cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
494
Views
0
Helpful
1
Replies

Dot 1Q Trunking to a pair of CheckPoint IP 380

mrbmchitlin
Level 1
Level 1

Hi, I am having problems getting trunking working between 2 firewalls and 2 6506 switches (System image file is "sup-bootflash:s72033-psv-mz.122-18.SXD7.bin"

cisco WS-C6506-E (R7000) processor (revision 1.0)

I am dot1q trunking 2 vlans into the CheckPoint IP 380s and the odd thing is that once configured I am able to ping the vrrp addresses and both vip addresses of both subnets on the firewall however connectivity is lost between the firewalls and all other devices on these 2 subnets. (The pings enter the firewall via another physical interface which is the next hop towards the two subnets we're trunking to.)

The switch seems to think it is trunking, and the firewalls respond to the pings so think those nets are up, and yet it is plainly broken.

Any thoughts would be appreciated. Tx

1 Reply 1

wong34539
Level 6
Level 6

For trunking to be autonegotiated, the ports must be in the same VLAN Trunking Protocol (VTP) domain. However, you can use the on or nonegotiate mode to force a port to become a trunk, even if it is in a different domain. For more information on VTP domains, see "Configuring VTP."

http://cisco.com/en/US/docs/switches/lan/catalyst6500/catos/8.x/configuration/guide/e_trunk.html

Review Cisco Networking for a $25 gift card