cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1205
Views
0
Helpful
10
Replies

Subnet advertising problems, 2821, 1841

Adam Hudson
Level 1
Level 1

I have two virtual servers that sit in my DMZ subnet. Pinging back and forth between these servers and other servers/machines at my main site (Site A) just fine. Between these servers and two my other sites (Site B and Site C) however, I cannot ping. Other devices that physically sit in the DMZ can connect to machines at these remote sites.

I thought it was an issue with the ACL so I pulled it and applied an "icmp any any" ACL but this didn't change my ping results. Upon checking the learned routes for my two remote sites I found that neither site had my DMZ subnet. Here's where the confusion comes in at, I have the subnet advertised to both sites. Can someone help with me this?

Sanitized configs will be attached.

=====

Facts:

Site A Firewall - Cisco ASA 5520

Site A Router - Cisco 2821

Site A to Site B connection: Fiber running EIGRP

Site B Router - Cisco 1841

Site A to Site C connection: MPLS line running BGP

Site C Router - Cisco 1841

=====

Testing:

Ping back and forth with ACL attached to DMZ interface, pings fail.

Pull ACL off of DMZ interface, pings fail.

Put "icmp any any" ACL on DMZ, pings fail.

Packet tracer ping test comes back successfully, but I never trust packet tracer results.

10 Replies 10

Jon Marshall
Hall of Fame
Hall of Fame

Adam

It's a bit confusing because you say "Other devices that physically sit in the DMZ can connect to machines at these remote sites" but you then say that the dmz route is not being learnt at the remote site so how do the machines connect ?

Could you clarify ?

If it is the case that the routes are not there can you post -

"sh ip route" and "sh ip bgp"  from all sites.

Jon

I was unclear about the connection situation myself. After looking, the machine housing the virtual servers does have one interface plugged into a small switch that's plugged into our dmz port.

After doing more checking I was wrong about the other devices being able to connect remotely, they cannot.

A co-worker pointed out the "passive-interface dmz" line in the EIGRP section of my Site A FW config. I removed this, pings worked from Site A to Site C for a limited amount of time, then quit. Back to square one.

So I've added a static route into my Site A router (which I shouldn't have to do because the route to my DMZ shows up on the Site A firewall just fine. For some reason the route is being communicated between the router and firewall.) and now the route for the DMZ shows up in Site B and Site C routers as well, goodie.

But, when I ping back to the DMZ from Site B and Site C the pings fail. Trace routing traces back to the Site A router, but no further. This also doesn't make any sense to me because the Site A router knows the route back to the DMZ, so why isn't traffic being pushed back over the routers connection to the DMZ?

In addition, adding that default route has interupted communication the devices in the DMZ have with the local subnet.

The mystery deepens. Any help is appreciated.

Adam

As requested can you post from site A/B/C router -

1) sh ip route

2) sh ip bgp

and from the ASA firewall "sh route"

If the devices hve many routes then just post the output for the specific DMZ subnet.

Can you also specify what subnet you are pinging from at the remote end ?

Jon

Here are the "sh ip route" and "sh ip bgp"/"sh ip eigrp neighbor" from my routers:



