All guided builds

Guided buildcore6 steps~15 min3 devices

Route between VLANs on the switch

Give one switch an SVI in each VLAN, find out why the VLANs still can't talk, then turn on ip routing — inter-VLAN routing with no router at all.

What you'll be able to do: One multilayer switch that is both the LAN and the router: two VLANs, a gateway for each living on the switch itself, and traffic between them routed inside the box instead of hairpinning up a cable to a router.

Topics: VLANs · Inter-VLAN routing · SVIs · Layer 3 switching

What you'll build

Step by step

  1. 1. Place the switch and cut it into two VLANs

    Drag one switch onto the canvas, name it SW-Core, and create VLAN 10 for Sales and VLAN 20 for Ops. This one box is going to do the job a router did in the router-on-a-stick build, so there is nothing else to place for the network itself.

    On SW-Core — Name the switch and define both VLANs

    enable
    configure terminal
    hostname SW-Core
    vlan 10
    name SALES
    exit
    vlan 20
    name OPS
    exit
    end

    Check: run show vlan brief on SW-Core and look for 20 OPS active.

    Why: Two VLANs are two broadcast domains, and traffic between broadcast domains has to be routed. The question this build answers is where that routing happens — here, inside the switch.

  2. 2. Put a Sales PC in VLAN 10

    Cable a PC to Fa0/1, make that port an access port in VLAN 10, and give the PC 192.168.10.10/24 with 192.168.10.1 as its gateway. That gateway address does not exist anywhere yet — it will live on the switch itself.

    • Cable PC-Sales Eth0 ↔ SW-Core Fa0/1

    On SW-Core — Hand Fa0/1 to VLAN 10

    enable
    configure terminal
    interface Fa0/1
    switchport mode access
    switchport access vlan 10
    exit
    end

    On PC-Sales — Name the PC and address it in the Sales subnet

    hostname PC-Sales
    ipconfig Eth0 192.168.10.10 255.255.255.0 192.168.10.1

    Check: run show vlan brief on SW-Core and look for 10 SALES active Fa0/1.

    Why: An access port belongs to exactly one VLAN and hands that VLAN's frames to the PC untagged, so the PC never knows VLANs exist. Which VLAN a host lives in is decided entirely by the switch port it is plugged into — nothing on the PC changes it.

  3. 3. Put an Ops PC in VLAN 20

    Same again on Fa0/2, in VLAN 20 and the 192.168.20.0/24 subnet, with 192.168.20.1 as the gateway. One VLAN, one subnet, one gateway: that pairing is what lets the switch route between them in a moment.

    • Cable PC-Ops Eth0 ↔ SW-Core Fa0/2

    On SW-Core — Hand Fa0/2 to VLAN 20

    enable
    configure terminal
    interface Fa0/2
    switchport mode access
    switchport access vlan 20
    exit
    end

    On PC-Ops — Name the PC and address it in the Ops subnet

    hostname PC-Ops
    ipconfig Eth0 192.168.20.10 255.255.255.0 192.168.20.1

    Check: run show vlan brief on SW-Core and look for 20 OPS active Fa0/2.

    Why: Each VLAN gets its own subnet so that a PC can tell local from remote on its own: anything outside 192.168.20.0/24 is handed to the gateway. That hand-off to the gateway is exactly what the switch will pick up and route in a moment.

  4. 4. Give VLAN 10 a gateway on the switch

    `interface vlan 10` creates a switch virtual interface: a routed interface with no cable of its own, living inside VLAN 10. Give it 192.168.10.1 — the gateway PC-Sales already points at — and bring it up. Every port in VLAN 10 can now reach that address.

    On SW-Core — Create the VLAN 10 SVI as the Sales gateway

    enable
    configure terminal
    interface vlan 10
    ip address 192.168.10.1 255.255.255.0
    no shutdown
    exit
    end

    On PC-Sales — Reach the new gateway

    ping 192.168.10.1

    Check: run show ip interface brief on SW-Core and look for Vlan10 192.168.10.1 YES manual up up.

    Why: An SVI is the switch's own foot inside a VLAN. It needs no cable because every access port in that VLAN (and every trunk carrying it) already reaches it — which is what makes it a natural default gateway for the whole VLAN.

  5. 5. Give VLAN 20 its gateway — and find the VLANs still can't talk

    Create the VLAN 20 SVI the same way, and PC-Ops reaches 192.168.20.1 at once. Both gateways are up/up, both answer — so ping PC-Ops from PC-Sales. It fails. Run `show ip route` on SW-Core and the reason is right there: no routing table at all, just "Default gateway is not set". The switch treats its SVIs as its own management addresses, and routing between them is not its job yet.

    On SW-Core — Create the VLAN 20 SVI as the Ops gateway

    enable
    configure terminal
    interface vlan 20
    ip address 192.168.20.1 255.255.255.0
    no shutdown
    exit
    end

    On PC-Sales — Try to cross from Sales to Ops

    ping 192.168.20.10

    Check: run show ip route on SW-Core and look for Default gateway is not set.

    Why: A switch ships as a layer 2 device. Its SVIs let it be managed from any VLAN, but forwarding a packet from one VLAN's subnet into another's is routing, and a switch only routes once `ip routing` is enabled.

  6. 6. Turn on ip routing

    One global command: `ip routing`. The switch builds a routing table from its SVIs — two connected routes, one per VLAN — and starts forwarding between them. Ping PC-Ops from PC-Sales again and it answers in two hops: into SW-Core through Vlan10, back out through Vlan20. The packet never left the box.

    On SW-Core — Make the switch route between its SVIs

    enable
    configure terminal
    ip routing
    end

    On PC-Sales — Cross from Sales to Ops again

    ping 192.168.20.10

    Check: run show ip route on SW-Core and look for C 192.168.20.0/24 is directly connected, Vlan20.

    Why: Routing between SVIs happens in the switch's own forwarding hardware, at switching speed, with no cable to a router to saturate. That is why real networks do inter-VLAN routing on a multilayer switch and keep router-on-a-stick for small sites.

The theory behind it

Build it for real

The lab walks you through these steps and ticks each one off as your network starts working.

Open in the lab
Route between VLANs on the switch — step-by-step network lab · NetForge-AI