[c-nsp] route problem

Dan Letkeman danletkeman at gmail.com
Mon Nov 17 18:05:42 EST 2008


Hello,

I have setup a guest vlan for internet access.  When the users connect
to the guest network they get only internet access and no access to
any of the servers on the rest of the network.  The problem I'm having
now is that the users on the guest network cannot access our internal
web servers.  I'm wondering if this is a simple access list problem or
is it a route problem?

topology is a follows:


normal user----------vlan 500--------------3560 switch----------2801
router------------internet
                                                          |
                                                          |
guest users---------vlan 167---------------------


There is an access list on vlan 167 on the 3560 switch that only
allows the guest users access to the internet.  So when I do a trace
route from the guest network to the internal web address I get a
timeout at the router.  The internal web server resolves with our
external ip address because the guest users are not using our internal
dns servers.

Any ideas where I should start?

Dan.


More information about the cisco-nsp mailing list