SiteA#sh ip rou

Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP

       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area

       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2

       E1 - OSPF external type 1, E2 - OSPF external type 2

       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2

       ia - IS-IS inter area, * - candidate default, U - per-user static route

       o - ODR, P - periodic downloaded static route


Gateway of last resort is 11.254.1.1 to network 0.0.0.0


     207.250.33.0/28 is subnetted, 4 subnets

D EX    207.250.33.16 [170/3072] via 11.254.1.1, 7w0d, GigabitEthernet0/0

D EX    207.250.33.0 [170/3072] via 11.254.1.1, 7w0d, GigabitEthernet0/0

D EX    207.250.33.144 [170/3072] via 11.254.1.1, 7w0d, GigabitEthernet0/0

D EX    207.250.33.128 [170/3072] via 11.254.1.1, 7w0d, GigabitEthernet0/0

     199.37.161.0/30 is subnetted, 4 subnets

B       199.37.161.64 [20/0] via 13.116.127.81, 1w4d

B       199.37.161.40 [20/0] via 13.116.127.81, 1w4d

B       199.37.161.48 [20/0] via 13.116.127.81, 1w4d

B       199.37.161.56 [20/0] via 13.116.127.81, 1w4d

     173.226.0.0/26 is subnetted, 1 subnets

D EX    173.226.50.128 [170/3072] via 11.254.1.1, 7w0d, GigabitEthernet0/0

     11.1.0.0/8 is variably subnetted, 13 subnets, 2 masks

D       11.2.2.0/24 [90/30720] via 11.253.0.2, 3d16h, FastEthernet0/3/0

C       11.2.1.0/24 is directly connected, GigabitEthernet0/1

C       11.1.1.0/24 is directly connected, GigabitEthernet0/1

B       11.8.0.0/24 [20/0] via 13.116.127.81, 7w0d

S       11.2.40.0/24 is directly connected, GigabitEthernet0/1

S       11.2.70.0/24 is directly connected, GigabitEthernet0/1

S       11.101.0.0/24 [1/0] via 11.1.1.129

S       11.101.1.0/24 [1/0] via 11.1.1.129

S       11.2.100.0/24 is directly connected, GigabitEthernet0/1

C       11.254.1.0/30 is directly connected, GigabitEthernet0/0

C       11.253.0.0/30 is directly connected, FastEthernet0/3/0

B       11.254.3.0/30 [20/0] via 13.116.127.81, 7w0d

D       11.254.2.0/30 [90/30720] via 11.253.0.2, 3d16h, FastEthernet0/3/0

     12.0.0.0/8 is variably subnetted, 3 subnets, 2 masks

C       13.116.127.80/30 is directly connected, Multilink1

B       12.38.168.0/24 [20/0] via 13.116.127.81, 7w0d

B       13.116.127.172/30 [20/0] via 13.116.127.81, 4w6d

     73.0.0.0/26 is subnetted, 1 subnets

D EX    73.44.242.64 [170/3072] via 11.254.1.1, 7w0d, GigabitEthernet0/0

     135.89.0.0/16 is variably subnetted, 4 subnets, 2 masks

B       135.89.152.56/29 [20/0] via 13.116.127.81, 7w0d

B       135.89.152.128/28 [20/0] via 13.116.127.81, 7w0d

B       135.89.154.152/29 [20/0] via 13.116.127.81, 7w0d

B       135.89.157.160/28 [20/0] via 13.116.127.81, 7w0d

S    193.169.222.0/24 [1/0] via 11.1.1.70

D*EX 0.0.0.0/0 [170/3072] via 11.254.1.1, 7w0d, GigabitEthernet0/0

==---==

SiteB#sh ip route

Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP

       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area

       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2

       E1 - OSPF external type 1, E2 - OSPF external type 2

       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2

       ia - IS-IS inter area, * - candidate default, U - per-user static route

       o - ODR, P - periodic downloaded static route


Gateway of last resort is 11.254.2.1 to network 0.0.0.0


     207.250.33.0/28 is subnetted, 4 subnets

D EX    207.250.33.16 [170/28672] via 11.253.0.1, 3d17h, FastEthernet0/1/0

D EX    207.250.33.0 [170/28672] via 11.253.0.1, 3d17h, FastEthernet0/1/0

D EX    207.250.33.144 [170/28672] via 11.253.0.1, 3d17h, FastEthernet0/1/0

D EX    207.250.33.128 [170/28672] via 11.253.0.1, 3d17h, FastEthernet0/1/0

     199.37.161.0/30 is subnetted, 4 subnets

D EX    199.37.161.64 [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

D EX    199.37.161.40 [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

D EX    199.37.161.48 [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

D EX    199.37.161.56 [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

     173.226.0.0/26 is subnetted, 1 subnets

D EX    173.226.50.128 [170/28672] via 11.253.0.1, 3d17h, FastEthernet0/1/0

     11.1.0.0/8 is variably subnetted, 10 subnets, 2 masks

C       11.2.2.0/24 is directly connected, FastEthernet0/1

D EX    11.2.1.0/24 [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

D EX    11.1.1.0/24 [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

D EX    11.8.0.0/24 [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

D EX    11.2.40.0/24 [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

D EX    11.2.70.0/24 [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

D       11.254.1.0/30 [90/28416] via 11.253.0.1, 3d17h, FastEthernet0/1/0

C       11.253.0.0/30 is directly connected, FastEthernet0/1/0

D EX    11.254.3.0/30 [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

C       11.254.2.0/30 is directly connected, FastEthernet0/0

     12.0.0.0/8 is variably subnetted, 2 subnets, 2 masks

D EX    12.38.168.0/24 [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

