Inter-VLAN Routing _ Objectives
Inter-VLAN Routing _ Objectives
Cisco Press
Inter-VLAN Routing
Date: Jul 29, 2020 By Cisco Networking Academy. Sample Chapter is provided
courtesy of Cisco Press.
Objectives
Upon completion of this chapter, you will be able to answer the following
questions:
Key Terms
This chapter uses the following key terms. You can nd the denitions in the
Glossary.
router-on-a-stick Page 98
Introduction (4.0)
Now you know how to segment and organize your network into VLANs. Hosts
can communicate with other hosts in the same VLAN, and you no longer have
hosts sending out broadcast messages to every other device in your network,
eating up needed bandwidth. But what if a host in one VLAN needs to
communicate with a host in a dierent VLAN? If you are a network administrator,
you know that people will want to communicate with other people outside of
your network. This is where inter-VLAN routing can help you. Inter-VLAN routing
uses a Layer 3 device, such as a router or a Layer 3 switch. Let’s take your
VLAN expertise and combine it with your network layer skills and put them to the
test!
[Link] 1/28
2021/2/17 Inter-VLAN Routing | Objectives
Inter-VLAN routing is the process of forwarding network trac from one VLAN
to another VLAN.
Layer 3 switch using switched virtual interfaces (SVIs): This is the most
scalable solution for medium to large organizations.
For example, refer to the topology in Figure 4-1 where R1 has two interfaces
connected to switch S1.
NOTE
The IPv4 addresses of PC1, PC2, and R1 all have a /24 subnet mask.
[Link] 2/28
2021/2/17 Inter-VLAN Routing | Objectives
NOTE
[Link] 3/28
2021/2/17 Inter-VLAN Routing | Objectives
Step 3. Switch S1 forwards the tagged trac out the other trunk interface
on port F0/3 to the interface on router R1.
Step 5. The unicast trac is tagged with VLAN 30 as it is sent out the
router interface to switch S1.
Step 6. Switch S1 forwards the tagged unicast trac out the other trunk
link to switch S2.
Step 7. Switch S2 removes the VLAN tag of the unicast frame and
forwards the frame out to PC3 on port F0/23.
NOTE
NOTE
Inter-VLAN SVIs are created the same way that the management VLAN interface
is congured. The SVI is created for a VLAN that exists on the switch. Although
virtual, the SVI performs the same functions for the VLAN as a router interface
would. Specically, it provides Layer 3 processing for packets that are sent to or
from all switch ports associated with that VLAN.
The following are advantages of using Layer 3 switches for inter-VLAN routing:
There is no need for external links from the switch to the router for
routing.
They are not limited to one link because Layer 2 EtherChannels can be
used as trunk links between the switches to increase bandwidth.
Latency is much lower because data does not need to leave the switch to
be routed to a dierent network.
The only disadvantage is that Layer 3 switches are more expensive than Layer 2
switches, but they can be less expensive than a separate Layer 2 switch and
router.
[Link] 5/28
2021/2/17 Inter-VLAN Routing | Objectives
Assume that R1, S1, and S2 have initial basic congurations. Currently, PC1 and
PC2 cannot ping each other because they are on separate networks. Only S1
and S2 can ping each other, but they but are unreachable by PC1 or PC2
because they are also on dierent networks.
To enable devices to ping each other, the switches must be congured with
VLANs and trunking, and the router must be congured for inter-VLAN routing.
Step 1. Create and name the VLANs. First, the VLANs are created and
named, as shown in Example 4-1. VLANs are created only after you exit
out of VLAN subconguration mode.
