07-26-2006 01:52 PM - edited 03-03-2019 04:14 AM
Hello Everyone,
I am attempting to run and test HSRP but there seems to be some errors.
My first switch is a Catalyst 3550 - 48 Port with SMI image
My second switch is a Catalyst 3550 - 48 Port with EMI image.
I configured HSRP on Vlan12 to try and see if my second switch will take over once I pull the cable out of the first one but it seems like it doesn't.
In the "show standby" command, the second switch shows as "Active router" because I gave it higher priority and it sees the neighbor switch which shows as standby router, so hsrp sees both the switches, knows which one is active and which one is standby but yet when I pull the plug on the first one, network is down, as if it did not revert to the second switch.
My cabling is as follows.
First switch has the first GIG (over fiber) uplink to my provider, the second GIG port is connected to the second gig port on the second switch over fiber as well. The first gig port of the second switch is NOT connected to anything as I only have one provider.
The two ports communicate since hsrp seems the neighbor switches.
The two are configured like this 10.0.0.1 s virtual gateway. 10.0.0.2 is the address of first switch. 10.0.0.3 is address of second switch (backup one). Those IP's are on a MANAGEMENT VLAN which I gave as VLAN ID 100
Now for the VLAN12 I am testing HSRP on, it has VALID INTERNET IP's and not local internal IP's.
Once again, the virtual IP finishes with 225, and I configured 226 as IP on switch1, 227 as IP on switch2.
I am NOT using the track option as I am not sure what it does, I only use the standby priority and preempt options.
So to put it in brief, I am trying to make VLAN12 work with HSRP so that all traffic from VLAN 12 enters switch 1 (from the provider uplink) goes to switch2 since I set vlan12 with higher priority (hsrp) on switch2 goes to the servers, then comes back to switch2, routes to switch1 (since it has to uplink to provider) and out to the internet.
I hope my formatting is not very bad and pretty much understandable.
Can someone please tell me what I am doing wrong and why is hsrp not working for me?
PS: I am suspecting the routing is not done well between one switch and the other so they cannot communicate the traffic, but I am not sure
Please help me
Thank You
08-02-2006 05:32 PM
Hello,
1) It is NOT its default gateway, .70.50 is a free IP, not attached to ANYTHING on my network, so when the customer asked for another IP, I statically router .70.50 to VLAN3 which has default gateway .60.1, so if the end user uses .70.50 on his server, the default gateway should be .60.1 no ?? Please explain in details as I do not understand
2) Normally I create /24 or whatever subnet and I use the IP's on host and default gateway on same subnet, but when a customer wants another IP and there is NO MORE Ip's available on that subnet, I route it as mentionned in number 1 above.
3) Sorry it was now added
4) But if I configure to route to the VLAN, why does it go to the standby 3550 and not the corresponding vlan on the active 3550? why does it go to the standby? the active one also has that vlan, why does it not route there?
Please answer all questions above and check earlier config, hopefully you can tell me exactly what is going on
Thank You
08-02-2006 07:10 PM
1) I understood what you mean. I don't mean 70.50 is the GW, and I mean what is the GW of 70.50. And you answered me 60.1 is the GW.
2) You are correct that I always config. same subnet of host IP & GW IP. So I don't know why it works for you. Because one subnet cannot communicate to other subnets without require L3 switch or routing. I understood your reason but I want to point out the requirement of same subnet between host IP & GW.
3) Thanks. Got it. Could you provide the standby 3550 config. before enable HSRP ? It may work if there is only one 3550 before.
4) In your current (updated) config., the HSRP should select the active 3550 as default GW (60.2).Could you advise which VLAN and user select standby 3550 as next-hop ? Please provide the "sh HSRP" then we can find which one is active HSRP router. Thx.
Please clarify which point and the area that you not understand and I will try my best to clarify it. If you read those HSRP doc. that I provided before, it should tell the operation, limitation of the HSRP.
