Guided buildcore7 steps~20 min3 devices
Let the core switch hand out the addresses
Run two department VLANs, their gateways and their DHCP pools on a single switch — and find out why a perfect pool can still hand out nothing.
What you'll be able to do: One switch does the whole job for two departments: Sales and Engineering each lease addresses from their own pool, get their own gateway, and reach each other through the switch.
Topics: DHCP · VLANs · Inter-VLAN routing
What you'll build
- SW-Core — a switch, the core switch: VLANs, gateways and DHCP in one box
- PC-Sales — a pc, a workstation in the Sales VLAN
- PC-Eng — a pc, a workstation in the Engineering VLAN
Step by step
1. Carve the switch into two departments
Drag a switch and a PC onto the canvas and cable the PC's Eth0 to the switch's Fa0/1. On the switch, create VLAN 10 for Sales and VLAN 20 for Engineering, put Fa0/1 in VLAN 10 and Fa0/2 in VLAN 20. Name the PC too — it stays unaddressed for now.
- Cable PC-Sales Eth0 ↔ SW-Core Fa0/1
On SW-Core — Name the switch, create both VLANs and assign the two access ports
enable configure terminal hostname SW-Core vlan 10 name SALES exit vlan 20 name ENG exit interface Fa0/1 switchport mode access switchport access vlan 10 exit interface Fa0/2 switchport mode access switchport access vlan 20 exit endOn PC-Sales — Name the Sales workstation
hostname PC-SalesCheck: run
show vlan briefon SW-Core and look for10 SALES active Fa0/1.Why: Each VLAN is its own broadcast domain, and a DHCP request is a broadcast — so each department will need its own pool, and something in each VLAN to answer it.
2. Give Sales a gateway on the switch itself
An SVI — interface vlan 10 — is the switch's own address inside VLAN 10, and 192.168.10.1 will be the Sales gateway. Turn on ip routing first: the switch is going to route between the departments, not just carry frames.
On SW-Core — Enable routing and create the Sales gateway
enable configure terminal ip routing interface vlan 10 ip address 192.168.10.1 255.255.255.0 no shutdown exit endCheck: run
show ip interface briefon SW-Core and look forVlan10 192.168.10.1 YES manual up up.Why: The SVI is what gives the switch a foot in the VLAN at layer 3. It is the gateway the Sales hosts will use, and — as you will see — the interface the switch answers DHCP on.
3. Build the Sales pool on the switch
Exclude .1 to .9 for fixed equipment, then define SALES: the subnet it leases from, the gateway it hands out — the Vlan10 address you just set — and the DNS servers.
On SW-Core — Reserve the fixed addresses and define the Sales pool
enable configure terminal ip dhcp excluded-address 192.168.10.1 192.168.10.9 ip dhcp pool SALES network 192.168.10.0 255.255.255.0 default-router 192.168.10.1 dns-server 1.1.1.1 8.8.8.8 exit endCheck: run
show ip dhcp poolon SW-Core and look forDefault router: 192.168.10.1.Why: A switch runs the same DHCP server a router does. When a request arrives in VLAN 10, the switch leases from the pool whose network matches its Vlan10 subnet.
4. Let PC-Sales lease its address
Ask for a lease on PC-Sales. It gets 192.168.10.10 — the first address past the exclusion — plus the gateway and DNS list, all from the switch it is plugged into. show ip dhcp binding on the switch lists the lease.
On PC-Sales — Ask the network for an address
ipconfig /renewCheck: run
show ip dhcp bindingon SW-Core and look for192.168.10.10.Why: The client never learns that its server is a switch. DHCP only cares that something in its broadcast domain answers with a lease from the right subnet.
5. Build the Engineering pool the same way
Engineering gets its own exclusion and its own pool, ENG, on 192.168.20.0/24, with 192.168.20.1 as the gateway it hands out. Type it carefully: this pool is correct, and that is the point of the next step.
On SW-Core — Reserve Engineering's fixed addresses and define its pool
enable configure terminal ip dhcp excluded-address 192.168.20.1 192.168.20.9 ip dhcp pool ENG network 192.168.20.0 255.255.255.0 default-router 192.168.20.1 dns-server 1.1.1.1 8.8.8.8 exit endCheck: run
show ip dhcp poolon SW-Core and look forDefault router: 192.168.20.1.Why: One switch can hold a pool per VLAN. Nothing in the pool itself names a VLAN — the link between a pool and the hosts it serves is the subnet of the SVI a request arrives on.
6. Plug in PC-Eng — and hear nothing back
Cable PC-Eng to Fa0/2, name it, and ask for a lease. Nothing comes back, and the pool is not the problem. The request is broadcast into VLAN 20, and the switch has no interface in VLAN 20 to hear it on — no SVI, so no DHCP server as far as that VLAN is concerned.
- Cable PC-Eng Eth0 ↔ SW-Core Fa0/2
On PC-Eng — Name the Engineering PC and ask for an address
hostname PC-Eng ipconfig /renewCheck: run
show ip dhcp poolon SW-Core and look forLeased addresses: 0.Why: A switch answers DHCP only in a VLAN where it has an up SVI whose subnet a pool covers. The pool says what to hand out; the SVI is where the switch listens.
7. Give Engineering its gateway, and ask again
Create interface vlan 20 with 192.168.20.1 and bring it up, then renew on PC-Eng. The same request now lands on an SVI in the ENG pool's subnet: PC-Eng leases 192.168.20.10, gets 192.168.20.1 as its gateway, and — because ip routing is on — reaches PC-Sales across the switch.
On SW-Core — Create the Engineering gateway
enable configure terminal interface vlan 20 ip address 192.168.20.1 255.255.255.0 no shutdown exit endOn PC-Eng — Ask for an address again
ipconfig /renewCheck: run
show ip routeon SW-Core and look forC 192.168.20.0/24 is directly connected, Vlan20.Why: Every VLAN on a routing switch needs its SVI for two reasons at once: it is the hosts' gateway, and it is the interface DHCP answers on. The routing table now holds both subnets as connected, which is all the switch needs to route between them.
The theory behind it
More in Network services
- Let the router hand out the addresses — Build a four-device office LAN, address one PC by hand, then put a DHCP pool on the router so the next machine configures itself.
- One DHCP server for every floor — Serve a user floor from a central DHCP server on another subnet — watch the first request die at the router, then relay it with ip helper-address.
- NAT to the internet — Hide two private office LANs behind the single public address your provider gave you.
- Give the whole network one clock — Build an NTP hierarchy from HQ to a branch switch, read the strata hop by hop, then find the security ACL that silently broke time while ping kept working.
- Lock management down to SSH — Make a switch manageable from the admin subnet, then harden it: RSA keys, SSH version 2, a local account, and VTY lines that refuse everything but SSH.
Build it for real
The lab walks you through these steps and ticks each one off as your network starts working.
Open in the lab