S1(config)# v l a n 10
S1(config-vlan)# name LAN10
S1(config-vlan)# exit
S1(config)# v l a n 20
S1(config-vlan)# name LAN20
S1(config-vlan)# exit
S1(config)# v l a n 99
S1(config-vlan)# name Management
[Link] 6/28
2021/2/17 Inter-VLAN Routing | Objectives
S1(config-vlan)# e x i t
S1(config)#
S1(config)# i n t e r f a c e v l a n 9 9
S1(config-if)# i p a d d 1 9 2 . 1 6 8 . 9 9 . 2 2 5 5 . 2 5 5 . 2 5 5 . 0
S1(config-if)# n o s h u t
S1(config-if)# e x i t
S1(config)# i p d e f a u l t - g a t e w a y 1 9 2 . 1 6 8 . 9 9 . 1
S1(config)#
S1(config)# i n t e r f a c e f a 0 / 6
S1(config-if)# s w i t c h p o r t m o d e a c c e s s
S1(config-if)# s w i t c h p o r t a c c e s s v l a n 1 0
S1(config-if)# n o s h u t
S1(config-if)# e x i t
S1(config)#
S1(config)# i n t e r f a c e f a 0 / 1
S1(config-if)# s w i t c h p o r t m o d e t r u n k
S1(config-if)# n o s h u t
S1(config-if)# e x i t
S1(config)# i n t e r f a c e f a 0 / 5
S1(config-if)# s w i t c h p o r t m o d e t r u n k
S1(config-if)# n o s h u t
S1(config-if)# e n d
*Mar 1 00:23:43.093: %LINEPROTO-5-UPDOWN: Line protocol on Interface
FastEthernet0/1, changed state to up
*Mar 1 00:23:44.511: %LINEPROTO-5-UPDOWN: Line protocol on Interface
FastEthernet0/5, changed state to up
S2(config)# v l a n 10
S2(config-vlan)# name LAN10
S2(config-vlan)# exit
S2(config)# v l a n 20
S2(config-vlan)# name LAN20
S2(config-vlan)# exit
S2(config)# v l a n 99
S2(config-vlan)# name Management
[Link] 7/28
2021/2/17 Inter-VLAN Routing | Objectives
S2(config-vlan)# e x i t
S2(config)#
S2(config)# i n t e r f a c e v l a n 9 9
S2(config-if)# i p a d d 1 9 2 . 1 6 8 . 9 9 . 3 2 5 5 . 2 5 5 . 2 5 5 . 0
S2(config-if)# n o s h u t
S2(config-if)# e x i t
S2(config)# i p d e f a u l t - g a t e w a y 1 9 2 . 1 6 8 . 9 9 . 1
S2(config)# i n t e r f a c e f a 0 / 1 8
S2(config-if)# s w i t c h p o r t m o d e a c c e s s
S2(config-if)# s w i t c h p o r t a c c e s s v l a n 2 0
S2(config-if)# n o s h u t
S2(config-if)# e x i t
S2(config)# i n t e r f a c e f a 0 / 1
S2(config-if)# s w i t c h p o r t m o d e t r u n k
S2(config-if)# n o s h u t
S2(config-if)# e x i t
S2(config-if)# e n d
*Mar 1 00:23:52.137: %LINEPROTO-5-UPDOWN: Line protocol on Interface
FastEthernet0/1, changed state to up
Repeat the process for each VLAN to be routed. Each router subinterface must
be assigned an IP address on a unique subnet for routing to occur.
When all subinterfaces have been created, enable the physical interface using
the no shutdown interface conguration command. If the physical interface is
disabled, all subinterfaces are disabled.
R1(config)# i n t e r f a c e G 0 / 0 / 1 . 1 0
R1(config-subif)# d e s c r i p t i o n D e f a u l t Gateway for VLAN 10
R1(config-subif)# e n c a p s u l a t i o n d o t 1 Q 10
R1(config-subif)# i p a d d 1 9 2 . 1 6 8 . 1 0 . 1 [Link]
R1(config-subif)# e x i t
R1(config)#
R1(config)# i n t e r f a c e G 0 / 0 / 1 . 2 0
R1(config-subif)# d e s c r i p t i o n D e f a u l t Gateway for VLAN 20
R1(config-subif)# e n c a p s u l a t i o n d o t 1 Q 20
R1(config-subif)# i p a d d 1 9 2 . 1 6 8 . 2 0 . 1 [Link]
R1(config-subif)# e x i t
R1(config)#
R1(config)# i n t e r f a c e G 0 / 0 / 1 . 9 9
R1(config-subif)# d e s c r i p t i o n D e f a u l t Gateway for VLAN 99
R1(config-subif)# e n c a p s u l a t i o n d o t 1 Q 99
[Link] 8/28
2021/2/17 Inter-VLAN Routing | Objectives
R1(config-subif)# i p a d d 1 9 2 . 1 6 8 . 9 9 . 1 2 5 5 . 2 5 5 . 2 5 5 . 0
R1(config-subif)# e x i t
R1(config)#
R1(config)# i n t e r f a c e G 0 / 0 / 1
R1(config-if)# d e s c r i p t i o n T r u n k l i n k t o S 1
R1(config-if)# n o s h u t
R1(config-if)# e n d
R1#
*Sep 15 19:08:47.015: %LINK-3-UPDOWN: Interface GigabitEthernet0/0/1, changed
state to down
*Sep 15 19:08:50.071: %LINK-3-UPDOWN: Interface GigabitEthernet0/0/1, changed
state to up
*Sep 15 19:08:51.071: %LINEPROTO-5-UPDOWN: Line protocol on Interface
GigabitEthernet0/0/1, changed state to up
R1#
From a host, verify connectivity to a host in another VLAN using the ping
command. It is a good idea to rst verify the current host IP conguration using
the ipcong Windows host command, as shown in Example 4-7.
