Zywall 110 Inter-VLAN (intra-Zone) routing problem
Accepted Solution
-
Hi @Matthias_AUT,
About the symptom "devices from other VLANs cannot connect to VLAN587 devices", try to use the following steps for troubleshooting.
PC1 in vlan587: 128.130.77.67
PC2 in vlan883: 128.130.77.99
Step 1: Go to Diagnostics > Network Tool. Select PING IPv4 and enter the IP address of PC1 128.130.77.67.
Remember to disable Windows firewall on PC1. Check if ping PC1 from ZyWALL successfully.
Step 2:
On PC2 (128.130.77.99), ping vlan587’s gateway 128.130.77.65.
Check if PC2 is able to ping vlan587’s gateway IP address.
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community5
All Replies
-
-
You shouldn't need static routes so remove that and try Policy Control off which should work.
When you say Inter-VLAN you mean VLAN77 can't connect to VLAN587 ?
unplug the WAN and see if that works0 -
PeterUK said:You shouldn't need static routes so remove that and try Policy Control off which should work.
When you say Inter-VLAN you mean VLAN77 can't connect to VLAN587 ?
unplug the WAN and see if that worksDear Peter, thanks for your help!1) I tried without the static routes and policy control off which also did not change connectivity (can still connect from VLAN77 to lan1 and from VLAN587 to lan1 but not from VLAN77 to VLAN5872) Yes exactly, VLAN77 can't connect to VLAN587 or VLAN883, same for the other VLANs, each can connect to lan1 but no other VLAN3) Unplugging the WAN resulted in lost connectivity from VLANs to lan1! Still no connectivity between VLANs...I really wonder why connectivity to lan1 is dependent on WAN being connected.Best regards, Matthias
0 -
Make some zones for VLAN77, VLAN587 and VLAN883 then go to each VLAN interface and set zone from LAN1 to a given zone this way their not all on LAN1.
Test again Policy Control off which should work.
Will all VLAN's to zone LAN1 you would of needed to make a Policy Control rule from LAN1 to LAN1 and with each VLAN in its zone you make Policy Control rules from given zone to given zone.
0 -
tested here between two VLANs with a ZyWALL 110 on V4.38 works fine
VLAN4091 10.255.251.2 ping 10.255.252.2
VLAN4090 10.255.252.2 replies to 10.255.251.20 -
PeterUK said:
Make some zones for VLAN77, VLAN587 and VLAN883 then go to each VLAN interface and set zone from LAN1 to a given zone this way their not all on LAN1.
Test again Policy Control off which should work.
Will all VLAN's to zone LAN1 you would of needed to make a Policy Control rule from LAN1 to LAN1 and with each VLAN in its zone you make Policy Control rules from given zone to given zone.
I made individual zones for each VLAN; like this?Tested with policy control off; I cannot ping between VLANs and neither to lan1 which works when all are in the same zone.I can (and always could) ping all the gateways, but not the machines connected to them.I tried both variants with policy control, all on zone LAN1 and LAN1toLAN1 as well as separate zones and LAN1toVLANxxx, did not work;I wonder if there is something fundamentally wrong with the way I set up the VLANs, this is how it looksAnd all the VLANs itself:Thanks for your effort!Best regards, MatthiasEDIT: Latest FW Version, V4.380 -
PeterUK said:tested here between two VLANs with a ZyWALL 110 on V4.38 works fine
VLAN4091 10.255.251.2 ping 10.255.252.2
VLAN4090 10.255.252.2 replies to 10.255.251.2Dear Peter, could you please upload the conf file of your working Zywall 110 so I can check for differences to my config?Thanks a lot,Matthias
0 -
I can't upload my config as I like to keep it private.
Can you change the port role so LAN1 is not linked to other ports for testing.
0 -
Hi @Matthias_AUT,
FW: 4.38(AAAA.0)
I applied your configuration file to a ZyWALL 110 to run the test.
Inter-VLAN routing is working successfully even if firewall is enabled.
PC1 in vlan587 is able to ping PC2 in vlan883 and vice versa.
Hence, there is no problem with the settings on ZyWALL110.
Try to check the configuration on the switch.
Topology:
ZyWALL 110(P4)----(P10)GS2210(P2)-----PC1(128.130.77.66)
(P3)-----PC2 (128.130.77.98)
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0 -
Hi Zyxel_Emily, are P4 and P3 in your topology different physical ports on the Zywall? My VLANs come all in as trunk on P4, can this be the problem?
Do I have to configure virtual interfaces for the VLANs?
I have no idea what could be wrong with the switch settings as all 3 VLANs successfully connect to the Internet, any suggestions?
Best regards, Matthias
0
Categories
- All Categories
- 415 Beta Program
- 2.5K Nebula
- 152 Nebula Ideas
- 101 Nebula Status and Incidents
- 5.8K Security
- 296 USG FLEX H Series
- 281 Security Ideas
- 1.5K Switch
- 77 Switch Ideas
- 1.1K Wireless
- 42 Wireless Ideas
- 6.5K Consumer Product
- 254 Service & License
- 396 News and Release
- 85 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.6K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 87 About Community
- 76 Security Highlight