Network Access // Lesson 03

Inter-VLAN
Routing.

VLANs deliberately separate Layer 2 networks. A trunk can carry those VLANs between switches, but it does not allow one VLAN to communicate with another. For that, we need Layer 3 routing.

Default gateways Router-on-a-stick Subinterfaces SVIs Layer 3 switching Cisco IOS
01 // The problem

VLAN 10 cannot simply talk to VLAN 20.

Consider two hosts:

VLAN 10

PC-A

IP address: 192.168.10.10/24
Gateway: 192.168.10.1

VLAN 20

PC-B

IP address: 192.168.20.10/24
Gateway: 192.168.20.1

These hosts are in different IP networks and different VLANs. A Layer 2 switch cannot simply bridge traffic from VLAN 10 into VLAN 20.

Key idea: communication between different IP networks requires a Layer 3 routing function.
02 // Follow the host

How does PC-A know it needs a router?

PC-A wants to send traffic to 192.168.20.10. Using its own IP address and subnet mask, it determines that the destination is not on its local subnet.

Instead of trying to deliver the packet directly to PC-B, PC-A sends the traffic toward its default gateway.

01PC-A
192.168.10.10
02Destination is remote
03Use default gateway
04Router routes packet
05PC-B
192.168.20.10
Remember: the host's default gateway must be reachable within the host's own IP subnet.
03 // Methods

How can we route between VLANs?

LEGACY

One router interface per VLAN

Each VLAN connects to a separate physical router interface. It works, but requires lots of interfaces and cabling.

ROAS

Router-on-a-stick

One physical router interface carries multiple VLANs using an 802.1Q trunk and logical subinterfaces.

L3 SWITCH

SVIs

A multilayer switch can route internally between VLANs using switched virtual interfaces.

04 // Router-on-a-stick

One router interface. Multiple VLANs.

PC-A192.168.10.10
VLAN 10

PC-B192.168.20.10
VLAN 20
SW1 Layer 2 switch
R1 802.1Q subinterfaces

The switch-to-router link is configured as an 802.1Q trunk. The router then creates a logical subinterface for each VLAN.

Each subinterface can have an IP address that acts as the default gateway for hosts in that VLAN.

05 // Configure

Configure the switch side.

Suppose Gi0/1 connects SW1 to the router. The switch interface needs to carry VLANs 10 and 20.

SW1> enable
SW1# configure terminal

SW1(config)# interface gigabitEthernet 0/1
SW1(config-if)# switchport mode trunk
SW1(config-if)# switchport trunk allowed vlan 10,20
SW1(config-if)# no shutdown

This should look familiar from Lesson 02: the router-facing switchport is carrying multiple VLANs, so it is a trunk.

06 // Configure

Create router subinterfaces.

Assume the router connects using GigabitEthernet0/0. First enable the physical interface:

R1> enable
R1# configure terminal

R1(config)# interface gigabitEthernet 0/0
R1(config-if)# no shutdown

Now create a subinterface for VLAN 10:

R1(config)# interface gigabitEthernet 0/0.10
R1(config-subif)# encapsulation dot1Q 10
R1(config-subif)# ip address 192.168.10.1 255.255.255.0

And VLAN 20:

R1(config)# interface gigabitEthernet 0/0.20
R1(config-subif)# encapsulation dot1Q 20
R1(config-subif)# ip address 192.168.20.1 255.255.255.0
Read the command literally: encapsulation dot1Q 10 associates that subinterface with 802.1Q VLAN 10.
07 // Gateways

The router becomes the gateway.

VLAN Network Router interface Host gateway
10 192.168.10.0/24 Gi0/0.10 192.168.10.1
20 192.168.20.0/24 Gi0/0.20 192.168.20.1

PC-A uses 192.168.10.1 as its gateway, while PC-B uses 192.168.20.1.

The router has an interface in both IP networks, which allows it to route packets between them.

08 // Follow the packet

VLAN 10 → VLAN 20.

1. PC-A wants to reach 192.168.20.10.

2. PC-A recognises that 192.168.20.10 is outside its 192.168.10.0/24 subnet.

3. PC-A sends the packet in an Ethernet frame addressed toward its default gateway.

4. SW1 forwards the VLAN 10 traffic toward R1 over the trunk.

5. R1 receives it on the VLAN 10 subinterface and examines the destination IP address.

6. R1's routing table identifies 192.168.20.0/24 as a connected network through the VLAN 20 subinterface.

7. R1 builds a new Layer 2 frame for the outgoing VLAN 20 segment and forwards the packet back across the trunk.

8. SW1 forwards the frame within VLAN 20 toward PC-B.

Important: the IP packet is being routed, while the Layer 2 Ethernet framing changes as the packet moves between Layer 3 interfaces.
09 // Verify ROAS

Check the router.

A very useful first command is:

R1# show ip interface brief

Interface              IP-Address      OK? Method Status  Protocol
GigabitEthernet0/0     unassigned      YES unset  up      up
GigabitEthernet0/0.10  192.168.10.1    YES manual up      up
GigabitEthernet0/0.20  192.168.20.1    YES manual up      up

The routing table should also contain both directly connected networks:

R1# show ip route connected

C    192.168.10.0/24 is directly connected, GigabitEthernet0/0.10
C    192.168.20.0/24 is directly connected, GigabitEthernet0/0.20

And don't forget the switch side:

SW1# show interfaces trunk
10 // Layer 3 switches

Routing without an external router.

