Hello there,
we've got some issues with the configuration of vlans between a HP 2920-24G switch and a WatchGuard XTM330 Firewall.
We have configured 2 VLANs on the Switch. VLAN-21 and VLAN-24.
VLAN-21 192.168.2.1 Ports 3-12 untagged
VLAN-24 192.168.4.1 Ports 13-22 untagged
We enabled Routing and configured DHCP-Helper IP for DHCP-Server which is in VLAN-21 to work also in VLAN-24.
The Interface on the Firewall which is connected to Port1 of the Switch has the IP 192.168.1.254.
In The Firewall Configuration this Interface is configured as TAGGED with VLAN-21 and VLAN-24.
Also Port1 (2, 23/24) on the Switch is TAGGED with both VLANs (VLAN-21 and VLAN-24).
If we now plug in a client in VLAN-21 or VLAN-24 Port we cannot reach/ping the Firewall (192.168.1.254).
But clients/devices can communicate with each other from VLAN-21 to VLAN-24 and vice versa, that works.
And also the DHCP-Server in VLAN-21 can provide IP-Adresses to clients in the VLAN-24.
We did test several things but do not know why we cannot communicate with the firewall from the VLAN-21 or VLAN-24 on the Switch Side.
Even if we plug the firewall directy to a VLAN-21 or VLAN-24 Port communication is not possibly.
Did we miss something elementary?
Would be great if you could provide us some input what we can do to solve this problem.
Here's the Config of the Switch:
------------------------------------------------------------------------
; J9726A Configuration Editor; Created on release #WB.15.12.0010
; Ver #04:01.ff.35.0d:c2
hostname "HP-2920-24G"
module 1 type j9726a
ip default-gateway 192.168.0.254
ip routing
snmp-server community "public" unrestricted
snmp-server contact "XXX" location "YYY"
vlan 1
name "VLAN_21"
no untagged 13-22
untagged 3-12,A1-A2,B1-B2
tagged 1-2,23-24
ip address 192.168.1.1 255.255.255.0
exit
vlan 2
name "VLAN_24"
untagged 13-22
tagged 1,23-24
ip address 192.168.4.1 255.255.255.0
ip helper-address 192.168.1.1
exit
no autorun
no dhcp config-file-update
no dhcp image-file-update
password manager
---------------------------------------------
Basically we want to achieve, that the Switch does the internal LAN routing, so that the Firewall Load isn't additionally getting stressed by doing LAN routing. Firewall should only do "WAN-Stuff". One Interface from the Firewall should be connected to Switch. And via this Interface both VLANs should exchange their Traffic.
Perhaps there's a better way or other approach to accomplish that!?
Any Ideas and inout is appreciated...