Enrutamiento entre VLANs: permitir que equipos de VLANs distintas se comuniquen. Dos métodos: Router-on-a-stick (con un router y subinterfaces) y SVIs (con un switch de capa 3).

Prerrequisitos

  • VLANs creadas en el switch.
  • Para Router-on-a-stick: un troncal entre el switch y el router.
  • Para SVIs: un switch de capa 3 (multilayer).
  • Activar o encender las interfaces fisicas primero del Switch y Router.

Configuración

Método 1 - Router-on-a-stick (RoaS)

Utilizamos una troncal entre un switch y un router. Se crean subinterfaces para cada VLAN, y cada subinterface será el gateway de una VLAN.

En el switch (lado trunk)

SW1(config)# interface fastEthernet 0/1 = Hacia el Router
SW1(config-if)# switchport trunk encapsulation dot1q
SW1(config-if)# switchport mode trunk
SW1(config-if)# switchport trunk native vlan <Numero-VLAN-Nativa>
SW1(config-if)# switchport trunk allowed vlan <Numero-VLAN>

En switchport trunk allowed vlan, pueden ser varias VLANs.

En el router (subinterfaces)

Router(config)# interface <nombre-interface.número-subinterface> = Camino hacia el Switch
Router(config-subif)# encapsulation dot1q <número-vlan>
Router(config-subif)# ip address <IP> <máscara>

Ejemplo (VLAN 10 y VLAN 20):

Router(config)# interface fastEthernet 0/0 
Router(config-if)# no shutdown 
Router(config-if)# exit

Router(config)# interface fastethernet0/0.10
Router(config-subif)# encapsulation dot1q 10
Router(config-subif)# ip address 192.168.10.1 255.255.255.0

Router(config)# interface fastethernet0/0.20
Router(config-subif)# encapsulation dot1q 20
Router(config-subif)# ip address 192.168.20.1 255.255.255.0

Router(config)# interface fastEthernet 0/0.99 
Router(config-subif)# encapsulation dot1q 99 native 
Router(config-subif)# ip address 192.168.99.1 255.255.255.0 

Para la VLAN nativa del troncal, la subinterface usa encapsulation dot1q <vlan> native.

Método 2 - SVIs (Switched Virtual Interfaces) = IP de Gestion

En un switch de capa 3 se crea una interface VLAN (SVI) por cada VLAN, que actúa como gateway, y se habilita el enrutamiento.

Switch(config)# interface vlan <número-de-vlan>
Switch(config-if)# ip address <IPv4> <máscara>

Switch(config)# ip routing
Switch(config)# interface vlan 10 
Switch(config-if)# ip address 192.168.10.1 255.255.255.0 
Switch(config-if)# no shutdown 
Switch(config-if)# exit

ip routing habilita el enrutamiento entre las SVIs (en un switch de capa 3 suele venir desactivado por defecto).
Para colocarle Gateway al Switch, ir a Configuracion Basica del Switch.

Importante una vez configurado (VLANs)

SW1(config-if)# switchport trunk allowed vlan 10,20,99 = Define la lista completa.
SW1(config-if)# switchport trunk allowed vlan add 30 = Agrega sin borrar las demás VLANs, (Add).

Ejemplos

Ejemplo 1 - Router-on-a-stick para dos VLANs

Topología: SW1 tiene la VLAN 10 (MKT, 192.168.10.0/24) y VLAN 20 (ING, 192.168.20.0/24). El enlace SW1 Fa0/1 ↔ R1 Fa0/0 es troncal. R1 enruta entre ambas VLANs con subinterfaces.

En SW1 (troncal hacia el router):

SW1(config)# interface fastEthernet 0/1
SW1(config-if)# switchport trunk encapsulation dot1q
SW1(config-if)# switchport mode trunk
SW1(config-if)# end

En R1 (subinterfaces = gateways):

R1# configure terminal
R1(config)# interface fastethernet0/0
R1(config-if)# no shutdown
R1(config-if)# exit

R1(config)# interface fastethernet0/0.10
R1(config-subif)# encapsulation dot1q 10
R1(config-subif)# ip address 192.168.10.1 255.255.255.0
R1(config-subif)# exit

R1(config)# interface fastethernet0/0.20
R1(config-subif)# encapsulation dot1q 20
R1(config-subif)# ip address 192.168.20.1 255.255.255.0
R1(config-subif)# end
R1# copy running-config startup-config

Cada PC usa como gateway la IP de la subinterface de su VLAN (192.168.10.1 o 192.168.20.1).

Ejemplo 2 - Inter-VLAN con SVIs en un switch de capa 3

Topología: SW-L3 es un switch multicapa. Enruta entre VLAN 10 y VLAN 20 con SVIs.

SW-L3# configure terminal

! Habilitar enrutamiento
SW-L3(config)# ip routing

! SVI de la VLAN 10 (gateway 192.168.10.1)
SW-L3(config)# interface vlan 10
SW-L3(config-if)# ip address 192.168.10.1 255.255.255.0
SW-L3(config-if)# no shutdown
SW-L3(config-if)# exit

! SVI de la VLAN 20 (gateway 192.168.20.1)
SW-L3(config)# interface vlan 20
SW-L3(config-if)# ip address 192.168.20.1 255.255.255.0
SW-L3(config-if)# no shutdown
SW-L3(config-if)# end
SW-L3# write memory

Recuerda que cada SVI sube solo si su VLAN tiene al menos un puerto activo.

Verificación

¿Las redes de las VLANs están en la tabla de rutas (como conectadas)?

R1# show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
       E1 - OSPF external type 1, E2 - OSPF external type 2
       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
       ia - IS-IS inter area, * - candidate default, U - per-user static route
       o - ODR, P - periodic downloaded static route, H - NHRP, l - LISP
       + - replicated route, % - next hop override

Gateway of last resort is not set

      192.168.10.0/24 is variably subnetted, 2 subnets, 2 masks
C        192.168.10.0/24 is directly connected, FastEthernet0/0.10
L        192.168.10.1/32 is directly connected, FastEthernet0/0.10
      192.168.20.0/24 is variably subnetted, 2 subnets, 2 masks
C        192.168.20.0/24 is directly connected, FastEthernet0/0.20
L        192.168.20.1/32 is directly connected, FastEthernet0/0.20
      192.168.99.0/24 is variably subnetted, 2 subnets, 2 masks
C        192.168.99.0/24 is directly connected, FastEthernet0/0.99
L        192.168.99.1/32 is directly connected, FastEthernet0/0.99

Estado de las subinterfaces / SVIs

R1# show ip interface brief
Interface              IP-Address      OK? Method Status                Protocol
FastEthernet0/0        unassigned      YES unset  up                    up
FastEthernet0/0.10     192.168.10.1    YES manual up                    up
FastEthernet0/0.20     192.168.20.1    YES manual up                    up
FastEthernet0/0.99     192.168.99.1    YES manual up                    up
FastEthernet0/1        unassigned      YES unset  administratively down down
Serial0/0/0            unassigned      YES unset  administratively down down

Prueba entre VLANs

  • Comando: Router# ping <IP>
  • Ejemplo: Router# ping 192.168.20.50

Qué deberías ver:

  • Las redes de cada VLAN como C (directamente conectadas) en la tabla de rutas.
  • Las subinterfaces (RoaS) o las SVIs (capa 3) en estado up/up.
  • Ping exitoso entre un host de la VLAN 10 y uno de la VLAN 20.