Inter VLAN Routing (I'm Stuck)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.

Inter VLAN Routing (I'm Stuck)

This thread has been locked for further replies. You can start a new thread to share your ideas or ask questions.
Inter VLAN Routing (I'm Stuck)
Inter VLAN Routing (I'm Stuck)
2020-10-18 17:31:10
Hardware Version: V4
Firmware Version: 4.0.5 Build 20200110 Rel.51761(s)

I have two VLANd setup.  Each one works as expected.   VLAN 1 (192.168.1.0/24) and VLAN 3 (192.168.3.0/24).     I have all of my nodes on VLAN 1 and IP CAMS on VLAN 3.   VLAN 1 routes out to my ISP as required.  I have a simple setup.       ATT Gateway ->ASUS ROUTER(192.168.1.1)->TPLINK SWITCH (192.168.1.7 Interface and 192.168.3.7 Interface)    I am trying to have VLAN 1 talk to VLAN 3. I dont want VLAN 3 to talk to VLAN 1.        I have read the other similar posts here but I become lost on the routing direction.  In the switch under L3 features I only see STATIC ROUTING.  I tried saying Destination 192.168.3.0 255.255.255.0 Next Hop 192.168.3.7 (VLAN Interface IP).   I'm lost.  Any ideas?

 

 

 

 

!T1600G-52PS
#
vlan 3
 name "IP_Cameras"
#
#
#
#
#
#
#
#
#
#
#
#
#
#
#
#
#
#
#
#
#
#
no system-time ntp
no system-time dst
#
#
#

telnet disable
no service reset-disable
#
#
#
#
#
#
#
#
#
#
ip igmp snooping
ip route 192.168.3.0 255.255.255.0 192.168.3.7
#
#
#
power inline consumption 384.0
#

#
#
#
#
#
#
interface vlan 1
  ip address 192.168.1.7 255.255.255.0
  ipv6 enable
#
interface vlan 3
  ip address 192.168.3.7 255.255.255.0
  description "VLAN3_IPCAMS"
  no ipv6 enable
#
interface gigabitEthernet 1/0/1
  description "VLAN1-ROUTER"
  
#
interface gigabitEthernet 1/0/2
  
#
interface gigabitEthernet 1/0/3
  description "VLAN3-CAM-PP1"
  switchport general allowed vlan 3 untagged
  switchport pvid 3
  no switchport general allowed vlan 1
  
#
interface gigabitEthernet 1/0/4
  description "VLAN1-CLOUDKEY"
  
#
interface gigabitEthernet 1/0/5
  description "VLAN3-CAM-PP2"
  switchport general allowed vlan 3 untagged
  switchport pvid 3
  no switchport general allowed vlan 1
  
#
interface gigabitEthernet 1/0/6
  description "VLAN1-VERA"
  
#
interface gigabitEthernet 1/0/7
  description "VLAN3-CAM-PP3"
  switchport general allowed vlan 3 untagged
  switchport pvid 3
  no switchport general allowed vlan 1
  
#
interface gigabitEthernet 1/0/8
  
#
interface gigabitEthernet 1/0/9
  description "VLAN3-CAM-PP4"
  switchport general allowed vlan 3 untagged
  switchport pvid 3
  no switchport general allowed vlan 1
  
#
interface gigabitEthernet 1/0/10
  
#
interface gigabitEthernet 1/0/11
  description "VLAN3-CAM-PP5"
  switchport general allowed vlan 3 untagged
  switchport pvid 3
  no switchport general allowed vlan 1
  
#
interface gigabitEthernet 1/0/12
  
#
interface gigabitEthernet 1/0/13
  
#
interface gigabitEthernet 1/0/14
  description "VLAN1-AP-PP6"
  speed 1000
  duplex full
  
#
interface gigabitEthernet 1/0/15
  description "VLAN3-CAM-PP7"
  switchport general allowed vlan 3 untagged
  switchport pvid 3
  no switchport general allowed vlan 1
  
#
interface gigabitEthernet 1/0/16
  
#
interface gigabitEthernet 1/0/17
  description "VLAN1-WALL-PP8"
  
#
interface gigabitEthernet 1/0/18
  
#
interface gigabitEthernet 1/0/19
  description "VLAN3-CAM-PP9"
  switchport general allowed vlan 3 untagged
  switchport pvid 3
  no switchport general allowed vlan 1
  
#
interface gigabitEthernet 1/0/20
  
#
interface gigabitEthernet 1/0/21
  description "VLAN3-CAM-PP10"
  switchport general allowed vlan 3 untagged
  switchport pvid 3
  no switchport general allowed vlan 1
  
#
interface gigabitEthernet 1/0/22
  
#
interface gigabitEthernet 1/0/23
  
#
interface gigabitEthernet 1/0/24
  
#
interface gigabitEthernet 1/0/25
  description "VLAN3-CAM-PP12"
  switchport general allowed vlan 3 untagged
  switchport pvid 3
  no switchport general allowed vlan 1
  