08-03-2006 02:12 AM
This guide provides the information you need to configure Layer 2 and Layer 3 software features on your switch. The Catalyst 3550 switch is supported by either the standard multilayer software image (SMI) or the enhanced multilayer software image (EMI). The EMI provides a richer set of enterprise-class features, including hardware-based IP unicast and multicast routing, inter-VLAN routing, routed access control lists (ACLs), and the Hot Standby Router Protocol (HSRP).
08-03-2006 07:00 AM
Hello,
the SMI supports the HSRP too as when I input the commands it did recognize it. Plus other forums on the web clearly stated that SMI supports HSRP.
Can you please clarify?
Thanks
08-03-2006 06:59 AM
Hello,
2) The L3 switch IS the 3550 which acts as L2/L3, it is that switch doing the routing of the vlans. Before, there was only ONE 3550, the standby one was not even connected and when I sent a /32 to a vlan whether it was in same subnet or not, it always worked... Since hsrp, it does not work
3) There was no standby 3550 configuration, it was an empty switch. There was only ONE connected 3550 before.
4) I dont know what you mean by next hop, as you saw in all my configs, standby 3550 is NEVER selected for next hop, I only want it in case the active 3550 fails....
5) sh hsrp is not a valid command, do you mean show standby ? (i already provided that to you in other replies).
The POINT I do not understand is WHY are my packets going to the standby 3550 by default, as you saw in traceroute, instead of going to VLAN3 using .60.2 which is active 3550 default gw, it goes to .60.3 which is standby 3550 default gw, WHY does it go there? I mean why would it know to go to standby and not to active?
Thanks
08-04-2006 08:26 AM
Thanks for your reply and sorry for the late reply.
2) This is why it works before, the current problem is two L3 switches forward the packet to each other and create the loop. It does not related to HSRP, you can try to remove the HSRP in one VLAN, it should still create the loop.
3) Got it.
4) What I am trying to say you are correct that the VLAN 3 is the next hop but the standby 3550 also located at VLAN 3 (60.3), so it can receive the packet from primary 3550. Just as you said, if there is only one switch, only the host 70.50 will receive the packet and also return the packet. so it may works. But if there is a router / L3 switch, it will also receive it and forward it that according to the routing table,
5) Sorry for the wrong command, you are correct. It is 'sh standby'. Could you mind to provide again and I want to get the updated status ? According to the config, primary 3550 should be active due to higher priority, so I want to prove it. If it is normal now then it is fine not to provide it.
As I mentioned before, the standby will receive the packet and forward it, due to they located at same VLAN. This is why I am requesting to setup the next hop as IP, but I believe it is quite difficult due to insufficient IP space in your current allocation. I suggest to reallocate the IP address and make all hosts in same VLAN at same subnet then you can simplify the static route in switches. Please consider it.
If you really not able to reallocate the IP, try to remove one HSRP in one VLAN then test the connectivity and isolate the problem. Moreover, I requested to provide the subnet mask of 70.50, could you please tell me ? I really want to know why it works before or please provide the pervious working host IP & GW, it helps to undrstand more why it works before and why not now.
Wait for your update.
08-04-2006 10:41 AM
Hello,
4) Ok but I don't have a router, all I have are those 2 3550's switches.
5) show standby shows everything as it should be. All active states belong to the primary 3550, hsrp looks normal.
Why are you saying impossible due to insufficient IP space, what makes you say that ? I cannot reallocate IP's, customers are already using it. Also I don't understand what you mean by next hop instead of VLANs, can you give an example route with next hop for my network?
Subnet mask of .70.50 is 255.255.255.255 I route it as a SINGLE IP since customer requested ONE MORE IP
You have all that in the config...
