cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
428
Views
0
Helpful
6
Replies

ospf switch cannot ping 3rd party router

mmercaldieze
Level 1
Level 1

I am supporting network that is having a route issue and I want to be sure it would be the 3rd party device

3rd party router: 192.168.1.1/24

ASA: 192.168.2.1/24

RouterA: 192.168.3.1/24

Nexus: 192.168.4.1/24

192.168.1.1<--IPSEC TUNNEL-->192.168.2.1-->192.168.3.1<---P2P Network-->192.168.4.1

192.168.2.1, 192.168.3.1 and 192.168.4.1 are connected to eachother via ospf and the ASA is redistributing the routes from the ipsec tunnel

the nexus can see the routes from the 3rd party router but cannot ping anything on the 192.168.1.1 network, but 192.168.3.1 can ping the 192.168.1.0 network 

A traceroute from the nexus shows it getting to RouterA  but then RouterA does not know what to do with this.  I do not believe the 3rd party router has any routes or ACLs on the 192.168.4.0 network

Does the 3rd party router need routes for the 192.168.4.0 network so the Nexus can ping the 192.168.1.0 network?

6 Replies 6

Hello

Is the subnet connecting R3 -R4 advertised in ospf, Can you ping 3rd party RTR  from RTR A sourced from this interface?

Can you share the routing table of R3 and R4


res
Paul


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

Router A can ping the 3rd party router

I can only do part of the routing table due to security standards

destination           gateway         vlan        type

192.168.1.0/24   192.168.2.1      5            ospf

192.168.4.0/24   192.168.4.1      10         connected

looks like ASA doesnt have information about 192.168.4.0 network. Try pinging ASA from Nexus and Vice versa, if that doesnt work then problem is route towards 192.168.4.0 from ASA.

Jon Marshall
Hall of Fame
Hall of Fame

Are you sending the IPs through the VPN tunnel without being translated ?

Have you included the Nexus subnet in your crypto map on the ASA ?

Are you actually exchanging OSPF routes with the 3rd party ?

Jon

Yes I am sending the nexus subnet into the crypto map, the router and nexus are in the same object group

The 3rd party is not part of the ospf, I am redistributing the static routes via  reverse route into the ospf network

Then assuming you are not translating the IPs through the tunnel you need to check what routes the 3rd party router has.

Jon

Review Cisco Networking for a $25 gift card