cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2287
Views
15
Helpful
17
Replies

L2tpv3 don't forward traffic

Maurizio Roggia
Level 1
Level 1

Hi All, 

I'm currently stuck on wondering why l2tpv3 is up but traffic don't forward and my target to extend Vlan from 1 router to another doesn't work

In attaching the configuration but basically, I have two industrial IR1101 with LTE module.

Through this LTE is running a normal tunnel Gre.

Then I tried to configure xconnect, firstly, I tried to configure directly on the VLAN, but router don't permit xconnect on the VLAN. So I used a g0/0/0 to create a sub interface dot1q with the same vlan and at this interface Xconnect works.

I used source and destination of the tunnel create through a LTE connection.

So the Xconnect show the segment UP and to extend the VLAN, I connect the G0/0/0 to the first port of the 4 port switch of the same router. From both side I saw the VLAN going up, if I connect 1 pc on 1 port switch of the router and the same in the other end, there no any traffic at all.

Someone could help me?

Many thanks

17 Replies 17

Hello,

I don't see any l2tp-class configs on either router. Try and add the lines marked in bold:

routchamois

l2tp-class interworking-ethernet-class
authentication
hostname routchamois
password 0 cisco
!
pseudowire-class ROUT
encapsulation l2tpv3
interworking ethernet
protocol l2tpv3 interworking-ethernet-class
ip local interface Tunnel0

routbuisson

l2tp-class interworking-ethernet-class
authentication
hostname routbuisson
password 0 cisco
!
pseudowire-class ROUT
encapsulation l2tpv3
interworking ethernet
protocol l2tpv3 interworking-ethernet-class
ip local interface Tunnel0

Hi Georg, thx for the rapid answer, unfortunately yesterday I was not able to fight with this configuration.

I just tried now. I insert the class for l2tp, but still no traffic from the switch port 

From your experience if I connect the g0/0/0.1 with connect to just a transport of the fastethernet as follow in the configuration, the other pc on the 3 other port of the router should talk on VLAN 1 and extend VLAN 1 through Xconnect right?

AS before I also verify that the tunnel is up and I can ping from one side to another.

This configuration drive me crazy, your help value much more than a beer

the config of the ethernet port after you suggestion:

ROUTBUISSON:

interface GigabitEthernet0/0/0.1
encapsulation dot1Q 1 native
xconnect 192.168.250.2 1 encapsulation l2tpv3 pw-class ROUT
!
interface FastEthernet0/0/1
switchport mode trunk
spanning-tree portfast
!
interface FastEthernet0/0/2
switchport mode access
!
interface FastEthernet0/0/3
!
interface FastEthernet0/0/4

!

interface Vlan1
ip address 172.31.50.11 255.255.255.192
ip nat inside
no ip virtual-reassembly

ROUTCHAMOIS

interface GigabitEthernet0/0/0.1
encapsulation dot1Q 1 native
xconnect 192.168.250.1 1 encapsulation l2tpv3 pw-class ROUT
!
interface FastEthernet0/0/1
switchport mode trunk
!
interface FastEthernet0/0/2
switchport mode access
!
interface FastEthernet0/0/3
!
interface FastEthernet0/0/4

!

interface Vlan1
ip address 172.31.50.10 255.255.255.192
no ip virtual-reassembly

 

Hi, still this issue?
can you add SW to router in each Side?

already did, I add a switch to connect the g0/0/0.1 and the pc in both end, but nothing change..this is sound to me very strange

Now we talking 
pseudowire-class MHM
encapsulation l2tpv3
ip local interface Loopback0
ip pmtu
ip tos value 10
!
!
interface Loopback0
ip address x.x.x.x
!
interface FastEthernet0/0.1
encapsulation dot1Q 5
xconnect y.y.y.y 100 encapsulation l2tpv3 pw-class mhm

in other side same config except the LO config with y.y.y.y

As you can see, the xconnect is UP and the show l2tp tunnel all show the packet sent and received, but no traffic from the 2 pc in both side, Wireshark don't show any packet coming on the pc and viceversa

ok, you config static ip in PC ?
are the FW for PC is allow ping ?
if you connect SW, 
then config the SVI for VLAN in SW and try ping from SW to SW

of course, is static, of course pc can pc vlan switch interface, of course if I directly connect the 2 pc with a direct ethernet cable can ping each other, and no of course with xconnect I can't ping between pc as well as between SVI Vlan ip interface of the switch

 

show l2tun session packet 
do ping and check the command again are the counter increase or not ?

increase! according with how many ping try from both side. If I stop ping, stop also the counter.

