Instead of router-on-a-stick, this network uses a 3560 multilayer switch (MLS1) to route between VLAN 10 and VLAN 20. The VLANs and access ports are done.
Enable IP routing and create the SVIs: VLAN 10 with 192.168.10.1/24 and VLAN 20 with 192.168.20.1/24. Then turn G0/1 into a routed port (10.0.0.1/30) toward R1 and add a default route to 10.0.0.2 to reach the "Internet" (8.8.8.8).
Topology
Devices and cabling
R1·2911
MLS1·3560-24PS
PC1, PC2·PC-PT
From
To
Cable
R1Gi0/0
MLS1Gi0/1
Straight-through
PC1Fa0
MLS1Fa0/1
Straight-through
PC2Fa0
MLS1Fa0/2
Straight-through
If in doubt, the automatic connection cable (the lightning bolt) picks the right one. Rule: straight-through between different devices (PC or router to switch) and crossover between alike ones.
Addressing
Device
Interface
Address
Mask
Default gateway
MLS1
VLAN 10
192.168.10.1
255.255.255.0
—
MLS1
VLAN 20
192.168.20.1
255.255.255.0
—
MLS1
G0/1
10.0.0.1
255.255.255.252
—
R1
G0/0
10.0.0.2
255.255.255.252
—
R1
Lo0
8.8.8.8
255.255.255.255
—
PC1
VLAN 10
192.168.10.10
255.255.255.0
192.168.10.1
PC2
VLAN 20
192.168.20.10
255.255.255.0
192.168.20.1
Starting configuration
In the app this is already done. In Packet Tracer, before you start, enter each device with enable and configure terminal and type (or paste) these lines.
R1hostname R1
no ip domain-lookup
interface g0/0
ip address 10.0.0.2 255.255.255.252
no shutdown
interface loopback 0
description Internet
ip address 8.8.8.8 255.255.255.255
ip route 192.168.0.0 255.255.0.0 10.0.0.1
MLS1hostname MLS1
no ip domain-lookup
vlan 10
name VENTAS
vlan 20
name RRHH
interface fa0/1
switchport mode access
switchport access vlan 10
interface fa0/2
switchport mode access
switchport access vlan 20
PCs and servers (Desktop › IP Configuration)
PC1: IP 192.168.10.10, mask 255.255.255.0, gateway 192.168.10.1
PC2: IP 192.168.20.10, mask 255.255.255.0, gateway 192.168.20.1
Tasks
What must end up working. In the app, each one ticks itself off as soon as you get it.
IP routing enabled on MLS1
VLAN 10 SVI with 192.168.10.1/24 and up
VLAN 20 SVI with 192.168.20.1/24 and up
PC1 reaches PC2
G0/1 as a routed port with 10.0.0.1/30
Default route to 10.0.0.2
PC1 reaches the "Internet" (8.8.8.8)
In Packet Tracer
Find the 3560-24PS switch in the switches section. PCs and the router use straight-through cables.
First do the starting configuration of MLS1 and R1 (R1 simulates the Internet with an 8.8.8.8 loopback).
Hints
IP routing enabled on MLS1: A 3560 doesn't route until you type ip routing in global config
VLAN 10 SVI with 192.168.10.1/24 and up: interface vlan 10 → ip address 192.168.10.1 255.255.255.0 → no shutdown
VLAN 20 SVI with 192.168.20.1/24 and up: interface vlan 20 → ip address 192.168.20.1 255.255.255.0 → no shutdown
PC1 reaches PC2: You need ip routing and both SVIs up
G0/1 as a routed port with 10.0.0.1/30: interface g0/1 → no switchport → ip address 10.0.0.1 255.255.255.252. You can't put an IP on a layer 2 port.
Default route to 10.0.0.2: ip route 0.0.0.0 0.0.0.0 10.0.0.2
PC1 reaches the "Internet" (8.8.8.8): From PC1: ping 8.8.8.8
Step-by-step solution
Try it on your own first: you learn much more by typing the commands yourself.
Show the solution
1Enable routing MLS1
A multilayer switch doesn't route between VLANs until you type ip routing.
MLS1enable
configure terminal
ip routing
2Create the SVIs MLS1
Each interface vlan is the default gateway of its VLAN. It only comes up if the VLAN exists and has an active port.
MLS1interface vlan 10
ip address 192.168.10.1 255.255.255.0
no shutdown
interface vlan 20
ip address 192.168.20.1 255.255.255.0
no shutdown
3Turn G0/1 into a routed port MLS1
no switchport takes the port out of switching: it behaves like a router interface.
MLS1interface g0/1
no switchport
ip address 10.0.0.1 255.255.255.252
no shutdown
exit
4Add the default route MLS1
MLS1ip route 0.0.0.0 0.0.0.0 10.0.0.2
end
Verification
Both VLANs and the 10.0.0.0/30 link must show as connected (C), plus the default route (S*).
MLS1MLS1#show ip route
Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
E1 - OSPF external type 1, E2 - OSPF external type 2, E - EGP
i - IS-IS, L1 - IS-IS level-1, L2 - IS-IS level-2, ia - IS-IS inter area
* - candidate default, U - per-user static route, o - ODR
P - periodic downloaded static route
Gateway of last resort is 10.0.0.2 to network 0.0.0.0
S* 0.0.0.0/0 [1/0] via 10.0.0.2
10.0.0.0/8 is variably subnetted, 2 subnets, 2 masks
C 10.0.0.0/30 is directly connected, GigabitEthernet0/1
L 10.0.0.1/32 is directly connected, GigabitEthernet0/1
192.168.10.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.10.0/24 is directly connected, Vlan10
L 192.168.10.1/32 is directly connected, Vlan10
192.168.20.0/24 is variably subnetted, 2 subnets, 2 masks
C 192.168.20.0/24 is directly connected, Vlan20
L 192.168.20.1/32 is directly connected, Vlan20
PC1 reaches 8.8.8.8: MLS1 routes and R1 knows how to get back to 192.168.0.0/16.
PC1C:\>ping 8.8.8.8
Pinging 8.8.8.8 with 32 bytes of data:
Reply from 8.8.8.8: bytes=32 time<1ms TTL=254
Reply from 8.8.8.8: bytes=32 time<1ms TTL=254
Reply from 8.8.8.8: bytes=32 time<1ms TTL=254
Reply from 8.8.8.8: bytes=32 time<1ms TTL=254
Ping statistics for 8.8.8.8:
Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
Common mistakes
Trying to set an IP on G0/1 without no switchport: IOS replies "% IP addresses may not be configured on L2 links".
Forgetting ip routing: the SVIs come up, but PCs in different VLANs can't see each other.
Practice this lab on your phone
RoutingLab has this lab with a simulated IOS terminal: abbreviations, ? help, the same error messages and objectives that check themselves. The first two labs are free.