THanks
08-04-2006 08:42 PM
Offical (not forum):
This chapter describes how to use Hot Standby Router Protocol (HSRP) to provide routing redundancy for routing IP traffic without being dependent on the availability of any single router. To use this feature, you must have the enhanced multilayer software image installed on your switch. All Catalyst 3550 Gigabit Ethernet switches ship with the enhanced multilayer software image (EMI) installed. Catalyst 3550 Fast Ethernet switches can be shipped with either the standard multilayer software image (SMI) or EMI pre-installed. You can order the Enhanced Multilayer Software Image Upgrade kit to upgrade Catalyst 3550 Fast Ethernet switches from the SMI to the EMI.
08-04-2006 10:50 PM
Hello,
One of my switch is EMI (I think) and the other one SMI, basically, I had an SMI switch and I upgrade the IOS (or perhaps downgraded) to an EMI ios image I had, does that make my 3550 an EMI now or something else needs to be done?
Also, could this be the problem I am getting?
Thanks
08-05-2006 01:35 AM
I understood your situation. If you cannot reallocate the IP, then it may require a device to provide NAT (Network Address Translation) function to have the Port Address Translation to make all hosts at same subnet but tranlate them to a single IP which is assigned by you.
Sorry if I am misleading you. What I mean the IP Space is I think you cannot assign new IP address to the user that is the same subnet of existing usage. It was because it is already using by the customer and difficult to reallocate most of the IP assignments. It is only related to the IP address assignment plan and not mean you cannot do it.
I mean to use next-hop as IP as below :
ip route x.x.x.x 255.255.255.0 y.y.y.y
instead y.y.y.y is the next-hop that just like your default static route.
If all hosts in same VLAN are configured in same subnet then there is no need to configue those static route, because it is the local subnet of the interface.
What I mean the subnet mask of 70.50 in the PC /sever and not in the switch. Can you confirmed that you configure as 255.255.255.255 in the PC/Server ?
BTW, I just have a new idea but don't know you will accept it or not, please comment.
You can still use the assigned IP address to users. But you have to create new VLAN for new subnet instead of using the same VLAN for different subnets.
Enable those new & old VLANs at the trunk between 3550s and 2950. Assign those new VLAN at 2950 as access mode. e.g. 70.50 change from VLAN3 to VLAN70 and create the VLAN 70 at both 3550 & 2950. Assign the IP address (e.g. 70.2 & 3) to VLAN 70 and condfigure the HSRP group (e.g. IP = 70.1) in the VLAN 70. Configure the 70.50 with 70.1 as default GW. Then you don't need the static routes in 3550, because the 70.x is the local interface and no need to configure the static route.
But if the user is using another hub or switch to connect to the 2950 then we need to enable the trunk at 2950 to the user switch (cannot support hub). If the user is connecting to the 2950 directly, then you can use this solution to fix the problem.
Moreover, there is another issue that if the primary between 3550 and 2950 down, the traffic cannot return to the standby 3550, it was the local interface (VLAN) in primary 3550 still up and not able to route via interlink between 3550s. I think we need to add a connection at ISP and remove the interlink. So I come up another solution :
Due to there is only one ISP connection, if use two 3550 then the single point of failure still on the primary 3550. So, we can stack two 3550 together and create a Etherchannel from two 3550s to the 2950. Then no more HSRP and routing between two 3550 is required. But we need the Gigastack cable and the 3550 should be placed at the same closet.It sounds much simpler and no more problem.
The current problem is the routing loop and IP address assignment, if we use the above proposed solution, we can remove lots of static route and maintain assigned IP. But the cons. is we need to create additonal VLAN for individual subnets.
Last issue, if you upgrade your 3550 IOS to 12.1.(11)EA1 or later, it can support the dynamic routing protocol. Check here :
http://www.cisco.com/en/US/tech/tk389/tk815/technologies_configuration_example09186a008019e74e.shtml
Please comment. Hope it really help to solve the problem.
08-05-2006 09:32 AM
Hello,
My network is already separated with Vlans and next hop as vlans. I cannot change everything into vlans as I have so many IP routes because many customers wanted only 1 IP, so I routed it with /32, I don't want to create separate vlans for all that as it can be big hassle...
