Switches, Hubs, and Modems
Showing results for 
Search instead for 
Did you mean: 

Routing between VLANs on 4208VL

Go to solution
Occasional Visitor

Routing between VLANs on 4208VL



I'm having trouble configuring routing between VLANs on a 4208VL

show run:


; J8773A Configuration Editor; Created on release #L.11.20

hostname "HP_CORESWITCH 4208VL"
module 3 type J8768A
module 4 type J8768A
module 2 type J8776A
module 1 type J8776A
ip default-gateway
ip routing
snmp-server community "public" Unrestricted
vlan 1
  untagged A1-A4,B1-B4,C1-C24,D1-D24
  ip address
vlan 2000
  name "vMotion"
  tagged C19-C24,D19-D24
vlan 2
  name "PROD_FTS"
  ip address
  tagged C19-C24,D19-D24
ip route
management-vlan 1
ip ssh



Hosts on vlan 1 CANNOT ping Hosts on vlan 2 and vice versa.

Hosts on vlan 1 and vlan 2 CAN ping the IP of the switch

Hosts on vlan 1 and vlan 2 CAN ping the default Gateway (

I CAN ping the default gateway from the Switch


I tried to move the management vlan to a separate vlan, but then I cannot connect to the switch anymore.


Host configuration hast been triple checked and seems ok,


Any hints?




Re: Routing between VLANs on 4208VL

Hello Slainte,


This is a common issue with misunderstanding the purpose of the Management VLAN.


Let me paste the description from the Management Guide...

The Secure Management VLAN: This optional, port-based VLAN establishes

an isolated network for managing the ProCurve switches that

support this feature. Access to this VLAN and to the switch’s management

functions are available only through ports configured as members (page



Important to note is that this feature is intended to ISOLATE THE VLAN. That means no traffic will go in and out, and that is done on purpose so that no network users can capture your management traffic and thus cause a potential security breach!

The Management VLAN should be set up (if deemed necessary) on a separate VLAN used only for Switch Management purposes. For example you could put a single PC/Server in the Server Room into this VLAN so that it has exclusive Management access to the switch, and your users on the network don't even get the opportunity to try to access the management of your switch (and thus fool around where they shouldn't be), since it won't allow them.


Does that make sense? I hope it's pretty clear now :)

Best regards,

Working @ HPE
Accept or Kudo
Occasional Visitor

Re: Routing between VLANs on 4208VL

> Does that make sense? I hope it's pretty clear now :)

Yes it is, thanks for the answer - it's working now :)