C:\Users\PC1> i p c o n f i g
Windows IP Configuration
Ethernet adapter Ethernet0:
Connection-specific DNS Suffix . :
Link-local IPv6 Address : fe80::5c43:ee7c:2959:da68%6
IPv4 Address : [Link]
Subnet Mask : [Link]
Default Gateway : [Link]
C:\Users\PC1>
The output conrms the IPv4 address and default gateway of PC1. Next, use
ping to verify connectivity with PC2 and S1, as shown in Figure 4-5. The ping
output successfully conrms that inter-VLAN routing is operating, as shown in
Example 4-8.
C:\Users\PC1> p i n g 1 9 2 . 1 6 8 . 2 0 . 1 0
Pinging [Link] with 32 bytes of data:
Reply from [Link]: bytes=32 time<1ms TTL=127
Reply from [Link]: bytes=32 time<1ms TTL=127
Reply from [Link]: bytes=32 time<1ms TTL=127
Reply from [Link]: bytes=32 time<1ms TTL=127
Ping statistics for [Link]:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss).
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
C:\Users\PC1>
C:\Users\PC1> p i n g 1 9 2 . 1 6 8 . 9 9 . 2
Pinging [Link] with 32 bytes of data:
Request timed out.
Request timed out.
Reply from [Link]: bytes=32 time=2ms TTL=254
Reply from [Link]: bytes=32 time=1ms TTL=254 |
Ping statistics for [Link]:
Packets: Sent = 4, Received = 2, Lost = 2 (50% loss).
Approximate round trip times in milli-seconds:
[Link] 9/28
2021/2/17 Inter-VLAN Routing | Objectives
show ip route
show interfaces
As shown in Example 4-9, verify that the subinterfaces are appearing in the
routing table of R1 by using the show ip route command. Notice that there are
three connected routes (C) and their respective exit interfaces for each routable
VLAN. The output conrms that the correct subnets, VLANs, and subinterfaces
are active.
R1# s h o w i p r o u t e | b e g i n G a t e w a y
Gateway of last resort is not set
[Link]/24 is variably subnetted, 2 subnets, 2 masks
C [Link]/24 is directly connected, GigabitEthernet0/0/1.10
L [Link]/32 is directly connected, GigabitEthernet0/0/1.10
[Link]/24 is variably subnetted, 2 subnets, 2 masks
C [Link]/24 is directly connected, GigabitEthernet0/0/1.20
L [Link]/32 is directly connected, GigabitEthernet0/0/1.20
[Link]/24 is variably subnetted, 2 subnets, 2 masks
C [Link]/24 is directly connected, GigabitEthernet0/0/1.99
L [Link]/32 is directly connected, GigabitEthernet0/0/1.99
R1#
R1# s h o w i p i n t e r f a c e b r i e f | i n c l u d e up
GigabitEthernet0/0/1 unassigned YES unset up up
Gi0/0/1.10 [Link] YES manual up up
Gi0/0/1.20 [Link] YES manual up up
Gi0/0/1.99 [Link] YES manual up up
R1#
R1# s h o w i n t e r f a c e s g 0 / 0 / 1 . 1 0
GigabitEthernet0/0/1.10 is up, line protocol is up
Hardware is ISR4221-2x1GE, address is 10b3.d605.0301 (bia 10b3.d605.0301)
Description: Default Gateway for VLAN 10
Internet address is [Link]/24
MTU 1500 bytes, BW 100000 Kbit/sec, DLY 100 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation 802.1Q Virtual LAN, Vlan ID 10.
ARP type: ARPA, ARP Timeout 04:00:00
Keepalive not supported
[Link] 10/28
2021/2/17 Inter-VLAN Routing | Objectives
The misconguration could also be on the trunking port of the switch. Therefore,
it is also useful to verify the active trunk links on a Layer 2 switch by using the
show interfaces trunk command, as shown in Example 4-12. The output
conrms that the link to R1 is trunking for the required VLANs.
NOTE
S1# s h o w i n t e r f a c e s t r u n k
Port Mode Encapsulation Status Native vlan
Fa0/1 on 802.1q trunking 1
Fa0/5 on 802.1q trunking 1
Port Vlans allowed on trunk
Fa0/1 1-4094
Fa0/5 1-4094
Port Vlans allowed and active in management domain
Fa0/1 1,10,20,99
Fa0/5 1,10,20,99
Port Vlans in spanning tree forwarding state and not pruned
Fa0/1 1,10,20,99
Fa0/5 1,10,20,99
S1#
In this Packet Tracer activity, you check for connectivity prior to implementing
inter-VLAN routing. Then you congure VLANs and inter-VLAN routing. Finally,
you enable trunking and verify connectivity between VLANs.
[Link] 11/28
2021/2/17 Inter-VLAN Routing | Objectives
Route from one VLAN to another using multiple switched virtual interfaces
(SVIs).
