Configure Inter-VLAN Routing on Cisco IOS XE
Inter-VLAN routing lets clients in separate VLANs communicate through a Layer 3 device. This lab configures VLAN 20 and VLAN 30 as directly connected networks on a multilayer switch. It assumes the switch and change are authorized and the private example subnets do not overlap your production plan.
Confirm the platform supports Layer 3 SVIs, the VLANs are carried to client ports, and the gateway addresses are unused before applying the configuration.
Define VLANs and Place Test Ports
Layer 2Create the VLANs and assign only intended test access ports. Identify switchport roles from the topology and change record; do not convert a live uplink to an access port.
configure terminalvlan 20 name USERSvlan 30 name APPLICATIONSinterface GigabitEthernet1/0/10 description Test user endpoint switchport mode access switchport access vlan 20 spanning-tree portfastinterface GigabitEthernet1/0/20 description Test application endpoint switchport mode access switchport access vlan 30 spanning-tree portfastend⯠View Expected Console Output
VLAN Name Status Ports20 USERS active Gi1/0/1030 APPLICATIONS active Gi1/0/20
Figure 1: IOS XE CLI with routed VLAN interfaces and the resulting connected routes.
Assign One Gateway Address to Each SVI
Layer 3 GatewaysConfigure each SVI with the planned gateway and enable Layer 3 forwarding globally. This example uses 10.20.20.1/24 for users and 10.20.30.1/24 for applications.
configure terminalip routinginterface Vlan20 description USERS gateway ip address 10.20.20.1 255.255.255.0 no shutdowninterface Vlan30 description APPLICATIONS gateway ip address 10.20.30.1 255.255.255.0 no shutdownend⯠View Expected Console Output
Vlan20 10.20.20.1 YES manual up upVlan30 10.20.30.1 YES manual up upCheck the Layer 2 and Layer 3 View
VerificationAn SVI becomes operational when its VLAN exists and at least one port in that VLAN is active and forwarding. Verify interface state, VLAN membership, and the routing table.
show ip interface brief | include Vlan20|Vlan30show vlan briefshow ip route connected⯠View Expected Console Output
C 10.20.20.0/24 is directly connected, Vlan20C 10.20.30.0/24 is directly connected, Vlan30Validate Each VLAN from a Test Endpoint
End-to-EndUse an address from each VLAN and set its SVI as the default gateway. Verify gateway reachability first, then test an approved destination in the other subnet and inspect ACLs if forwarding is blocked.
show ip access-listsshow ip route 10.20.30.25⯠View Expected Console Output
Routing entry for 10.20.30.0/24 Known via "connected", distance 0, metric 0