Hi Rene
After another day of banging my keyboard I learned a few things.
1 - my Barracuda DCHP sever needs to be rebooted on changes - many times it was not giving DCHP (which led me to think VLANS were broken) but on static assignments of IP the VLAN could ping the Firewall. This took 2 days to figure out.
- I finally think I got the TRUNKING correct. I did it this way
Port 1 - TRUNK - 10UP, 100T, 200T
Port 2 - 49 - ACCESS in 3 groups of ports for 10, 100 200
IPV4 routing enabled on Cisco
Subnets and DCHP all defined on Firewall
VLAN routing first set as DCHP one for each 10, 100, 200 worked, but the router got very confused by the same MAC for each IP and would make 10.1.200.1 the gateway for all 3 VLANS, so only that subnet could get internet.
I set the Cisco admin to be 10.1.5.2 static assignment on ACCESS PORT connected to firewall on 10UP. the 10 VLAN is only the spare ports + the ADMIN. I can access this from my laptop that works. After trying 10 ways to get the Internet working by trunking 10UP , deleting all the Cisco VLAN IPs etc I gave up and tried Static. YAY, by giving each VLAN a static ip of 10.1.200.2 and 10.1.100.2, each VLAN uses the Firewalls subnet and acesss to internet and the Laptop finally got the correct gateway of 10.1.100.1 and 10.1.200.1 on each subnet. Before with DCHP the Cisco would put 0.0.0.0 out either VLAN , whichever seemed to get assigned LAST. This failed no idea why really. I also tried just deleting the IPS complely except ADMIN and turning off IPV4 on the Cisco but it didnt work. I thought maybe just using it as L2 with Barracuda doing all the work would be fine, but seems I have got the same effect by assigning the firewall subnet and static IP on VLANs.
I had to create the VLANS, Subnets, DCHP service then assign to PORT 4 of my firewall which is TRUNKED to port 1 (10UP,100T,200T) on Cisco. I tried deleting 10UP from the Trunk but the Cisco gave me ERROR must have one untagged in trunk. Not sure why I have to have an untagged mixed with the two tagged. Or why DCHP was such a pain in the ass. But after 3 days I finally got it working with trial and error.
I also set the default VLAN to 10 and deleted 1
I tested and 10.1.100.1 cannot ping or see the 10.1.200.1 network.
Sounds right to you? Not sure if I just didn’t disabled the L3 good enough or what.