To provide inter-VLAN routing, Layer 3 switches use SVIs. SVIs are congured
using the same interface vlan vlan-id command used to create the management
SVI on a Layer 2 switch. A Layer 3 SVI must be created for each of the routable
VLANs.
Step 1. Create the VLANs. First, create the two VLANs as shown in
Example 4-13.
[Link] 12/28
2021/2/17 Inter-VLAN Routing | Objectives
D1(config)# v l a n 10
D1(config-vlan)# name LAN10
D1(config-vlan)# vlan 20
D1(config-vlan)# name LAN20
D1(config-vlan)# exit
D1(config)#
Step 2. Create the SVI VLAN interfaces. Congure the SVI for VLANs 10
and 20, as shown in Example 4-14. The IP addresses that are congured
will serve as the default gateways to the hosts in the respective VLANs.
Notice the informational messages showing the line protocol on both SVIs
changed to up.
D1(config)# i n t e r f a c e v l a n 1 0
D1(config-if)# d e s c r i p t i o n D e f a u l t G a t e w a y S V I f o r 1 9 2 . 1 6 8 . 1 0 . 0 / 2 4
D1(config-if)# i p a d d 1 9 2 . 1 6 8 . 1 0 . 1 2 5 5 . 2 5 5 . 2 5 5 . 0
D1(config-if)# n o s h u t
D1(config-if)# e x i t
D1(config)#
D1(config)# i n t v l a n 2 0
D1(config-if)# d e s c r i p t i o n D e f a u l t G a t e w a y S V I f o r 1 9 2 . 1 6 8 . 2 0 . 0 / 2 4
D1(config-if)# i p a d d 1 9 2 . 1 6 8 . 2 0 . 1 2 5 5 . 2 5 5 . 2 5 5 . 0
D1(config-if)# n o s h u t
D1(config-if)# e x i t
D1(config)#
*Sep 17 13:52:16.053: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan10,
changed state to up
*Sep 17 13:52:16.160: %LINEPROTO-5-UPDOWN: Line protocol on Interface Vlan20,
changed state to up
D1(config)# i n t e r f a c e G i g a b i t E t h e r n e t 1 / 0 / 6
D1(config-if)# d e s c r i p t i o n A c c e s s p o r t t o P C 1
D1(config-if)# s w i t c h p o r t m o d e a c c e s s
D1(config-if)# s w i t c h p o r t a c c e s s v l a n 1 0
D1(config-if)# e x i t
D1(config)#
D1(config)# i n t e r f a c e G i g a b i t E t h e r n e t 1 / 0 / 1 8
D1(config-if)# d e s c r i p t i o n A c c e s s p o r t t o P C 2
D1(config-if)# s w i t c h p o r t m o d e a c c e s s
D1(config-if)# s w i t c h p o r t a c c e s s v l a n 2 0
D1(config-if)# e x i t
Step 4. Enable IP routing. Finally, enable IPv4 routing with the ip routing
global conguration command to allow trac to be exchanged between
VLANs 10 and 20, as shown in Example 4-16. This command must be
congured to enable inter-VAN routing on a Layer 3 switch for IPv4.
D1(config)# i p r o u t i n g
D1(config)#
[Link] 13/28
2021/2/17 Inter-VLAN Routing | Objectives
From a host, verify connectivity to a host in another VLAN using the ping
command. It is a good idea to rst verify the current host IP conguration using
the ipcong Windows host command. The output in Example 4-17 conrms the
IPv4 address and default gateway of PC1.
C:\Users\PC1> i p c o n f i g
Windows IP Configuration
Ethernet adapter Ethernet0:
Connection-specific DNS Suffix . :
Link-local IPv6 Address : fe80::5c43:ee7c:2959:da68%6
IPv4 Address : [Link]
Subnet Mask : [Link]
Default Gateway : [Link]
C:\Users\PC1>
Next, verify connectivity with PC2 using the ping Windows host command, as
shown in Example 4-18. The ping output successfully conrms that inter-VLAN
routing is operating.
