NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
sigint
Jul 16, 2013Aspirant
Can't static route on netgear firewall between two vlans on a netgear switch
Can someone take a lot at the screenshots and let me know what I'm doing wrong? This should be really quick and simple but I can't seem to get it to work.
I have a created two port-based vlans (vlan 1 and vlan 2) on a netgear switch.... this is actually on two netgear switches that have been stacked as one logical.
vlan 1 is on 192.168.1.X network and used for data
vlan 2 is on 192.168.10.X network for voice and phones
So on the router I have set up a static route, but I can't seem to ping from one network to the other.
http://humint.s3.amazonaws.com/7-16-2013%2010-51-58%20AM.png
http://humint.s3.amazonaws.com/7-16-2013%2010-53-10%20AM.png
http://humint.s3.amazonaws.com/7-16-2013%2010-53-33%20AM.png
http://humint.s3.amazonaws.com/7-16-2013%2010-54-54%20AM.png
http://humint.s3.amazonaws.com/7-16-2013%2010-55-32%20AM.png
I have a created two port-based vlans (vlan 1 and vlan 2) on a netgear switch.... this is actually on two netgear switches that have been stacked as one logical.
vlan 1 is on 192.168.1.X network and used for data
vlan 2 is on 192.168.10.X network for voice and phones
So on the router I have set up a static route, but I can't seem to ping from one network to the other.
http://humint.s3.amazonaws.com/7-16-2013%2010-51-58%20AM.png
http://humint.s3.amazonaws.com/7-16-2013%2010-53-10%20AM.png
http://humint.s3.amazonaws.com/7-16-2013%2010-53-33%20AM.png
http://humint.s3.amazonaws.com/7-16-2013%2010-54-54%20AM.png
http://humint.s3.amazonaws.com/7-16-2013%2010-55-32%20AM.png
3 Replies
- jmizoguchiVirtuosoFVS336Gv2 does not support VLAN
You want to look at prosecure UTM series which as VLAN support or SRX5308 - sigintAspirant
jmizoguchi wrote: FVS336Gv2 does not support VLAN
You want to look at prosecure UTM series which as VLAN support or SRX5308
Are you sure that model does NOT support vlan at all? But I'm not doing 802 etc just port based vlan not even tagging them, simple treating them like two networks on two switches... why would a simple static route configuration not work then? - fordemMentorWhilst June is correct in saying the firewall does not support VLANs, I'd be very surprised if it can't do what you're asking of it - I've done something very similar with an FVS336Gv1 and an FVS338.
First - make sure you're using "multi-homing" on the firewall and you have both the 192.168.1.x & 192.168.10.x networks configured on the firewall's LAN interface - I don't see this screen in your screen shots.
Second - make sure the switch port that the firewall is connected to is on both VLANs if it's a port VLAN, and for an 802.1Q VLAN make sure it's an untagged (edge) port - this is also not shown in your screen shots.
You could also try having two completely separate port VLANs (no shared port) and connect each VLAN to the firewall with it's own cable.
Third - your static routing screenshot shows TWO static routes - only ROUTE2 is required.
There is also another potential problem area - for some reason, you have chosen not to have the firewall at it's default 192.168.1.1 address, possibly because you have another firewall at that address - if this is the case, there will probably be a default route on your PCs pointing all "non 192.168.1.x" traffic to that device (including your 192.168.10.x traffic), which will then forward it to the internet, so that it never hits the FVS336G.
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!