<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RE: Switch Config for routing through a Firewall (routing on a Stick) in ExtremeSwitching (EXOS/Switch Engine)</title>
    <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/switch-config-for-routing-through-a-firewall-routing-on-a-stick/m-p/43521#M10520</link>
    <description>Sonicwall NSA2600.</description>
    <pubDate>Fri, 30 Jun 2017 02:16:00 GMT</pubDate>
    <dc:creator>Joe80</dc:creator>
    <dc:date>2017-06-30T02:16:00Z</dc:date>
    <item>
      <title>Switch Config for routing through a Firewall (routing on a Stick)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/switch-config-for-routing-through-a-firewall-routing-on-a-stick/m-p/43519#M10518</link>
      <description>Hi.&lt;BR /&gt;
&lt;BR /&gt;
Hope someone can help, am having a bit of a problem routing two vlans through a firewall.   I've sub interfaced a nic on a FW to have two vlans attached to the physical nic.&lt;BR /&gt;
&lt;BR /&gt;
On the uplink to the interface on the FW I've configured the port to be tagged.   Then on the two ports to the two differing PCs in the different vlans I've put them in an untagged port but also tagged the uplink port in on the vlan.&lt;BR /&gt;
&lt;BR /&gt;
So vlan to FW port is tagged&lt;BR /&gt;
Vlan x to PC1 port is untagged for PC but FW port tagged into vlan&lt;BR /&gt;
Vlan y to PC2 port is untagged for PC but FW port tagged into vlan&lt;BR /&gt;
&lt;BR /&gt;
I thought this would have worked but no joy.    I've tried variations of the above but not working.  I can see the ip address of the FW nic in the arp table but not the PCs&lt;BR /&gt;
&lt;BR /&gt;
I can putty on to the FW and see in arp table and ping both PCs so FW config seems okay.&lt;BR /&gt;
&lt;BR /&gt;
What am I missing?  Any help gratefully received.&lt;BR /&gt;
&lt;BR /&gt;
Thanks&lt;BR /&gt;</description>
      <pubDate>Fri, 30 Jun 2017 01:51:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/switch-config-for-routing-through-a-firewall-routing-on-a-stick/m-p/43519#M10518</guid>
      <dc:creator>Joe80</dc:creator>
      <dc:date>2017-06-30T01:51:00Z</dc:date>
    </item>
    <item>
      <title>RE: Switch Config for routing through a Firewall (routing on a Stick)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/switch-config-for-routing-through-a-firewall-routing-on-a-stick/m-p/43520#M10519</link>
      <description>What kind of a FW do you use?&lt;BR /&gt;
&lt;BR /&gt;</description>
      <pubDate>Fri, 30 Jun 2017 02:01:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/switch-config-for-routing-through-a-firewall-routing-on-a-stick/m-p/43520#M10519</guid>
      <dc:creator>Nick_Yakimenko</dc:creator>
      <dc:date>2017-06-30T02:01:00Z</dc:date>
    </item>
    <item>
      <title>RE: Switch Config for routing through a Firewall (routing on a Stick)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/switch-config-for-routing-through-a-firewall-routing-on-a-stick/m-p/43521#M10520</link>
      <description>Sonicwall NSA2600.</description>
      <pubDate>Fri, 30 Jun 2017 02:16:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/switch-config-for-routing-through-a-firewall-routing-on-a-stick/m-p/43521#M10520</guid>
      <dc:creator>Joe80</dc:creator>
      <dc:date>2017-06-30T02:16:00Z</dc:date>
    </item>
    <item>
      <title>RE: Switch Config for routing through a Firewall (routing on a Stick)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/switch-config-for-routing-through-a-firewall-routing-on-a-stick/m-p/43522#M10521</link>
      <description>&lt;BLOCKQUOTE&gt; I can see the ip address of the FW nic in the arp table but not the PCs&lt;/BLOCKQUOTE&gt;&lt;BR /&gt;
Is this the only problem? If so, why do you expect to see the arp of an ip-address located in a different subnet?&lt;BR /&gt;</description>
      <pubDate>Fri, 30 Jun 2017 02:16:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/switch-config-for-routing-through-a-firewall-routing-on-a-stick/m-p/43522#M10521</guid>
      <dc:creator>Nick_Yakimenko</dc:creator>
      <dc:date>2017-06-30T02:16:00Z</dc:date>
    </item>
    <item>
      <title>RE: Switch Config for routing through a Firewall (routing on a Stick)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/switch-config-for-routing-through-a-firewall-routing-on-a-stick/m-p/43523#M10522</link>
      <description>Is there a Extreme switch involved as I don't see one mentioned in the problem description.  Please add also switch model and software and a simple network diagram with the IPs.    But if I should guess with this very limited information... no/wrong default gateway on the PCs.    Cheers,  Ron</description>
      <pubDate>Fri, 30 Jun 2017 04:22:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/switch-config-for-routing-through-a-firewall-routing-on-a-stick/m-p/43523#M10522</guid>
      <dc:creator>Ronald_Dvorak</dc:creator>
      <dc:date>2017-06-30T04:22:00Z</dc:date>
    </item>
    <item>
      <title>RE: Switch Config for routing through a Firewall (routing on a Stick)</title>
      <link>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/switch-config-for-routing-through-a-firewall-routing-on-a-stick/m-p/43524#M10523</link>
      <description>Hi Joe,&lt;BR /&gt;
&lt;BLOCKQUOTE&gt;I can putty on to the FW and see in arp table and ping both PCs so FW config seems okay.&lt;BR /&gt;
&lt;/BLOCKQUOTE&gt;Can you ping both FW IP addresses? Can you ping both PCs from the FW? Can you ping the FW interface in the same VLAN as the PC?&lt;BR /&gt;
&lt;BR /&gt;
What is not working &lt;I&gt;exactly&lt;/I&gt;?&lt;BR /&gt;
&lt;BR /&gt;
As I understand you description you want to use the switch as layer 2 only (no IP forwarding) and use the firewall as gateway between two VLANs. If the switch is configured correctly, you should see the MAC addresses in the FDB of the correct VLAN. I.e. PC A and FW in VLAN A and PC B and FW in VLAN B. The command to verify this is:&lt;BR /&gt;
show fdb vlan VLAN_A&lt;BR /&gt;
show fdb vlan VLAN_BOf course, the PCs must be configured to use the correct FW interface as default gateway and the FW needs to allow the traffic that is supposed to be allowed.&lt;BR /&gt;
&lt;BR /&gt;
You should not enable IP forwarding on the switch, otherwise traffic could bypass the FW if the switch is used as gateway.&lt;BR /&gt;
&lt;BR /&gt;
Thanks,&lt;BR /&gt;
Erik</description>
      <pubDate>Fri, 30 Jun 2017 13:59:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/extremeswitching-exos-switch/switch-config-for-routing-through-a-firewall-routing-on-a-stick/m-p/43524#M10523</guid>
      <dc:creator>Erik_Auerswald</dc:creator>
      <dc:date>2017-06-30T13:59:00Z</dc:date>
    </item>
  </channel>
</rss>

