Original Message:
Sent: Sep 22, 2021 01:34 PM
From: Robert Großmann
Subject: Vlan reaching the interent without default gateway
@Davide
Maybe you are right, i don't know the 1930. So VRF could be useful to make separation of networks more secure. But here it is not the answer.
After reading the topic again, he said there is no SVI for VLAN 20 on the core. This makes it less desirable that it is a routing/proxy-arp error.
Indeed, I would always configure no ip proxy-arp on every SVI, therefore I do have control over default gateway and routing. Because proxy-arp is responsible for such errors (no configured gateway, but switch/router acts as a default-gateway).
It would be helpful to see the mac-adress table entries for the used ports and the full ip configuration on the clients (like ipconfig -all) even as a traceroute from a client in vlan 10 and vlan 20.
If the firewall does not know about the IP Network in VLAN 20 and does not have a route using the existing connection between core and firewall there can't be traffic (dont think about nat).
maybe florian is right that the clients to have a wifi connection integrated and use this, as the wired connection does not offer a default-gateway.
------------------------------
Robert Großmann
Original Message:
Sent: Sep 22, 2021 09:11 AM
From: Davide Poletto
Subject: Vlan reaching the interent without default gateway
Just to add that "If a switch does have more than one ip interface, then it acts as a router, so traffic between vlans will be possible." excluding those switches requiring to explicitly enable the IP Routing feature in addition to assigning an IP Address to a VLAN interface (that's to say that simply assigning an IP Addresses to VLANs is not enough to enable routing between those VLANs).
I don't believe the Aruba Instant On 1930 Switch series is VRF capable...that's a feature typically found on DC Switch series.
------------------------------
Davide Poletto
Original Message:
Sent: Sep 22, 2021 02:29 AM
From: Robert Großmann
Subject: Vlan reaching the interent without default gateway
Do you have configured your switches with ip addresses in vlan 20?
if yes, then please add the "no ip proxy-arp" in their interface vlan 20 config everywhere.
if no, then yes it is strange. Then you could use ACL on the interface vlans.
<<But perhaps it would be better, to put the the interface vlan 20 in another VRF (especially on the core), then your static route to the firewall will not be used for vlan 20.>>
EDIT: Maybe the 1930 does not support VRF. Please have a look at the switch features and configuration guide.
Please remind. If a switch does have more than one ip interface, then it acts as a router, so traffic between vlans will be possible.
------------------------------
Robert Großmann
Original Message:
Sent: Sep 21, 2021 02:16 AM
From: mohammad shamseddine
Subject: Vlan reaching the interent without default gateway
Hello Dears,
I have 3 aruba 1930 switches, 2 used as edges and one as core. I have two vlans, vlan 10 and 20. I created a L3 interface for vlan 10 (192.168.10.1) , and no interface for vlan 20 on the core. Static route also created on core to the firewall for internet access. I am planning to use vlan 20 for connectivity between internal devices only , with no access to the internet and no access to other vlans. What is confusing for me is that when i plug a pc to vlan 20 , i am able to access the internet from this device although no default-gateway assigned (only ip and netmask in ip configuration), may someone explain on how this is possible ?
I attached a sketch for better understanding, PC1 is untagged with vlan 10 (able to access internet), PC2 and PC3 should only able to communication with each other on vlan 20 but they are reaching the internet !! besides, uplinks from edge to core are tagged all with vlan 10 and 20
Thanks for your support
------------------------------
mohammad shamseddine
------------------------------