A multilayer switch can perform both Layer 2 switching and Layer 3 routing. Instead of sending inter-VLAN traffic to an external router, we can create switched virtual interfaces (SVIs).

VLAN 10 192.168.10.0/24
Layer 3 Switch VLAN 10 SVI
VLAN 20 SVI
VLAN 20 192.168.20.0/24

An SVI is a logical Layer 3 interface associated with a VLAN.

11 // Configure SVIs

Give each VLAN a Layer 3 interface.

First create the VLANs if required:

SW1(config)# vlan 10
SW1(config-vlan)# name STAFF
SW1(config-vlan)# exit

SW1(config)# vlan 20
SW1(config-vlan)# name GUEST

Now create the SVIs:

SW1(config)# interface vlan 10
SW1(config-if)# ip address 192.168.10.1 255.255.255.0
SW1(config-if)# no shutdown

SW1(config)# interface vlan 20
SW1(config-if)# ip address 192.168.20.1 255.255.255.0
SW1(config-if)# no shutdown

On a Layer 3 switch, enable IPv4 routing:

SW1(config)# ip routing
Easy one to forget: creating SVIs does not by itself guarantee that the switch will route IPv4 traffic between them. On a multilayer switch, ip routing enables IPv4 routing.
12 // Router-on-a-stick vs SVI

Same goal. Different architecture.

Feature Router-on-a-stick Layer 3 switch
Layer 3 device External router Multilayer switch
Gateway interfaces Router subinterfaces SVIs
VLAN transport 802.1Q trunk to router Routing can occur internally
Key command encapsulation dot1Q interface vlan + ip routing
Physical router links One trunk can serve many VLANs No external router required for local inter-VLAN routing
13 // SVI state

Why is my SVI down?

Configuring interface vlan 10 does not necessarily mean the SVI will immediately become operational.

In a typical Cisco switching scenario, the VLAN must exist and the switch needs an active Layer 2 port in that VLAN (or a trunk carrying it) for the SVI line protocol to come up, assuming the SVI itself is not shut down.

SW1# show ip interface brief

Interface              IP-Address      OK? Method Status  Protocol
Vlan10                 192.168.10.1    YES manual up      up
Vlan20                 192.168.20.1    YES manual up      up
If an SVI is unexpectedly down, check both the Layer 3 interface configuration and the underlying VLAN/Layer 2 state.
14 // Troubleshooting

The VLANs still can't communicate.

CHECK 01

Host addressing

Check the IP address, subnet mask and especially the default gateway.

CHECK 02

VLAN membership

Use show vlan brief to verify access ports and VLAN existence.

CHECK 03

Trunk

For router-on-a-stick, verify that the required VLANs are allowed across the switch-to-router trunk.

CHECK 04

dot1Q VLAN

Check that each router subinterface has the correct encapsulation dot1Q VLAN ID.

CHECK 05

Interfaces

Use show ip interface brief and look for interfaces that are down or administratively down.

CHECK 06

Routing enabled?

On a multilayer switch, confirm that Layer 3 routing is enabled with ip routing.

15 // Exam traps

Things worth remembering.

  • Different VLANs are separate Layer 2 broadcast domains.
  • A trunk does not route between VLANs.
  • Inter-VLAN communication requires a Layer 3 function.
  • Router-on-a-stick uses router subinterfaces over an 802.1Q trunk.
  • encapsulation dot1Q 10 associates a router subinterface with VLAN 10.
  • Each VLAN normally has its own IP subnet and default gateway.
  • A Layer 3 switch can use SVIs as VLAN gateway interfaces.
  • interface vlan 10 creates/configures an SVI — it does not configure a physical switchport.
  • On a multilayer switch, ip routing enables IPv4 routing.
  • When a packet is routed between VLANs, the Layer 2 framing changes even though the Layer 3 packet continues toward its destination.
16 // Quick reference

Commands to remember.

# Switch trunk toward router
interface gigabitEthernet 0/1
 switchport mode trunk
 switchport trunk allowed vlan 10,20

# Router-on-a-stick
interface gigabitEthernet 0/0.10
 encapsulation dot1Q 10
 ip address 192.168.10.1 255.255.255.0

interface gigabitEthernet 0/0.20
 encapsulation dot1Q 20
 ip address 192.168.20.1 255.255.255.0

# Layer 3 switch SVI
interface vlan 10
 ip address 192.168.10.1 255.255.255.0
 no shutdown

# Enable IPv4 routing on multilayer switch
ip routing

# Verification
show vlan brief
show interfaces trunk
show ip interface brief
show ip route
17 // Test yourself

Inter-VLAN routing quick quiz

1. What is required for hosts in different VLANs to communicate?

2. What does router-on-a-stick use to represent multiple VLANs on one physical router interface?

3. What does this command do: encapsulation dot1Q 20?

4. What is an SVI?

5. Which command enables IPv4 routing on a Cisco multilayer switch?

6. A host is 192.168.10.50/24. Which gateway is valid for that host?

7. Which statement about a trunk is correct?

Score: 0 / 7