C:\Users\PC1> p i n g 1 9 2 . 1 6 8 . 2 0 . 1 0
Pinging [Link] with 32 bytes of data:
Reply from [Link]: bytes=32 time<1ms TTL=127
Reply from [Link]: bytes=32 time<1ms TTL=127
Reply from [Link]: bytes=32 time<1ms TTL=127
Reply from [Link]: bytes=32 time<1ms TTL=127
Ping statistics for [Link]:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
C:\Users\PC1>
[Link] 14/28
2021/2/17 Inter-VLAN Routing | Objectives
NOTE
D1(config)# i n t e r f a c e G i g a b i t E t h e r n e t 1 / 0 / 1
D1(config-if)# d e s c r i p t i o n r o u t e d P o r t L i n k t o R 1
D1(config-if)# n o s w i t c h p o r t
D1(config-if)# i p a d d r e s s 1 0 . 1 0 . 1 0 . 2 2 5 5 . 2 5 5 . 2 5 5 . 0
D1(config-if)# n o s h u t
D1(config-if)# e x i t
D1(config)#
D1(config)# i p r o u t i n g
D1(config)#
D1(config)# r o u t e r o s p f 1 0
D1(config-router)# n e t w o r k 1 9 2 . 1 6 8 . 1 0 . 0 0 . 0 . 0 . 2 5 5 a r e a 0
D1(config-router)# n e t w o r k 1 9 2 . 1 6 8 . 2 0 . 0 0 . 0 . 0 . 2 5 5 a r e a 0
D1(config-router)# n e t w o r k 1 0 . 1 0 . 1 0 . 0 0 . 0 . 0 . 3 a r e a 0
D1(config-router)# ^ Z
D1#
*Sep 17 13:52:51.163: %OSPF-5-ADJCHG: Process 10, Nbr [Link] on
[Link] 15/28
2021/2/17 Inter-VLAN Routing | Objectives
Step 4. Verify routing. Verify the routing table on D1, as shown in Example
4-22. Notice that D1 now has a route to the [Link]/24 network.
D1# s h o w i p r o u t e | b e g i n G a t e w a y
Gateway of last resort is not set
[Link]/8 is variably subnetted, 3 subnets, 3 masks
C [Link]/30 is directly connected, GigabitEthernet1/0/1
L [Link]/32 is directly connected, GigabitEthernet1/0/1
O [Link]/24 [110/2] via [Link], 00:00:06, GigabitEthernet1/0/1
[Link]/24 is variably subnetted, 2 subnets, 2 masks
C [Link]/24 is directly connected, Vlan10
L [Link]/32 is directly connected, Vlan10
[Link]/24 is variably subnetted, 2 subnets, 2 masks
C [Link]/24 is directly connected, Vlan20
L [Link]/32 is directly connected, Vlan20
D1#
Step 5. Verify connectivity. At this time, PC1 and PC2 are able to ping the
server connected to R1, as shown in Example 4-23.
C:\Users\PC1> p i n g 1 0 . 2 0 . 2 0 . 2 5 4
Pinging [Link] with 32 bytes of data:
Request timed out.
Reply from [Link]: bytes=32 time<1ms TTL=127
Reply from [Link]: bytes=32 time<1ms TTL=127
Reply from [Link]: bytes=32 time<1ms TTL=127
Ping statistics for [Link]:
Packets: Sent = 4, Received = 3, Lost = 1 (25% loss).
Approximate round trip times in milli-seconds:
Minimum = 1ms, Maximum = 2ms, Average = 1ms
C:\Users\PC1>
!==================================================
C:\Users\PC2> ping [Link]
Pinging [Link] with 32 bytes of data:
Reply from [Link]: bytes=32 time<1ms TTL=127
Reply from [Link]: bytes=32 time<1ms TTL=127
Reply from [Link]: bytes=32 time<1ms TTL=127
Reply from [Link]: bytes=32 time<1ms TTL=127
Ping statistics for [Link]:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss).
Approximate round trip times in milli-seconds:
Minimum = 1ms, Maximum = 2ms, Average = 1ms
C:\Users\PC2>
In this Packet Tracer activity, you congure Layer 3 switching and Inter-VLAN
routing on a Cisco 3560 switch.
[Link] 16/28
2021/2/17 Inter-VLAN Routing | Objectives
There are a number of reasons why an inter-VAN conguration may not work.
All are related to connectivity issues. First, check the physical layer to resolve
any issues where a cable might be connected to the wrong port. If the
connections are correct, use the list in Table 4-4 for other common reasons why
inter-VLAN connectivity may fail.
The topology in Figure 4-8 will be used for all of these issues.
[Link] 17/28
2021/2/17 Inter-VLAN Routing | Objectives
The VLAN and IPv4 addressing information for R1 is shown in Table 4-5.
For example, PC1 is currently connected to VLAN 10, as shown in the show vlan
brief command output in Example 4-24.
