Contact US

Log In

Come Join Us!

Are you a
Computer / IT professional?
Join Tek-Tips Forums!
  • Talk With Other Members
  • Be Notified Of Responses
    To Your Posts
  • Keyword Search
  • One-Click Access To Your
    Favorite Forums
  • Automated Signatures
    On Your Posts
  • Best Of All, It's Free!

*Tek-Tips's functionality depends on members receiving e-mail. By joining you are opting in to receive e-mail.

Posting Guidelines

Promoting, selling, recruiting, coursework and thesis posting is forbidden.

Students Click Here

Vlan restrictions

Vlan restrictions

Vlan restrictions


I have recently installed an 5412ZL switch and for some reason no matter what your port's tagging is set to you can still ping across the vlan's to devices that your tagging is set to no. So a pc is untagged for the workstation VLAN and tagged for voice and Servers, all other vlans are set to no but they can ping devices in all other vlans. It's almost as if the port does not follow it's tagging. I have done this setup many times before and have not had this issue.

The switch is set as the gateway for their respective VLAN's and IP routing is enabled. Please see the inserted config:

module 1 type J9535A
module 2 type J9534A
module 3 type J9534A
module 4 type J9534A
module 5 type J9534A
module 6 type J9534A
module 7 type J9534A
module 8 type J9534A
module 9 type J9534A
trunk A1-A2 Trk1 LACP
trunk A3-A4 Trk2 LACP
trunk A5-A6 Trk3 LACP
trunk A7-A8 Trk4 LACP
trunk A9-A10 Trk5 LACP
ip routing
vlan 1
name "Servers"
untagged A11-A24,H11,Trk1-Trk5
ip address
tagged B1-B13,D1-D6,D8-D12,D21-D24,E1-E24,F1-F11,F13-F24,G1-G24,H1-H10,H12-H24,I1-I24
vlan 20
name "Workstations"
untagged E1-E24,F1-F24,G1-G24,H1-H10,H12-H24,I1-I24
ip helper-address
ip address
tagged A11-A24,B1-B13,D1-D6,D8-D12,D21-D24,H11,Trk1-Trk5
vlan 30
name "Voice"
untagged C20-C24
ip address
tagged A11-A24,B1-B12,D21-D24,E1-E24,F1-F11,F13-F24,G1-G24,H1-H24,I1-I24,Trk1-Trk5
vlan 40
name "CRCS"
untagged D1-D12
ip address
tagged I19-I24,Trk1-Trk5
vlan 50
name "Bur"
untagged B1-B12,D21-D24
ip helper-address
ip address
tagged I19-I24,Trk1-Trk5
vlan 70
name "AX"
untagged B13,C1
ip address
tagged I19-I24,Trk1-Trk5
vlan 80
name "Guest"
ip address
tagged I19-I24,Trk1-Trk5
vlan 90
name "Sec"
untagged B14-B24,C2-C19
ip helper-address
ip address
tagged A11-A24,I19-I24,Trk1-Trk5
console inactivity-timer 30
ip route
snmp-server community "public"
no snmp-server enable
spanning-tree Trk1 priority 4
spanning-tree Trk2 priority 4
spanning-tree Trk3 priority 4
spanning-tree Trk4 priority 4
spanning-tree Trk5 priority 4
loop-protect B1-B24,C1-C24,D1-D24,E1-E24,F1-F24,G1-G24,H1-H24,I1-I24
loop-protect disable-timer 600
no autorun
no dhcp config-file-update
no dhcp image-file-update
password manager
password operator

RE: Vlan restrictions

So you have a PC is subnet and it can ping a Server in subnet
Is that the problem?
If IP routing is enabled would you expect this to behave any differently?

What is the purpose of having multiple tagged VLANs trunked out to PCs, anyway?

Red Flag This Post

Please let us know here why this post is inappropriate. Reasons such as off-topic, duplicates, flames, illegal, vulgar, or students posting their homework.

Red Flag Submitted

Thank you for helping keep Tek-Tips Forums free from inappropriate posts.
The Tek-Tips staff will check this out and take appropriate action.

Reply To This Thread

Posting in the Tek-Tips forums is a member-only feature.

Click Here to join Tek-Tips and talk with other members! Already a Member? Login

Close Box

Join Tek-Tips® Today!

Join your peers on the Internet's largest technical computer professional community.
It's easy to join and it's free.

Here's Why Members Love Tek-Tips Forums:

Register now while it's still free!

Already a member? Close this window and log in.

Join Us             Close