Enrutamiento entre VLANs: permitir que equipos de VLANs distintas se comuniquen. Dos métodos: Router-on-a-stick (con un router y subinterfaces) y SVIs (con un switch de capa 3).
Prerrequisitos
- VLANs creadas en el switch.
- Para Router-on-a-stick: un troncal entre el switch y el router.
- Para SVIs: un switch de capa 3 (multilayer).
- Activar o encender las interfaces fisicas primero del Switch y Router.
Configuración
Método 1 - Router-on-a-stick (RoaS)
Utilizamos una troncal entre un switch y un router. Se crean subinterfaces para cada VLAN, y cada subinterface será el gateway de una VLAN.
En el switch (lado trunk)
SW1(config)# interface fastEthernet 0/1 = Hacia el Router
SW1(config-if)# switchport trunk encapsulation dot1q
SW1(config-if)# switchport mode trunk
SW1(config-if)# switchport trunk native vlan <Numero-VLAN-Nativa>
SW1(config-if)# switchport trunk allowed vlan <Numero-VLAN>
En switchport trunk allowed vlan, pueden ser varias VLANs.
En el router (subinterfaces)
Router(config)# interface <nombre-interface.número-subinterface> = Camino hacia el Switch
Router(config-subif)# encapsulation dot1q <número-vlan>
Router(config-subif)# ip address <IP> <máscara>
Ejemplo (VLAN 10 y VLAN 20):
Router(config)# interface fastEthernet 0/0
Router(config-if)# no shutdown
Router(config-if)# exit
Router(config)# interface fastethernet0/0.10
Router(config-subif)# encapsulation dot1q 10
Router(config-subif)# ip address 192.168.10.1 255.255.255.0
Router(config)# interface fastethernet0/0.20
Router(config-subif)# encapsulation dot1q 20
Router(config-subif)# ip address 192.168.20.1 255.255.255.0
Router(config)# interface fastEthernet 0/0.99
Router(config-subif)# encapsulation dot1q 99 native
Router(config-subif)# ip address 192.168.99.1 255.255.255.0
Para la VLAN nativa del troncal, la subinterface usa
encapsulation dot1q <vlan> native.
Método 2 - SVIs (Switched Virtual Interfaces) = IP de Gestion
En un switch de capa 3 se crea una interface VLAN (SVI) por cada VLAN, que actúa como gateway, y se habilita el enrutamiento.
Switch(config)# interface vlan <número-de-vlan>
Switch(config-if)# ip address <IPv4> <máscara>
Switch(config)# ip routing
Switch(config)# interface vlan 10
Switch(config-if)# ip address 192.168.10.1 255.255.255.0
Switch(config-if)# no shutdown
Switch(config-if)# exit
ip routinghabilita el enrutamiento entre las SVIs (en un switch de capa 3 suele venir desactivado por defecto).
Para colocarle Gateway al Switch, ir a Configuracion Basica del Switch.
Importante una vez configurado (VLANs)
SW1(config-if)# switchport trunk allowed vlan 10,20,99 = Define la lista completa.
SW1(config-if)# switchport trunk allowed vlan add 30 = Agrega sin borrar las demás VLANs, (Add).
Ejemplos
Ejemplo 1 - Router-on-a-stick para dos VLANs
Topología: SW1 tiene la VLAN 10 (MKT, 192.168.10.0/24) y VLAN 20 (ING, 192.168.20.0/24). El enlace SW1 Fa0/1 ↔ R1 Fa0/0 es troncal. R1 enruta entre ambas VLANs con subinterfaces.
En SW1 (troncal hacia el router):
SW1(config)# interface fastEthernet 0/1
SW1(config-if)# switchport trunk encapsulation dot1q
SW1(config-if)# switchport mode trunk
SW1(config-if)# end
En R1 (subinterfaces = gateways):
R1# configure terminal
R1(config)# interface fastethernet0/0
R1(config-if)# no shutdown
R1(config-if)# exit
R1(config)# interface fastethernet0/0.10
R1(config-subif)# encapsulation dot1q 10
R1(config-subif)# ip address 192.168.10.1 255.255.255.0
R1(config-subif)# exit
R1(config)# interface fastethernet0/0.20
R1(config-subif)# encapsulation dot1q 20
R1(config-subif)# ip address 192.168.20.1 255.255.255.0
R1(config-subif)# end
R1# copy running-config startup-config
Cada PC usa como gateway la IP de la subinterface de su VLAN (192.168.10.1 o 192.168.20.1).
Ejemplo 2 - Inter-VLAN con SVIs en un switch de capa 3
Topología: SW-L3 es un switch multicapa. Enruta entre VLAN 10 y VLAN 20 con SVIs.
SW-L3# configure terminal
! Habilitar enrutamiento
SW-L3(config)# ip routing
! SVI de la VLAN 10 (gateway 192.168.10.1)
SW-L3(config)# interface vlan 10
SW-L3(config-if)# ip address 192.168.10.1 255.255.255.0
SW-L3(config-if)# no shutdown
SW-L3(config-if)# exit
! SVI de la VLAN 20 (gateway 192.168.20.1)
SW-L3(config)# interface vlan 20
SW-L3(config-if)# ip address 192.168.20.1 255.255.255.0
SW-L3(config-if)# no shutdown
SW-L3(config-if)# end
SW-L3# write memory
Recuerda que cada SVI sube solo si su VLAN tiene al menos un puerto activo.
Verificación
¿Las redes de las VLANs están en la tabla de rutas (como conectadas)?
R1# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2
i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
ia - IS-IS inter area, * - candidate default, U - per-user static route
o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
+ - replicated route, % - next hop override
Gateway of last resort is not set
192.168.10.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.10.0/24 is directly connected, FastEthernet0/0.10
L 192.168.10.1/32 is directly connected, FastEthernet0/0.10
192.168.20.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.20.0/24 is directly connected, FastEthernet0/0.20
L 192.168.20.1/32 is directly connected, FastEthernet0/0.20
192.168.99.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.99.0/24 is directly connected, FastEthernet0/0.99
L 192.168.99.1/32 is directly connected, FastEthernet0/0.99
Estado de las subinterfaces / SVIs
R1# show ip interface brief
Interface IP-Address OK? Method Status Protocol
FastEthernet0/0 unassigned YES unset up up
FastEthernet0/0.10 192.168.10.1 YES manual up up
FastEthernet0/0.20 192.168.20.1 YES manual up up
FastEthernet0/0.99 192.168.99.1 YES manual up up
FastEthernet0/1 unassigned YES unset administratively down down
Serial0/0/0 unassigned YES unset administratively down down
Prueba entre VLANs
- Comando:
Router# ping <IP> - Ejemplo:
Router# ping 192.168.20.50
Qué deberías ver:
- Las redes de cada VLAN como
C(directamente conectadas) en la tabla de rutas. - Las subinterfaces (RoaS) o las SVIs (capa 3) en estado up/up.
- Ping exitoso entre un host de la VLAN 10 y uno de la VLAN 20.