S1# s h o w v l a n b r i e f
VLAN Name Status Ports
---- ------------------------------- --------- -------------------------------
1 default active Fa0/2, Fa0/3, Fa0/4, Fa0/7
Fa0/8, Fa0/9, Fa0/10, Fa0/11
Fa0/12, Fa0/13, Fa0/14, Fa0/15
Fa0/16, Fa0/17, Fa0/18, Fa0/19
Fa0/20, Fa0/21, Fa0/22, Fa0/23
Fa0/24, Gi0/1, Gi0/2
10 LAN10 active Fa0/6
20 LAN20 active
99 Management active
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
S1#
[Link] 18/28
2021/2/17 Inter-VLAN Routing | Objectives
S1(config)# n o v l a n 1 0
S1(config)# d o s h o w v l a n b r i e f
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Fa0/2, Fa0/3, Fa0/4, Fa0/7
Fa0/8, Fa0/9, Fa0/10, Fa0/11
Fa0/12, Fa0/13, Fa0/14, Fa0/15
Fa0/16, Fa0/17, Fa0/18, Fa0/19
Fa0/20, Fa0/21, Fa0/22, Fa0/23
Fa0/24, Gi0/1, Gi0/2
20 LAN20 active
99 Management active
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
S1(config)#
Notice that VLAN 10 is now missing from the output in Example 4-25. Also
notice that port Fa0/6 has not been reassigned to the default VLAN. The reason
is because when you delete a VLAN, any ports assigned to that VLAN become
inactive. They remain associated with the VLAN (and thus inactive) until you
assign them to a new VLAN or re-create the missing VLAN.
Use the show interface interface-id switchport command to verify the VLAN
membership, as shown in Example 4-26.
S1(config)# d o s h o w i n t e r f a c e f a 0 / 6 s w i t c h p o r t
Name: Fa0/6
Switchport: Enabled
Administrative Mode: static access
Operational Mode: static access
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: native
Negotiation of Trunking: Off
Access Mode VLAN: 10 (Inactive)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
(Output omitted)
Re-creating the missing VLAN would automatically reassign the hosts to it, as
shown in Example 4-27.
S1(config)# v l a n 1 0
S1(config-vlan)# d o s h o w v l a n b r i e f
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Fa0/2, Fa0/3, Fa0/4, Fa0/7
Fa0/8, Fa0/9, Fa0/10, Fa0/11
Fa0/12, Fa0/13, Fa0/14, Fa0/15
Fa0/16, Fa0/17, Fa0/18, Fa0/19
Fa0/20, Fa0/21, Fa0/22, Fa0/23
Fa0/24, Gi0/1, Gi0/2
20 LAN20 active
99 Management active
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
[Link] 19/28
2021/2/17 Inter-VLAN Routing | Objectives
Notice that the VLAN has not been created as expected. The reason is because
you must exit from VLAN sub-conguration mode to create the VLAN, as shown
in Example 4-28.
Example 4-28 Exit VLAN Conguration Mode and Then Re-create and
Verify VLAN
S1(config-vlan)# e x i t
S1(config)# v l a n 1 0
S1(config)# d o s h o w v l a n b r i e f
VLAN Name Status Ports
---- -------------------------------- --------- -------------------------------
1 default active Fa0/2, Fa0/3, Fa0/4, Fa0/7
Fa0/8, Fa0/9, Fa0/10, Fa0/11
Fa0/12, Fa0/13, Fa0/14, Fa0/15
Fa0/16, Fa0/17, Fa0/18, Fa0/19
Fa0/20, Fa0/21, Fa0/22, Fa0/23
Fa0/24, Gi0/1, Gi0/2
10 VLAN0010 active Fa0/6
20 LAN20 active
99 Management active
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup
S1(config)#
Now notice that the VLAN is included in the list and that the host connected to
Fa0/6 is on VLAN 10.
For example, assume PC1 was able to connect to hosts in other VLANs until
recently. A quick look at maintenance logs revealed that the S1 Layer 2 switch
was recently accessed for routine maintenance. Therefore, you suspect the
problem may be related to that switch.
On S1, verify that the port connecting to R1 (i.e., F0/5) is correctly congured as
a trunk link using the show interfaces trunk command, as shown in Example 4-
29.
S1# s h o w i n t e r f a c e s t r u n k
Port Mode Encapsulation Status Native vlan
Fa0/1 on 802.1q trunking 1
Port Vlans allowed on trunk
Fa0/1 1-4094
Port Vlans allowed and active in management domain
Fa0/1 1,10,20,99
Port Vlans in spanning tree forwarding state and not pruned
Fa0/1 1,10,20,99
S1#
The Fa0/5 port connecting to R1 is mysteriously missing from the output. Verify
the interface conguration using the show running-cong interface fa0/5
[Link] 20/28
2021/2/17 Inter-VLAN Routing | Objectives
S1# s h o w r u n n i n g - c o n f i g i n t e r f a c e f a 0 / 5
Building configuration...
Current configuration : 96 bytes
!
interface FastEthernet0/5
description Trunk link to R1
switchport mode trunk
shutdown
end
S1#
As you can see, the port was accidently shut down. To correct the problem,
reenable the port and verify the trunking status, as shown in Example 4-31.
