• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

sg-300 switch and vlans?

rgraze911

Limp Gawd
Joined
May 12, 2005
Messages
290
So I've spent many hours trying to figure this out. I have a sa520w router I configured w a vlan for the wireless and port 2. Now I would like the switch to handle both traffic from the default lan and the vlan. I tried creating a vlan on ports 28 and 10 but I cant get it to work. I have my other lan on port 27. Ive read something about switch layers? not sure. so I want port 10 to route to the vlan and other ports go to the default lan.
 
You want to setup a trunk between the router and the switch. (Basically tag VLAN1 and VLAN2 on both ports on the router and switch)

Set all the ports that you want in the default vlan to the default vlan (1). (Untagged in VLAN 1)

Set the ports you want in the second VLAN to VLAN 2. You'll want them untagged in VLAN 2.

If you have an AP that has SSIDs on different VLANs. you will also need a trunk to the AP.
 
I enabled the switch to 3 layer via telnet. On the router port 1 is pvid 1, port 2 is pvid 25. On the switch the default is pvid 1 , I created vlan 25. I untaged ports 13,14 and 27 so its on vlan 25. the rest are on vlan 1. I still can only get one lan or the other, not both. If I get ports 13,14, and 27 to work with the vlan 25 (192.168.25.0) I can not get the default ports to work (192.168.0.0). So as it sits now I have port 2 plug into the cisco switch port 28 which is vlan 25, I have port 1 on the router plug into an unmanaged gig switch then into port 27.
 
I am quite confused. Can you draw out your setup and the links? A diagram would be very helpful.

You can have two cables running between the router and the switch.

On the switch, the port that has the cable coming from port 1 on the router, nothing should be set. The default is VLAN 1 which you want.

On the port that come sfrom the second port on the router, set the switch port to an access port on VLAN 25. Do the same for the other ports you want in the VLAN.

Have you created the VLANs and set the ports appropriately on the router? If you plug into each router port, do you get the desired result?


I believe the small business series switches like you have, have a bit different "terms" and config than their big brothers. I'm used to higher end Cisco switches and routers and I have never used the SB series so my terms may be a bit different than what you can see.
 
I think that switch is layer 3 only in the barest sense. You have to set up static routes to route between VLANs, I think.
 
@ /usr/home it is setup like you say. I do get desired results from router.
@ Electrofreak It can be set either as 2 or 3 layer
 
@ /usr/home it is setup like you say. I do get desired results from router.
@ Electrofreak It can be set either as 2 or 3 layer

Yes, I understand that, but some lower-tier Cisco "layer 3" switches that static routes to route between VLANs. I'd check your product documentation to confirm if this is the case.

Here's what you need for inter-vlan routing to work:

  • Ports assigned to VLANs, obviously.
  • Layer 3 mode enabled.
  • Each VLAN has an IP assigned to it in the switch, this is used for routing between VLANs.
  • Each device on a VLAN needs to have a default gateway to the IP of the VLAN in the switch.
  • If your switch doesn't route between local interfaces automagically, you need static routes for each network to the IP address of the other VLAN you want to route to. Some devices will route between local interfaces but still need static routes to route over the trunk ports to other devices.
 
Ports are assigned to vlan. Might not be clear where to assign ip to vlan. In ipv4 interface I have statics set up vlan 1 192.168.0.4 and vlan 25 192.168.25.4, DHCP relay enabled with dhcp server 192.168.0.1 and 25.1, DHCP relay port 27 to vlan1 192.168.0.4 and vlan 25 port 28 to 192.168.25.4. Static routes destination 192.168.0.0 next hop 192.168.0.1 and 192.168.25.0 next hop 192.168.25.1. The switch darn nears does what its supposed to until you have both uplinks to the router plugged in then one vlan cant communicate back to the router but it can communicate to the switch.
 
