 40
name "Door"
vlan association subnet 10.4.0.0 255.255.255.0
exit
vlan 50
name "HVAC"
vlan association subnet 10.5.0.0 255.255.255.0

exit
vlan 60
name "Chromebooks"
exit
vlan 70
name "Ipads"
exit
vlan 80
name "Phones"
exit
snmp-server location "EDUPRIZE GILBERT B3"
hostname "B1 L3 Switch"
slot 1/0 6 ! PowerConnect 7048P
stack
member 1 6 ! PCT7048P
exit
interface out-of-band
ip address 192.168.0.1 255.255.255.0 0.0.0.0
exit
ip domain-name "eduprize"
ip name-server "10.0.0.9"
ip name-server "10.1.0.9"
logging file debugging

ip routing
ip route 0.0.0.0 0.0.0.0 10.0.0.1
interface vlan 1 1
ip address 10.0.20.46 255.255.0.0
ip netdirbcast
bandwidth 10000
ip dvmrp
ip igmp
exit
interface vlan 30 2
ip address 10.3.0.2 255.255.0.0
ip netdirbcast
bandwidth 10000000
exit
interface vlan 40 3
ip address 10.4.0.2 255.255.255.0
ip netdirbcast
bandwidth 10000000
ip dvmrp
ip igmp
exit
interface vlan 50 4
ip address 10.5.0.2 255.255.255.0

ip netdirbcast
bandwidth 1000000
exit
interface vlan 60 5
ip address 10.6.0.1 255.255.0.0
ip netdirbcast
bandwidth 10000000
exit
interface vlan 70 6
ip address 10.7.0.1 255.255.0.0
ip netdirbcast
bandwidth 10000000
exit
interface vlan 80 7
ip address 10.8.0.1 255.255.0.0
ip netdirbcast
bandwidth 10000000
exit
username "admin" password fb873850a0992cefa24a5add0990fae3 privilege 15 encrypted
monitor session 1 destination interface Gi1/0/47
line telnet
login authentication defaultList
enable authentication enableList

exit
line ssh
login authentication defaultList
enable authentication enableList
exit
ip multicast
ip dvmrp
ip igmp
!
interface Gi1/0/2
switchport mode general
switchport access vlan 40
exit
!
interface Gi1/0/6
switchport access vlan 40
exit
!
interface Gi1/0/7
switchport general acceptable-frame-type tagged-only
exit
!
interface Gi1/0/11
--More-- or (q)uit
switchport mode trunk
switchport access vlan 30
switchport trunk native vlan 30
exit
!
interface Gi1/0/12
switchport mode trunk
switchport access vlan 30
switchport trunk native vlan 30
exit
!
interface Gi1/0/13
switchport mode trunk
switchport access vlan 30
switchport trunk native vlan 30
exit
!
interface Gi1/0/14
switchport mode trunk
switchport access vlan 30
switchport trunk native vlan 30
exit
!
--More-- or (q)uit
interface Gi1/0/15
switchport mode trunk
switchport access vlan 30
switchport trunk native vlan 30
exit
!
interface Gi1/0/16
switchport general pvid 40
switchport access vlan 40
switchport trunk native vlan 40
exit
!
interface Gi1/0/17
switchport general pvid 40
switchport access vlan 40
switchport trunk native vlan 40
exit
!
interface Gi1/0/18
switchport general pvid 40
switchport access vlan 40
switchport trunk native vlan 40
exit

!
interface Gi1/0/19
switchport general pvid 40
switchport general ingress-filtering disable
switchport general allowed vlan add 40,50,60,70,80
switchport access vlan 40
switchport trunk native vlan 40
exit
!
interface Gi1/0/20
switchport general pvid 40
switchport access vlan 40
exit
!
interface Gi1/0/21
switchport access vlan 50
exit
!
interface Gi1/0/22
switchport access vlan 50
exit
!
interface Gi1/0/23
--More-- or (q)uit
switchport access vlan 50
exit
!
interface Gi1/0/24
switchport access vlan 50
exit
!
interface Gi1/0/25
switchport access vlan 50
exit
!
interface Gi1/0/26
switchport access vlan 60
exit
!
interface Gi1/0/27
switchport access vlan 60
exit
!
interface Gi1/0/28
switchport access vlan 60
exit
!

interface Gi1/0/29
switchport access vlan 60
exit
!
interface Gi1/0/30
switchport access vlan 60
exit
!
interface Gi1/0/31
switchport access vlan 70
exit
!
interface Gi1/0/32
switchport access vlan 70
exit
!
interface Gi1/0/33
switchport access vlan 70
exit
!
interface Gi1/0/34
switchport access vlan 70
exit

interface Gi1/0/35
switchport access vlan 70
exit
!
interface Gi1/0/36
switchport access vlan 80
exit
!
interface Gi1/0/37
switchport access vlan 80
exit
!
interface Gi1/0/38
switchport access vlan 80
exit
!
interface Gi1/0/39
switchport access vlan 80
exit
!
interface Gi1/0/40
switchport access vlan 80

!
interface Gi1/0/44
switchport general ingress-filtering disable
switchport general allowed vlan add 40 tagged
exit
!
interface Gi1/0/45
gvrp enable
switchport mode trunk
switchport general pvid 40
switchport general ingress-filtering disable
switchport general allowed vlan add 30,40,50,60,70,80
exit
!
interface Gi1/0/46
gvrp enable
switchport mode trunk
switchport general pvid 40
switchport general ingress-filtering disable
switchport general allowed vlan add 30,40,50,60,70,80
exit
!
--More-- or (q)uit
interface Gi1/0/47
gvrp enable
switchport general ingress-filtering disable
switchport general allowed vlan add 40,50,60,70,80
exit
!
interface Gi1/0/48
switchport mode trunk
exit

snmp-server engineid local 800002a203d067e5dcde66
exit

Thank you very much.

Seth

Moderator

 • 

9.6K Posts

 • 

42.7K Points

October 11th, 2017 13:00

Hi,

Does the VLAN routing work between VLAN 40 and 50? Which ports are you testing on? 

2 Posts

October 11th, 2017 15:00

Hi Josh, thanks for replying. VLAN routing does not work between VLANs 40 and 50. I only need any device on Vlan 1 to talk to one device on VLAN 40 and one device on VLAN 50 for HTTP management purposes.

We have a Sonicwall as our gateway and I have confirmed that routing is configured correctly on it. When I ping a device on VLAN 40 from VLAN 1, I can monitor traffic from the Sonicwall showing that a ping from my computer on VLAN 1 enters the Sonicwall on a port designated for VLAN 1 traffic from Port 47 on the 7048p switch and exits on a port designated for VLAN 40 traffic on the Sonicwall. I can also see the reply come back in on the VLAN 40 port on the Sonicwall and see it forwarded out of the VLAN 1 on the Sonicwall which is the same path it took coming in. Wireshark running on my computer shows it is never received by my computer which indicates the 7048p switch is dropping it. The same thing occurs when pinging VLAN 50 from VLAN 1. Devices on their respective VLANS communicate with each other as expected. 

I am not confident that inter-VLAN routing is occurring at all on the switch. Given that "VLAN Routing "under the Routing menu is not present on my switch despite being called out in the user manual I am not sure how to do it. You input and help is greatly appreciated.

Moderator

 • 

9.6K Posts

 • 

42.7K Points

October 12th, 2017 09:00

It sounds like the sonicwall is handling the routing, so it shouldn’t need the switch to route. The packets are hitting the switch on VLAN 1 both times. It may be tagging the vlan 1 traffic and the switch is expecting the untagged packet. 

No Events found!

Top