S1(config)# i n t e r f a c e f a 0 / 5
S1(config-if)# n o s h u t
S1(config-if)#
*Mar 1 04:46:44.153: %LINK-3-UPDOWN: Interface FastEthernet0/5, changed state to
up
S1(config-if)#
*Mar 1 04:46:47.962: %LINEPROTO-5-UPDOWN: Line protocol on Interface
FastEthernet0/5, changed state to up
S1(config-if)# d o s h o w i n t e r f a c e t r u n k
Port Mode Encapsulation Status Native vlan
Fa0/1 on 802.1q trunking 1
Fa0/5 on 802.1q trunking 1
Port Vlans allowed on trunk
Fa0/1 1-4094
Fa0/5 1-4094
Port Vlans allowed and active in management domain
Fa0/1 1,10,20,99
Fa0/5 1,10,20,99
Port Vlans in spanning tree forwarding state and not pruned
Fa0/1 1,10,20,99
Fa0/1 1,10,20,99
S1(config-if)#
Assume PC1 has the correct IPv4 address and default gateway but is not able
to ping its own default gateway. PC1 is supposed to be connected to a VLAN 10
port.
S1# s h o w i n t e r f a c e f a 0 / 6 s w i t c h p o r t
Name: Fa0/6
Switchport: Enabled
Administrative Mode: static access
Operational Mode: static access
[Link] 21/28
2021/2/17 Inter-VLAN Routing | Objectives
The Fa0/6 port has been congured as an access port, as indicated by “static
access”. However, it appears that it has not been congured to be in VLAN 10.
Verify the conguration of the interface, as shown in Example 4-33.
S1# s h o w r u n n i n g - c o n f i g i n t e r f a c e f a 0 / 6
Building configuration...
Current configuration : 87 bytes
!
interface FastEthernet0/6
description PC-A access port
switchport mode access
end
S1#
Assign port Fa0/6 to VLAN 10 and verify the port assignment, as shown in
Example 4-34.
Example 4-34 Assign the VLAN to the Port and Verify the Conguration
S1# c o n f i g u r e t e r m i n a l
S1(config)# i n t e r f a c e f a 0 / 6
S1(config-if)# s w i t c h p o r t a c c e s s v l a n 1 0
S1(config-if)#
S1(config-if)# d o s h o w i n t e r f a c e f a 0 / 6 s w i t c h p o r t
Name: Fa0/6
Switchport: Enabled
Administrative Mode: static access
Operational Mode: static access
Administrative Trunking Encapsulation: dot1q
Operational Trunking Encapsulation: native
Negotiation of Trunking: Off
Access Mode VLAN: 10 (VLAN0010)
Trunking Native Mode VLAN: 1 (default)
Administrative Native VLAN tagging: enabled
Voice VLAN: none
(Output omitted)
For example, R1 should be providing inter-VLAN routing for users in VLANs 10,
20, and 99. However, users in VLAN 10 cannot reach any other VLAN.
You veried the switch trunk link and all appears to be in order. Verify the
subinterface status using the show ip interface brief command, as shown in
Example 4-35.
[Link] 22/28
2021/2/17 Inter-VLAN Routing | Objectives
R1# s h o w i p i n t e r f a c e b r i e f
Interface IP-Address OK? Method Status Protocol
GigabitEthernet0/0/0 unassigned YES unset administratively down down
GigabitEthernet0/0/1 unassigned YES unset up up
Gi0/0/1.10 [Link] YES manual up up
Gi0/0/1.20 [Link] YES manual up up
Gi0/0/1.99 [Link] YES manual up up
Serial0/1/0 unassigned YES unset administratively down down
Serial0/1/1 unassigned YES unset administratively down down
R1#
The subinterfaces have been assigned the correct IPv4 addresses, and they are
operational.
Verify which VLANs each of the subinterfaces is on. To do so, the show
interfaces command is useful, but it generates a great deal of additional
unrequired output. The command output can be reduced using IOS command
lters as shown in Example 4-36.
R1# s h o w i n t e r f a c e s | i n c l u d e G i g | 8 0 2 . 1 Q
GigabitEthernet0/0/0 is administratively down, line protocol is down
GigabitEthernet0/0/1 is up, line protocol is up
Encapsulation 802.1Q Virtual LAN, Vlan ID 1., loopback not set
GigabitEthernet0/0/1.10 is up, line protocol is up
Encapsulation 802.1Q Virtual LAN, Vlan ID 100.
GigabitEthernet0/0/1.20 is up, line protocol is up
Encapsulation 802.1Q Virtual LAN, Vlan ID 20.
GigabitEthernet0/0/1.99 is up, line protocol is up
Encapsulation 802.1Q Virtual LAN, Vlan ID 99.
R1#
The pipe symbol ( | ) along with some select keywords is a useful method to
help lter command output. In this example, the keyword include was used to
identify that only lines containing the letters “Gig” or “802.1Q” will be displayed.