I thought maybe my problem is the following:
I have one switch running SMI and the other EMI, can that be the problem?
Here are the ISO versions:
Active 3550: 12.2(25)SEE - IP BASE
Standby 3550: 12.1(22)EA8 - EMI
Can this be the problem?
Also, please answer this question. My standby 3550 came originally with SMI image but I had the above EMI package so I changed the IOS, does that make my 3550 with complete EMI functions now? or something else needs to be done?
Thanks
08-05-2006 10:17 AM
According to the link that I stated in my last message, there is no more SMI after 12.1.11EA1,so I believe both of your switch will support EMI. Once you upgraded to EMI, it does support EMI feature due to it is the running ver.
For the VLAN issue, in my suggestion, if you can create the additional VLANs for the new subnets, you won't require those /32 mask static route, so it should be no more problem. And the user only require to assign the new GW address and won't affect the user too much.
Please also consider to stack two 3550 as a sinlge domain then there will be no more HSRP issue.
I understood there will be lots of problem if you create new VLAN for new subnet, but it is the only solution that I can propose at the moment.
If you insist not to create new VLAN, then I will suggest not to use HSRP due to there is single point of failure of the connection to ISP, then just use the standby 3550 as a cascaded switch of primary 3550 then there will be no more problem too.
Please advise your prefernece. Hope I can help but the situation is limited.
08-05-2006 10:52 AM
Hello,
1) But on my SMI with the latest version, in my Cisco Network Assistant I DON'T see IGRP, EIRGP for my active 3550 which runs SMI latest version. BUT I DO see those routing protocols for the EMI switch running an earlier version but specific to EMI, what is th eexact check I can do to check really what each supports?
2) I will check for the vlans issue and try to put everyone on vlans.
3) How do I stack two 3550 as a single domain? what is the procedure to do that?
4) After we implement HSRP, we will add ANOTHER provider on the MAIN uplink of standby 3550 and run BGP as well in HSRP environment, so for now we want to integrated HSRP as later on there will be NO ONE POINT of failure.
Please answer 4 points above.
Thanks
08-05-2006 10:19 PM
1) The 12.2 IPbase is the IP only w/o those routing protocol. You have to upgrade to IP Services feature set or EMI. According to below link, you can download the EMI (IP Services) software at "no additional cost", I tried and able to download the file. Then you will able to enable routing at both switches.
http://www.cisco.com/en/US/products/hw/switches/ps646/products_qanda_item09186a00800913d3.shtml
2) Thanks for that.
3) Please check below for the stack info. If you will have another provider in future then it may better to keep your design w/ two 3550s as L3 switches.
http://www.cisco.com/en/US/products/hw/switches/ps646/products_data_sheet09186a00800a1789.html
4) This is great, please test the VLAN suggestion then you will have no more problem and minimize all potential problem in future. Because use separated VLANs, you don't need those static route and the BGP will also be much simpler. Please remember to consult w/ two providers to enure the network will work w/ both providers and how to make one provider as the active and the other as standby or load-sharing the links. It will be quite complicated issue in future. You can also ask the provider to provide sample config. However, you have to upgrade the active 3550 w/ 3550 (IP Services) first to enable the routing protocol.
Hope this helps.
08-06-2006 07:09 AM
Hello,
1) Can you please give me the exact version to download? because the latest EMI IOS I found on cisco's website is:
c3550-i5q3l2-tar.121-22.EA8.tar
Is that the correct one? Does that include everything I will need?
2) Also if there is a later version that I can have that will work, that is fine, but please tell me exactly what file name. Make sure it has all EMI features because I will have BGP on those afterwards.
3) Can I upgrade a switch in production? Will the config be lost? How much downtime should I expect from the switch? Please tell me exactly how I should upgrade it and with what precautions to take.
4) Let me know what is the best IOS version to put on BOTH the 3550's so they are the same and can run all EMI features.
Thank You
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide