Guided buildcore6 steps~15 min3 devices
Route between VLANs on the switch
Give one switch an SVI in each VLAN, find out why the VLANs still can't talk, then turn on ip routing — inter-VLAN routing with no router at all.
What you'll be able to do: One multilayer switch that is both the LAN and the router: two VLANs, a gateway for each living on the switch itself, and traffic between them routed inside the box instead of hairpinning up a cable to a router.
Topics: VLANs · Inter-VLAN routing · SVIs · Layer 3 switching
What you'll build
- SW-Core — a switch, the multilayer switch that switches and routes
- PC-Sales — a pc, a workstation in the Sales VLAN
- PC-Ops — a pc, a workstation in the Ops VLAN
Step by step
1. Place the switch and cut it into two VLANs
Drag one switch onto the canvas, name it SW-Core, and create VLAN 10 for Sales and VLAN 20 for Ops. This one box is going to do the job a router did in the router-on-a-stick build, so there is nothing else to place for the network itself.
On SW-Core — Name the switch and define both VLANs
enable configure terminal hostname SW-Core vlan 10 name SALES exit vlan 20 name OPS exit endCheck: run
show vlan briefon SW-Core and look for20 OPS active.Why: Two VLANs are two broadcast domains, and traffic between broadcast domains has to be routed. The question this build answers is where that routing happens — here, inside the switch.
2. Put a Sales PC in VLAN 10
Cable a PC to Fa0/1, make that port an access port in VLAN 10, and give the PC 192.168.10.10/24 with 192.168.10.1 as its gateway. That gateway address does not exist anywhere yet — it will live on the switch itself.
- Cable PC-Sales Eth0 ↔ SW-Core Fa0/1
On SW-Core — Hand Fa0/1 to VLAN 10
enable configure terminal interface Fa0/1 switchport mode access switchport access vlan 10 exit endOn PC-Sales — Name the PC and address it in the Sales subnet
hostname PC-Sales ipconfig Eth0 192.168.10.10 255.255.255.0 192.168.10.1Check: run
show vlan briefon SW-Core and look for10 SALES active Fa0/1.Why: An access port belongs to exactly one VLAN and hands that VLAN's frames to the PC untagged, so the PC never knows VLANs exist. Which VLAN a host lives in is decided entirely by the switch port it is plugged into — nothing on the PC changes it.
3. Put an Ops PC in VLAN 20
Same again on Fa0/2, in VLAN 20 and the 192.168.20.0/24 subnet, with 192.168.20.1 as the gateway. One VLAN, one subnet, one gateway: that pairing is what lets the switch route between them in a moment.
- Cable PC-Ops Eth0 ↔ SW-Core Fa0/2
On SW-Core — Hand Fa0/2 to VLAN 20
enable configure terminal interface Fa0/2 switchport mode access switchport access vlan 20 exit endOn PC-Ops — Name the PC and address it in the Ops subnet
hostname PC-Ops ipconfig Eth0 192.168.20.10 255.255.255.0 192.168.20.1Check: run
show vlan briefon SW-Core and look for20 OPS active Fa0/2.Why: Each VLAN gets its own subnet so that a PC can tell local from remote on its own: anything outside 192.168.20.0/24 is handed to the gateway. That hand-off to the gateway is exactly what the switch will pick up and route in a moment.
4. Give VLAN 10 a gateway on the switch
`interface vlan 10` creates a switch virtual interface: a routed interface with no cable of its own, living inside VLAN 10. Give it 192.168.10.1 — the gateway PC-Sales already points at — and bring it up. Every port in VLAN 10 can now reach that address.
On SW-Core — Create the VLAN 10 SVI as the Sales gateway
enable configure terminal interface vlan 10 ip address 192.168.10.1 255.255.255.0 no shutdown exit endOn PC-Sales — Reach the new gateway
ping 192.168.10.1Check: run
show ip interface briefon SW-Core and look forVlan10 192.168.10.1 YES manual up up.Why: An SVI is the switch's own foot inside a VLAN. It needs no cable because every access port in that VLAN (and every trunk carrying it) already reaches it — which is what makes it a natural default gateway for the whole VLAN.
5. Give VLAN 20 its gateway — and find the VLANs still can't talk
Create the VLAN 20 SVI the same way, and PC-Ops reaches 192.168.20.1 at once. Both gateways are up/up, both answer — so ping PC-Ops from PC-Sales. It fails. Run `show ip route` on SW-Core and the reason is right there: no routing table at all, just "Default gateway is not set". The switch treats its SVIs as its own management addresses, and routing between them is not its job yet.
On SW-Core — Create the VLAN 20 SVI as the Ops gateway
enable configure terminal interface vlan 20 ip address 192.168.20.1 255.255.255.0 no shutdown exit endOn PC-Sales — Try to cross from Sales to Ops
ping 192.168.20.10Check: run
show ip routeon SW-Core and look forDefault gateway is not set.Why: A switch ships as a layer 2 device. Its SVIs let it be managed from any VLAN, but forwarding a packet from one VLAN's subnet into another's is routing, and a switch only routes once `ip routing` is enabled.
6. Turn on ip routing
One global command: `ip routing`. The switch builds a routing table from its SVIs — two connected routes, one per VLAN — and starts forwarding between them. Ping PC-Ops from PC-Sales again and it answers in two hops: into SW-Core through Vlan10, back out through Vlan20. The packet never left the box.
On SW-Core — Make the switch route between its SVIs
enable configure terminal ip routing endOn PC-Sales — Cross from Sales to Ops again
ping 192.168.20.10Check: run
show ip routeon SW-Core and look forC 192.168.20.0/24 is directly connected, Vlan20.Why: Routing between SVIs happens in the switch's own forwarding hardware, at switching speed, with no cable to a router to saturate. That is why real networks do inter-VLAN routing on a multilayer switch and keep router-on-a-stick for small sites.
The theory behind it
More in Switching & wireless
- Map the network with CDP and LLDP — Let two switches and a router discover each other, find the router's address from a switch that was never told it, add LLDP, then stop the router announcing itself toward the internet.
- Two departments, one switch — Split a single switch into Sales and Ops with VLANs, and watch the pings between them stop.
- One VLAN across two switches — Split four PCs into two VLANs across two switches, then carry both VLANs between the switches over a single tagged trunk.
- Router on a stick — Split one switch into two VLANs and route between them over a single router port.
- Choose your root bridge — Close a loop of three switches, find the port spanning tree blocks on its own, then decide which switch is root — and which one takes over when it fails.
- Two cables, one logical link — Add a second uplink between two switches, watch spanning tree block it, then bundle both into an LACP EtherChannel so they carry traffic together.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab