snagrat Posted June 15, 2016 Posted June 15, 2016 What information do I need to provide to SWGfL regarding the VLANs I have setup. Currently I cannot ping the router from the VLANs but camping everything else. Do they just need to know the IP subnet and the VLAN ID?
newpersn Posted June 15, 2016 Posted June 15, 2016 Don't need to give any information to SWGFL. We added a NAT between the router and switch.
FragglePete Posted June 15, 2016 Posted June 15, 2016 We had to put a Sophos UTM in as a NAT box so we could do Masquerade IP (interent traffic from each VLAN then appears to come from a different IP address on the SWGfL range). This stops overloading one proxy server in the SWGfL farm. I believe however things have changed since then but it was tricky for us as we get our SWGfL feed via the LEA. Pete
snagrat Posted June 16, 2016 Author Posted June 16, 2016 Isn't a NAT just an extra thing to have to setup. I thought SWGfL would be able to do it on their router by setting up sub interfaces?
localzuk Posted June 16, 2016 Posted June 16, 2016 Do you have a layer 3 switch in your network? Is it set up to do intra-VLAN routing? The way we have it set up is, our core switch is the router for the network internally, with it having an IP for each VLAN, which is set as the gateway for all devices on that VLAN. The switch then has a default route set, pointing at the edge router. The edge router (ISP's router), is then set to be in a single VLAN, with it set to route things to the core switch. No NAT involved.
snagrat Posted June 16, 2016 Author Posted June 16, 2016 Do you have a layer 3 switch in your network? Is it set up to do intra-VLAN routing? The way we have it set up is, our core switch is the router for the network internally, with it having an IP for each VLAN, which is set as the gateway for all devices on that VLAN. The switch then has a default route set, pointing at the edge router. The edge router (ISP's router), is then set to be in a single VLAN, with it set to route things to the core switch. No NAT involved. Yes Inter-VLAN all working just can't pong router. I'll check my default route as not sure I have one pointing to the router Did SWGfL do anything to the router at all for you or was it all configured already?
localzuk Posted June 16, 2016 Posted June 16, 2016 Yes Inter-VLAN all working just can't pong router. I'll check my default route as not sure I have one pointing to the router Did SWGfL do anything to the router at all for you or was it all configured already? We're a little different here as we go via our council first. However, the principle is the same. SWGfL need to alter the rules on the router to send all traffic to your core switch.
snagrat Posted June 24, 2016 Author Posted June 24, 2016 I have had a reply from SWGfL as below: We have assigned a new IP range on the interface FE/0/0/3 and routed the 10.55.210.0/23 inside. Assigned IP on interface FE/0/0/3 : 10.55.97.193 IP route : 10.55.210.0 255.255.254.0 10.55.97.194 Please assign 10.55.97.194 at switch port end. I have added a new VLAN and assigned its interface the IP mentioned but still cannot ping the gateway. Should I be doing anything else? 1
snagrat Posted June 24, 2016 Author Posted June 24, 2016 Actually it appears to be working now. I created a static route from 10.55.210.0/23 to 10.55.97.193 I can browse the web and DNS appears to be working.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now