<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Vlan Routing Issue in Switches, Hubs, and Modems</title>
    <link>https://community.hpe.com/t5/switches-hubs-and-modems/vlan-routing-issue/m-p/4210516#M14439</link>
    <description>Hi All.&lt;BR /&gt;&lt;BR /&gt;I'm setting up a 5300xl switch for a shared environment, where each vlan must NOT be able to see any other vlan apart from the vlan with the router in it.&lt;BR /&gt;&lt;BR /&gt;Config is as follows:&lt;BR /&gt;&lt;BR /&gt;Running configuration:&lt;BR /&gt;&lt;BR /&gt;; J4819A Configuration Editor; Created on release #E.10.37&lt;BR /&gt;&lt;BR /&gt;hostname "HP ProCurve Switch 5308xl" &lt;BR /&gt;module 2 type J4820B &lt;BR /&gt;module 3 type J4820B &lt;BR /&gt;module 4 type J4820B &lt;BR /&gt;module 5 type J4820B &lt;BR /&gt;module 7 type J4820B &lt;BR /&gt;module 8 type J4820B &lt;BR /&gt;ip routing &lt;BR /&gt;snmp-server community "public" Unrestricted &lt;BR /&gt;vlan 1 &lt;BR /&gt;   name "DEFAULT_VLAN" &lt;BR /&gt;   untagged B1-B24,C1-C24,D1-D24,E5-E24,G1-G24,H1-H14 &lt;BR /&gt;   ip address 192.168.1.2 255.255.255.0 &lt;BR /&gt;   no untagged E1-E4,H15-H24 &lt;BR /&gt;   exit &lt;BR /&gt;vlan 2 &lt;BR /&gt;   name "systemcore" &lt;BR /&gt;   untagged H15-H23&lt;BR /&gt;   ip address 172.20.1.30 255.255.255.224 &lt;BR /&gt;   exit &lt;BR /&gt;vlan 3 &lt;BR /&gt;   name "dirtyserve" &lt;BR /&gt;   untagged H24 &lt;BR /&gt;   ip address 172.20.0.253 255.255.255.248 &lt;BR /&gt;   exit &lt;BR /&gt;vlan 4 &lt;BR /&gt;   name "rm212-213" &lt;BR /&gt;   untagged E1-E4 &lt;BR /&gt;   ip address 172.20.2.254 255.255.255.0 &lt;BR /&gt;   ip helper-address 172.20.1.1 &lt;BR /&gt;   exit &lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 172.20.0.254 &lt;BR /&gt;password manager&lt;BR /&gt;&lt;BR /&gt;a sh ip route shows:  &lt;BR /&gt;&lt;BR /&gt;HP ProCurve Switch 5308xl# sh ip route&lt;BR /&gt;&lt;BR /&gt;                                IP Route Entries&lt;BR /&gt;&lt;BR /&gt;  Destination        Gateway         VLAN Type      Sub-Type   Metric     Dist.&lt;BR /&gt;  ------------------ --------------- ---- --------- ---------- ---------- -----&lt;BR /&gt;  0.0.0.0/0          172.20.0.254    3    static               1          1    &lt;BR /&gt;  127.0.0.0/8        reject               static               0          250  &lt;BR /&gt;  127.0.0.1/32       lo0                  connected            0          0    &lt;BR /&gt;  172.20.0.248/29    dirtyserve      3    connected            0          0    &lt;BR /&gt;  172.20.1.0/27      systemcore      2    connected            0          0    &lt;BR /&gt;  172.20.2.0/24      rm212-213       4    connected            0          0   &lt;BR /&gt;&lt;BR /&gt;now ideally I would like it that each vlan can see the internet, but the vlans cannot see each other (obviously with the exception of IP helpers)&lt;BR /&gt;&lt;BR /&gt;I'm sure I'm missing something really simple with the config I have.&lt;BR /&gt;&lt;BR /&gt;I have tried removing the IP address from the vlan, but that also stops internet access.&lt;BR /&gt;&lt;BR /&gt;all ideas appreciated.&lt;BR /&gt;</description>
    <pubDate>Wed, 04 Jun 2008 12:52:03 GMT</pubDate>
    <dc:creator>Mike Hyslop</dc:creator>
    <dc:date>2008-06-04T12:52:03Z</dc:date>
    <item>
      <title>Vlan Routing Issue</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/vlan-routing-issue/m-p/4210516#M14439</link>