Ports are assigned to vlan. Might not be clear where to assign ip to vlan. In ipv4 interface I have statics set up vlan 1 192.168.0.4 and vlan 25 192.168.25.4, DHCP relay enabled with dhcp server 192.168.0.1 and 25.1, DHCP relay port 27 to vlan1 192.168.0.4 and vlan 25 port 28 to 192.168.25.4. Static routes destination 192.168.0.0 next hop 192.168.0.1 and 192.168.25.0 next hop 192.168.25.1. The switch darn nears does what its supposed to until you have both uplinks to the router plugged in then one vlan cant communicate back to the router but it can communicate to the switch.

Would you be able to post a topology? It might help me figure out what's happening.
 
Vlan 1 is problematic don't use this vlan. I have about 10 of these switches and all small business cisco switches can't use vlan 1. Vlan 1 is there when there is no VLAN configs. As soon as you configure any VLANs you need to carry your normal traffic on a different traffic other then vlan 1. This is why your static routing is not working.
Exapmle config.
VLAN 1 (unused)
VLAN 10 Normal Traffic + Management traffic
VLAN 20 AP VLAN.
 
Drawing1.jpg
 
Moved the 192.168.0.0 to vlan 100 with port 1 and 27 on vlan 100 still only one or the other both cant reach router at same time. Yes I did i was trying it out.
 
Moved the 192.168.0.0 to vlan 100 with port 1 and 27 on vlan 100 still only one or the other both cant reach router at same time

Your setup will not work unless you have a high end router.
Use a single Trunk port to uplink your router.
 
I plugged a separate switch into port 2 of the router which is my vlan25 then I have a computer that picks up an ip of 192.168.25.6 so that works and the main vlan (192.168.0.0) still works. So the router is routing for both ip sets just not when they are both plugged into the same switch. but i will look into the single uplink trunk, just not sure how I would get both networks through 1 uplink.
 
I plugged a separate switch into port 2 of the router which is my vlan25 then I have a computer that picks up an ip of 192.168.25.6 so that works and the main vlan (192.168.0.0) still works. So the router is routing for both ip sets just not when they are both plugged into the same switch. but i will look into the single uplink trunk, just not sure how I would get both networks through 1 uplink.

I forgot how I did it on my setup but there is a trunk option. I tried something similar to you but the switch was found to be a problem I was using a Sonicwall NSA 3500 to do it.
Does your router know how to handle VLANS?
 
Vlan 1 is problematic don't use this vlan. I have about 10 of these switches and all small business cisco switches can't use vlan 1. Vlan 1 is there when there is no VLAN configs. As soon as you configure any VLANs you need to carry your normal traffic on a different traffic other then vlan 1. This is why your static routing is not working.
Exapmle config.
VLAN 1 (unused)
VLAN 10 Normal Traffic + Management traffic
VLAN 20 AP VLAN.

First, your post about Vlan 1 wasn't accurate. By default, Vlan 1 is configured for management on switches, which is fine. In fact, management traffic should remain on Vlan 1 instead of another Vlan because this ensures it'll traverse trunks even if they're pruned.

Your setup will not work unless you have a high end router.
Use a single Trunk port to uplink your router.

Secondly, he doesn't NEED to trunk Vlans to his router, a router with 2 ethernet ports (a Vlan on each one) is perfectly capable of routing between them. And, regarding your last statement above... I'd be surprised if Cisco sold a router that doesn't understand Vlans...
 
I can only assume since it allowed me to create a vlan 25 for the wireless and assign it to a port. While still having the main on a separate wireless and ports
 
Well I configured the router to run vlan1 and 25 through port 2 in trunk mode. I reconfigured switch back to vlan1 and vlan25. So now port 13 and 14 are on vlan25 everything else vlan1. The devices on vlan 25 will automatically get the proper IP 192.168.25.*. vlan1 will not get an ip but if I give them a static address either 192.168.25.* or 192.168.0.* they work. They should be getting the 192.168.0.* range.
 
So what I've noticed is I have to have vlan1 untagged on my port 28 which is the trunk from the router for it to work, but it seems I have to have it tagged in vlan25 for vlan25 to work. Reason being?
 
VLAN1 is most likely the default VLAN on both the router and the switch so it wouldn't need to be tagged. Any traffic that doesn't have any .Q tags will automatically be place in VLAN1.

What you are seeing is to be expected and normal.
 
Back
Top