That's why, It looks so strange... and just because I don't have enough and I want to solve this feature that actually should be a commodity, I create another lab with 2 ISR4321 , one gigaport I used to direct connect the 2 router, and the other gigaethernet I used to create the xconnect from the 2 router, I do this, to clarify that the problem shouldn't create from the new Industrial router IR1101 and that the tunnel create by a cellular LTE interface.

And surprice, I have the same behavior: xconnect and l2tp tunnel work sa well as the counter, but pc, and SVI od the switch can't ping each other, also wireshark on the pc don't show any packet coming

I don't know what can be. on the prerequisite are just written that CEF should be enable and the source interface should be a tunnel.

And i verify also both of this.

Is it possible find 1 person that happen the same issue??

NOW 
tunnel is UP and router forward the traffic through the tunnel, 
only 
show ip interface <interface you use for Xconnect>

check the INPUT/OUTPUT counter are it increase with your ping,
not ping with at least repeat 20 

routbuisson#sh int gigabitEthernet 0/0/0
GigabitEthernet0/0/0 is up, line protocol is up
Hardware is ISR4321-2x1GE, address is b4a8.b901.59f0 (bia b4a8.b901.59f0)
MTU 1500 bytes, BW 1000000 Kbit/sec, DLY 10 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive not supported
Full Duplex, 1000Mbps, link type is auto, media type is RJ45
output flow-control is on, input flow-control is on
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:27:25, output 00:00:16, output hang never
Last clearing of "show interface" counters never
Input queue: 0/375/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
672 packets input, 96220 bytes, 0 no buffer
Received 483 broadcasts (0 IP multicasts)
0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 watchdog, 189 multicast, 0 pause input
3949 packets output, 381143 bytes, 0 underruns

routbuisson#sh int gigabitEthernet 0/0/0
GigabitEthernet0/0/0 is up, line protocol is up
Hardware is ISR4321-2x1GE, address is b4a8.b901.59f0 (bia b4a8.b901.59f0)
MTU 1500 bytes, BW 1000000 Kbit/sec, DLY 10 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive not supported
Full Duplex, 1000Mbps, link type is auto, media type is RJ45
output flow-control is on, input flow-control is on
ARP type: ARPA, ARP Timeout 04:00:00
Last input 00:27:51, output 00:00:42, output hang never
Last clearing of "show interface" counters never
Input queue: 0/375/0/0 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/40 (size/max)
5 minute input rate 0 bits/sec, 0 packets/sec
5 minute output rate 0 bits/sec, 0 packets/sec
677 packets input, 96520 bytes, 0 no buffer
Received 488 broadcasts (0 IP multicasts)
0 runts, 0 giants, 0 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
0 watchdog, 189 multicast, 0 pause input
3992 packets output, 384204 bytes, 0 underruns

 

if I stop ping the counter stop, of course I did sh int giga0/0/0 because sh int giga0/0/0.1 don't show counter

 

routbuisson#sh int gigabitEthernet 0/0/0.1
GigabitEthernet0/0/0.1 is up, line protocol is up
Hardware is ISR4321-2x1GE, address is b4a8.b901.59f0 (bia b4a8.b901.59f0)
MTU 1500 bytes, BW 1000000 Kbit/sec, DLY 10 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation 802.1Q Virtual LAN, Vlan ID 1.
ARP type: ARPA, ARP Timeout 04:00:00
Keepalive not supported
Last clearing of "show interface" counters never

ping from the PC or from SW with MTU 1000 and check again.
1500 add to that l2tp overhead this give you more than 1560 this can accept in some router but other drop it.

also when ping check the Queue of interface with 
show interface g0/0/0 summary

hi Friend 
can I see 
show l2tun session all 

Review Cisco Networking for a $25 gift card