Because of the way the show interface output is naturally listed, using these
lters produces a condensed list of interfaces and their assigned VLANs.
Notice that the G0/0/1.10 interface has been incorrectly assigned to VLAN 100
instead of VLAN 10. This is conrmed by looking at the conguration of the R1
GigabitEthernet 0/0/1.10 subinterface, as shown in Example 4-37.
R1# s h o w r u n n i n g - c o n f i g i n t e r f a c e g 0 / 0 / 1 . 1 0
Building configuration...
Current configuration : 146 bytes
!
interface GigabitEthernet0/0/1.10
description Default Gateway for VLAN 10
encapsulation dot1Q 100
ip address [Link] [Link]
end
R1#
[Link] 23/28
2021/2/17 Inter-VLAN Routing | Objectives
R1# c o n f t
Enter configuration commands, one per line. End with CNTL/Z.
R1(config)# i n t e r f a c e g i g a b i t E t h e r n e t 0 / 0 / 1 . 1 0
R1(config-subif)# e n c a p s u l a t i o n d o t 1 Q 1 0
R1(config-subif)# e n d
R1#
R1# s h o w i n t e r f a c e s | i n c l u d e G i g | 8 0 2 . 1 Q
GigabitEthernet0/0/0 is administratively down, line protocol is down
GigabitEthernet0/0/1 is up, line protocol is up
Encapsulation 802.1Q Virtual LAN, Vlan ID 1., loopback not set
GigabitEthernet0/0/1.10 is up, line protocol is up
Encapsulation 802.1Q Virtual LAN, Vlan ID 10.
GigabitEthernet0/0/1.20 is up, line protocol is up
Encapsulation 802.1Q Virtual LAN, Vlan ID 20.
GigabitEthernet0/0/1.99 is up, line protocol is up
R1#
When the subinterface has been assigned to the correct VLAN, it is accessible
by devices on that VLAN, and the router can perform inter-VLAN routing.
Summary (4.5)
The following is a summary of each section in the chapter:
routing is the process of forwarding network trac from one VLAN to another
VLAN. Three options include legacy, router-on-a-stick, and a Layer 3 switch
using SVIs. Legacy used a router with multiple Ethernet interfaces. Each router
interface was connected to a switch port in dierent VLANs. Requiring one
physical router interface per VLAN quickly exhausts the physical interface
capacity of a router. The router-on-a-stick inter-VLAN routing method requires
only one physical Ethernet interface to route trac between multiple VLANs on a
network. A Cisco IOS router Ethernet interface is congured as an 802.1Q trunk
and connected to a trunk port on a Layer 2 switch. The router interface is
congured using subinterfaces to identify routable VLANs. The congured
subinterfaces are software-based virtual interfaces associated with a single
physical Ethernet interface. The modern method is Inter-VLAN routing on a
Layer 3 switch using SVIs. The SVI is created for a VLAN that exists on the
switch. The SVI performs the same functions for the VLAN as a router interface.
It provides Layer 3 processing for packets being sent to or from all switch ports
associated with that VLAN.
[Link] 25/28
2021/2/17 Inter-VLAN Routing | Objectives
In this activity, you demonstrate and reinforce your ability to implement inter-
VLAN routing, including conguring IP addresses, VLANs, trunking, and
subinterfaces.
Practice
The following activities provide practice with the topics introduced in this
chapter. The Labs are available in the companion Switching, Routing, and
Wireless Essentials Labs and Study Guide (CCNAv7) (ISBN 9780136634386).
The Packet Tracer Activity instructions are also in the Labs & Study Guide. The
PKA les are found in the online course.
LABS
1. A router has two FastEthernet interfaces and needs to connect to four VLANs
in the local network. How can this be accomplished using the fewest number of
physical interfaces without unnecessarily decreasing network performance?
D. Use a hub to connect the four VLANS with a FastEthernet interface on the
router.
C. Traditional routing uses one port per logical network, whereas a router-
on-a-stick uses subinterfaces to connect multiple logical networks to a
single router port.
D. Traditional routing uses multiple paths to the router and therefore requires
STP, whereas router-on-a-stick does not provide multiple connections
and therefore eliminates the need for STP.
A. encapsulation dot1q 10
B. encapsulation vlan 10
5. What are the steps that must be completed in order to enable inter-VLAN
routing using router-on-a-stick?
B. Create the VLANs on the router and dene the port membership
assignments on the switch.
[Link] 27/28
2021/2/17 Inter-VLAN Routing | Objectives
6. What two statements are true regarding the use of subinterfaces for inter-
VLAN routing? (Choose two.)
D. It supports trunking.
10. What are two advantages of using a Layer 3 switch with SVIs for inter-VLAN
routing? (Choose two.)
[Link] 28/28