      <description>Hi All.&lt;BR /&gt;&lt;BR /&gt;I'm setting up a 5300xl switch for a shared environment, where each vlan must NOT be able to see any other vlan apart from the vlan with the router in it.&lt;BR /&gt;&lt;BR /&gt;Config is as follows:&lt;BR /&gt;&lt;BR /&gt;Running configuration:&lt;BR /&gt;&lt;BR /&gt;; J4819A Configuration Editor; Created on release #E.10.37&lt;BR /&gt;&lt;BR /&gt;hostname "HP ProCurve Switch 5308xl" &lt;BR /&gt;module 2 type J4820B &lt;BR /&gt;module 3 type J4820B &lt;BR /&gt;module 4 type J4820B &lt;BR /&gt;module 5 type J4820B &lt;BR /&gt;module 7 type J4820B &lt;BR /&gt;module 8 type J4820B &lt;BR /&gt;ip routing &lt;BR /&gt;snmp-server community "public" Unrestricted &lt;BR /&gt;vlan 1 &lt;BR /&gt;   name "DEFAULT_VLAN" &lt;BR /&gt;   untagged B1-B24,C1-C24,D1-D24,E5-E24,G1-G24,H1-H14 &lt;BR /&gt;   ip address 192.168.1.2 255.255.255.0 &lt;BR /&gt;   no untagged E1-E4,H15-H24 &lt;BR /&gt;   exit &lt;BR /&gt;vlan 2 &lt;BR /&gt;   name "systemcore" &lt;BR /&gt;   untagged H15-H23&lt;BR /&gt;   ip address 172.20.1.30 255.255.255.224 &lt;BR /&gt;   exit &lt;BR /&gt;vlan 3 &lt;BR /&gt;   name "dirtyserve" &lt;BR /&gt;   untagged H24 &lt;BR /&gt;   ip address 172.20.0.253 255.255.255.248 &lt;BR /&gt;   exit &lt;BR /&gt;vlan 4 &lt;BR /&gt;   name "rm212-213" &lt;BR /&gt;   untagged E1-E4 &lt;BR /&gt;   ip address 172.20.2.254 255.255.255.0 &lt;BR /&gt;   ip helper-address 172.20.1.1 &lt;BR /&gt;   exit &lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 172.20.0.254 &lt;BR /&gt;password manager&lt;BR /&gt;&lt;BR /&gt;a sh ip route shows:  &lt;BR /&gt;&lt;BR /&gt;HP ProCurve Switch 5308xl# sh ip route&lt;BR /&gt;&lt;BR /&gt;                                IP Route Entries&lt;BR /&gt;&lt;BR /&gt;  Destination        Gateway         VLAN Type      Sub-Type   Metric     Dist.&lt;BR /&gt;  ------------------ --------------- ---- --------- ---------- ---------- -----&lt;BR /&gt;  0.0.0.0/0          172.20.0.254    3    static               1          1    &lt;BR /&gt;  127.0.0.0/8        reject               static               0          250  &lt;BR /&gt;  127.0.0.1/32       lo0                  connected            0          0    &lt;BR /&gt;  172.20.0.248/29    dirtyserve      3    connected            0          0    &lt;BR /&gt;  172.20.1.0/27      systemcore      2    connected            0          0    &lt;BR /&gt;  172.20.2.0/24      rm212-213       4    connected            0          0   &lt;BR /&gt;&lt;BR /&gt;now ideally I would like it that each vlan can see the internet, but the vlans cannot see each other (obviously with the exception of IP helpers)&lt;BR /&gt;&lt;BR /&gt;I'm sure I'm missing something really simple with the config I have.&lt;BR /&gt;&lt;BR /&gt;I have tried removing the IP address from the vlan, but that also stops internet access.&lt;BR /&gt;&lt;BR /&gt;all ideas appreciated.&lt;BR /&gt;</description>
      <pubDate>Wed, 04 Jun 2008 12:52:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/vlan-routing-issue/m-p/4210516#M14439</guid>
      <dc:creator>Mike Hyslop</dc:creator>
      <dc:date>2008-06-04T12:52:03Z</dc:date>
    </item>
    <item>
      <title>Re: Vlan Routing Issue</title>
      <link>https://community.hpe.com/t5/switches-hubs-and-modems/vlan-routing-issue/m-p/4210517#M14440</link>
      <description>You'll need to create some access control lists to do this. I would deny the other VLANs IP address ranges and permit ip any any to allow Internet access, and then apply it incoming to each VLAN.&lt;BR /&gt;&lt;BR /&gt;e.g.&lt;BR /&gt;deny ip any 192.168.1.0/24&lt;BR /&gt;permit ip any any&lt;BR /&gt;&lt;BR /&gt;That's not complete but it should get you started.</description>
      <pubDate>Wed, 04 Jun 2008 13:55:22 GMT</pubDate>
      <guid>https://community.hpe.com/t5/switches-hubs-and-modems/vlan-routing-issue/m-p/4210517#M14440</guid>
      <dc:creator>Matt Hobbs</dc:creator>
      <dc:date>2008-06-04T13:55:22Z</dc:date>
    </item>
  </channel>
</rss>