#
interface gigabitEthernet 1/0/26
  
#
interface gigabitEthernet 1/0/27
  
#
interface gigabitEthernet 1/0/28
  
#
interface gigabitEthernet 1/0/29
  description "VLAN3-CAM-PP14"
  switchport general allowed vlan 3 untagged
  switchport pvid 3
  no switchport general allowed vlan 1
  
#
interface gigabitEthernet 1/0/30
  
#
interface gigabitEthernet 1/0/31
  description "VLAN1-AP-PP15"
  speed 1000
  duplex full
  
#
interface gigabitEthernet 1/0/32
  
#
interface gigabitEthernet 1/0/33
  description "VLAN1-AP-PP16"
  speed 1000
  duplex full
  
#
interface gigabitEthernet 1/0/34
  
#
interface gigabitEthernet 1/0/35
  description "VLAN1-AP-PP17"
  speed 1000
  duplex full
  
#
interface gigabitEthernet 1/0/36
  
#
interface gigabitEthernet 1/0/37
  description "VLAN3-CAM-PP18"
  switchport general allowed vlan 3 untagged
  switchport pvid 3
  no switchport general allowed vlan 1
  
#
interface gigabitEthernet 1/0/38
  
#
interface gigabitEthernet 1/0/39
  
#
interface gigabitEthernet 1/0/40
  
#
interface gigabitEthernet 1/0/41
  description "VLAN3-CAM-PP19"
  switchport general allowed vlan 3 untagged
  switchport pvid 3
  no switchport general allowed vlan 1
  
#
interface gigabitEthernet 1/0/42
  description "VLAN1-FING"
  
#
interface gigabitEthernet 1/0/43
  
#
interface gigabitEthernet 1/0/44
  
#
interface gigabitEthernet 1/0/45
  description "VLAN1-NAS_PORT1"
  
#
interface gigabitEthernet 1/0/46
  
#
interface gigabitEthernet 1/0/47
  description "VLAN3-NAS_PORT4"
  switchport general allowed vlan 3 untagged
  switchport pvid 3
  no switchport general allowed vlan 1
  
#
interface gigabitEthernet 1/0/48
  description "VLAN3-CONSOLE"
  switchport general allowed vlan 3 untagged
  switchport pvid 3
  no switchport general allowed vlan 1
  
#
interface gigabitEthernet 1/0/49
  
#
interface gigabitEthernet 1/0/50
  
#
interface gigabitEthernet 1/0/51
  
#
interface gigabitEthernet 1/0/52
  
#
end
 

  0      
  0      
#1
Options
3 Reply
Re:Inter VLAN Routing (I'm Stuck)
2020-10-18 20:00:20 - last edited 2020-10-18 20:10:40

 

badtoro wrote

I am trying to have VLAN 1 talk to VLAN 3. I dont want VLAN 3 to talk to VLAN 1.

 

First of all, if you define an interface for the VLANs on the switch, Inter-VLAN routing is turned on automatically (unless you disable it globally). The default gateway for clients now is the switch.

 

Access control can be done using switch ACLs. But your goal is not  possible with switch ACLs. If you permit traffic from VLAN1 to VLAN3, but block all traffic from VLAN3 to VLAN1, then how should replies to requests ever reach the originator?

 

You have to at least allow replies from devices in VLAN3 to reach devices in VLAN1, which might be hard to set up using switch ACLs.

 

It's much easier to use a stateful firewall which allows to specify who can initiate a connection and which then tracks all established connections and automatically opens the reverse direction for traffic related to only those sessions, so that devices in VLAN3 can reply to requests from devices in VLAN1, but can not initiate a session on their own behalf.

 

Usually you use a one-armed router (aka router on a stick) for Inter-VLAN routing which requires a stateful firewall.

༺ 0100 1101 0010 10ཏ1 0010 0110 1010 1110 ༻
  0  
  0  
#2
Options
Re:Inter VLAN Routing (I'm Stuck)
2020-10-19 12:21:10

@R1D2 Thanks.  Even with the Static route removed I can not interact with any device from another VLAN either way.  PC on plugged into VLAN 1 can see the internet and other devices not not VLAN 3 devices.     The pc plugged into VLAN 3 can ping the IP cams and NVR but cant ping or access anything on VLAN 1.    That is why I thought I needed the STATIC ROUTE.     I guess I'll just leave them seperate. 

 

Thanks for your input

 

  0  
  0  
#3
Options
Re:Inter VLAN Routing (I'm Stuck)
2020-10-19 12:50:17 - last edited 2020-10-19 12:51:32

@badtoro, what is the default gateway on your PC? I guess it's the router if you can access the Internet.

 

A static route on the switch has no effect at all if you use your router for routing. You either need to set static routes directly on your PC (on every PC and on every other device) or on your router. But since VLANs are usually used to isolate networks, your router probably has firewall settings which block Inter-VLAN routing.

 

If you want the switch to perform routing, all your devices must use the switch as the default gateway. In addition, to provide Internet access your switch must have a default route pointing to your router for all traffic which can not be forwarded locally.

༺ 0100 1101 0010 10ཏ1 0010 0110 1010 1110 ༻
  1  
  1  
#4
Options