Jump to content

Setting a Default Gateway for One VLAN not for whole core switch


Recommended Posts

Posted

Hi,

 

I am using a cisco core switch and what I need is to set the guest VLAN to go to our filtering unit as its default gateway so that unit can then pass on the traffic (transparent proxy) to the firewall. I know i can use ip default-gateway ip-address to change the whole core switch but I dont want that, I really want to do it only for the traffic on that VLAN. I though I may be able to use IP-Helper but I am not to sure if I can.

 

Any Advise would be good.

 

Thanks

Posted
Have you set the correct range on the VLAN and are you trunking the VLANS properly if so it will work. if your trunking the Guest VLAN and its on the correct IP Range then it should be able to talk toy our Firewall.
Posted

In your DHCP scope for the guest vlan (I assume you have one), what have you got the scopes' default gateway to be? I would be guessing it is set to the core switch for inter-vlan routing? Could you change it to be the filtering box instead and then have that forward its data to the core switch??

 

Or am I thinking this through wrong?

Posted
Your filtering unit will need to have an interface on the wireless vlan with an IP within that vlan range. Once that it present you can then use that IP as the DFG, this is usually one higher than the network address to follow convention.
Posted (edited)

When you setup your new VLAN you will give in an IP address and subnet mask. You will use this VLAN IP address for your default gateway on your clients. Static routes that are already setup will send it to your firewall / router.

 

You shouldn't need to setup a new interface on the firewall etc.

 

You can lockdown your VLANs using Access Control Lists.

 

You will need to setup a DHCP range on your DHCP server and setup a IP Helper on your VLAN.

Edited by FN-GM
Posted

Thanks all,

 

I have a DHCP scope made for the guest wireless and The access list in place and working. This whole issue stems from getting apps like twitter and Facebook to work on tablets. When speaking to the company that makes our filtering unit they said that for these apps to work the traffic needs to be forced into the interface of the filtering unit, when this happens the data on these non 80 or 443 ports will work. I have tested without the filter in place and the firewall allows for this to work.

 

Hope that helps.

 

Thanks for all the help

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...