Jump to content

Recommended Posts

Posted

Afternoon all

 

I have created a Guest VLAN with a new IP range (e.g 10.10.200.0/22). Our current IP range, for example, is 10.50.200.0/20.

 

Core switch is IP address is 10.50.200.50.

 

Our Guest VLAN is dishing IP addresses out within the correct range (from DHCP server within main IP range), and from the Guest VLAN I can ping my laptop within the main IP range (e.g. 10.50.200.100), my laptop having 10.50.200.50 as the Gateway. However I am unable to ping our firewall from the Guest VLAN which has the IP address of 10.50.200.10.

 

I have been banging my head against the wall so much over the last day or so, so any pointers based upon the information above would be appreciated. Been looking at it so much, I have possibly missed the obvious. This is my first attempt at creating VLANS - please help!

 

If more info is needed please let me know.

 

Thanks

Posted (edited)

I did think that's what was need. Our firewall is co-managed so I dont have access to everything on there unfortunately. Would this basically mean a new interface needs creating on the firewall that has an internal IP address on within the new Guest VLAN range? I have been told that no traffic is hitting the firewall from the range, but surely thats expected if there is no route?

 

Thanks

 

Ah I forgot - firewall is Palo Alto

Edited by Craig_W
Posted

You wouldn't need to create an interface. Just a static route that points to your guest subent with the destination/gateway as your core switch.

 

You probably wouldn't see the traffic if there is no route back.

 

You could subnet your existing range to avoid having to modify the firewall.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...