Skip to content

Configure Inter-VLAN Routing on Cisco IOS XE

Inter-VLAN routing lets clients in separate VLANs communicate through a Layer 3 device. This lab configures VLAN 20 and VLAN 30 as directly connected networks on a multilayer switch. It assumes the switch and change are authorized and the private example subnets do not overlap your production plan.

Confirm the platform supports Layer 3 SVIs, the VLANs are carried to client ports, and the gateway addresses are unused before applying the configuration.


01

Define VLANs and Place Test Ports

Layer 2

Create the VLANs and assign only intended test access ports. Identify switchport roles from the topology and change record; do not convert a live uplink to an access port.

configure terminal
vlan 20
name USERS
vlan 30
name APPLICATIONS
interface GigabitEthernet1/0/10
description Test user endpoint
switchport mode access
switchport access vlan 20
spanning-tree portfast
interface GigabitEthernet1/0/20
description Test application endpoint
switchport mode access
switchport access vlan 30
spanning-tree portfast
end
❯ View Expected Console Output
VLAN Name Status Ports
20 USERS active Gi1/0/10
30 APPLICATIONS active Gi1/0/20
Cisco IOS XE terminal showing VLAN 20 and VLAN 30 SVI configuration and connected route verification

Figure 1: IOS XE CLI with routed VLAN interfaces and the resulting connected routes.


02

Assign One Gateway Address to Each SVI

Layer 3 Gateways

Configure each SVI with the planned gateway and enable Layer 3 forwarding globally. This example uses 10.20.20.1/24 for users and 10.20.30.1/24 for applications.

configure terminal
ip routing
interface Vlan20
description USERS gateway
ip address 10.20.20.1 255.255.255.0
no shutdown
interface Vlan30
description APPLICATIONS gateway
ip address 10.20.30.1 255.255.255.0
no shutdown
end
❯ View Expected Console Output
Vlan20 10.20.20.1 YES manual up up
Vlan30 10.20.30.1 YES manual up up

03

Check the Layer 2 and Layer 3 View

Verification

An SVI becomes operational when its VLAN exists and at least one port in that VLAN is active and forwarding. Verify interface state, VLAN membership, and the routing table.

show ip interface brief | include Vlan20|Vlan30
show vlan brief
show ip route connected
❯ View Expected Console Output
C 10.20.20.0/24 is directly connected, Vlan20
C 10.20.30.0/24 is directly connected, Vlan30

04

Validate Each VLAN from a Test Endpoint

End-to-End

Use an address from each VLAN and set its SVI as the default gateway. Verify gateway reachability first, then test an approved destination in the other subnet and inspect ACLs if forwarding is blocked.

show ip access-lists
show ip route 10.20.30.25
❯ View Expected Console Output
Routing entry for 10.20.30.0/24
Known via "connected", distance 0, metric 0

Comments