D EX    13.116.127.172/30

           [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

     73.0.0.0/26 is subnetted, 1 subnets

D EX    73.44.242.64 [170/28672] via 11.253.0.1, 3d17h, FastEthernet0/1/0

     135.89.0.0/16 is variably subnetted, 4 subnets, 2 masks

D EX    135.89.152.56/29

           [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

D EX    135.89.152.128/28

           [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

D EX    135.89.154.152/29

           [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

D EX    135.89.157.160/28

           [170/1709312] via 11.253.0.1, 3d17h, FastEthernet0/1/0

S*   0.0.0.0/0 [1/0] via 11.254.2.1

==--==

SiteC#sh ip rou

Codes: C - connected, S - static, R - RIP, M - mobile, B - BGP

       D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area

       N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2

       E1 - OSPF external type 1, E2 - OSPF external type 2

       i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2

       ia - IS-IS inter area, * - candidate default, U - per-user static route

       o - ODR, P - periodic downloaded static route


Gateway of last resort is 11.254.3.1 to network 0.0.0.0


     207.250.33.0/28 is subnetted, 4 subnets

B       207.250.33.16 [20/0] via 13.116.127.173, 7w0d

B       207.250.33.0 [20/0] via 13.116.127.173, 7w0d

B       207.250.33.144 [20/0] via 13.116.127.173, 7w0d

B       207.250.33.128 [20/0] via 13.116.127.173, 7w0d

     199.37.161.0/30 is subnetted, 4 subnets

B       199.37.161.64 [20/0] via 13.116.127.173, 1w4d

B       199.37.161.40 [20/0] via 13.116.127.173, 1w4d

B       199.37.161.48 [20/0] via 13.116.127.173, 1w4d

B       199.37.161.56 [20/0] via 13.116.127.173, 1w4d

     173.226.0.0/26 is subnetted, 1 subnets

B       173.226.50.128 [20/0] via 13.116.127.173, 7w0d

     11.1.0.0/8 is variably subnetted, 13 subnets, 2 masks

B       11.2.2.0/24 [20/0] via 13.116.127.173, 3d17h

B       11.2.1.0/24 [20/0] via 13.116.127.173, 7w0d

B       11.1.1.0/24 [20/0] via 13.116.127.173, 7w0d

C       11.8.0.0/24 is directly connected, FastEthernet0/1

B       11.2.40.0/24 [20/0] via 13.116.127.173, 7w0d

B       11.2.70.0/24 [20/0] via 13.116.127.173, 7w0d

B       11.101.0.0/24 [20/0] via 13.116.127.173, 7w0d

B       11.101.1.0/24 [20/0] via 13.116.127.173, 7w0d

B       11.2.100.0/24 [20/0] via 13.116.127.173, 7w0d

B       11.254.1.0/30 [20/0] via 13.116.127.173, 7w0d

B       11.253.0.0/30 [20/0] via 13.116.127.173, 7w0d

C       11.254.3.0/30 is directly connected, FastEthernet0/0

B       11.254.2.0/30 [20/0] via 13.116.127.173, 3d17h

     12.0.0.0/8 is variably subnetted, 3 subnets, 2 masks

B       13.116.127.80/30 [20/0] via 13.116.127.173, 7w0d

B       12.38.168.0/24 [20/0] via 13.116.127.173, 7w0d

C       13.116.127.172/30 is directly connected, Serial0/0/0

     73.0.0.0/26 is subnetted, 1 subnets

B       73.44.242.64 [20/0] via 13.116.127.173, 7w0d

     135.89.0.0/16 is variably subnetted, 4 subnets, 2 masks

B       135.89.152.56/29 [20/0] via 13.116.127.173, 7w0d

B       135.89.152.128/28 [20/0] via 13.116.127.173, 7w0d

B       135.89.154.152/29 [20/0] via 13.116.127.173, 7w0d

B       135.89.157.160/28 [20/0] via 13.116.127.173, 7w0d

B    193.169.222.0/24 [20/0] via 13.116.127.173, 7w0d

S*   0.0.0.0/0 [1/0] via 11.254.3.1

==--==--==

SiteC#sh bgp

BGP table version is 792, local router ID is 13.116.127.174

Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,

              r RIB-failure, S Stale

Origin codes: i - IGP, e - EGP, ? - incomplete


   Network          Next Hop            Metric LocPrf Weight Path

*> 11.1.1.0/24      13.116.127.173                         0 7018 7018 i

*> 11.2.1.0/24      13.116.127.173                         0 7018 7018 i

*> 11.2.2.0/24      13.116.127.173                         0 7018 7018 ?

*> 11.2.40.0/24     13.116.127.173                         0 7018 7018 i

*> 11.2.70.0/24     13.116.127.173                         0 7018 7018 i

*> 11.2.100.0/24    13.116.127.173                         0 7018 7018 ?

*> 11.8.0.0/24      0.0.0.0                  0         32768 i

*> 11.101.0.0/24    13.116.127.173                         0 7018 7018 ?

*> 11.101.1.0/24    13.116.127.173                         0 7018 7018 ?

*> 11.253.0.0/30    13.116.127.173                         0 7018 7018 ?

*> 11.254.1.0/30    13.116.127.173                         0 7018 7018 i

*> 11.254.2.0/30    13.116.127.173                         0 7018 7018 ?

*> 11.254.3.0/30    0.0.0.0                  0         32768 i

*> 12.38.168.0/24   13.116.127.173                         0 7018 2386 i

*> 13.116.127.80/30 13.116.127.173                         0 7018 ?

r> 13.116.127.172/30

                    13.116.127.173           0             0 7018 ?

*> 73.44.242.64/26  13.116.127.173                         0 7018 7018 ?

*> 135.89.152.56/29 13.116.127.173                         0 7018 2386 i

*> 135.89.152.128/28

                    13.116.127.173                         0 7018 2386 i

*> 135.89.154.152/29

                    13.116.127.173                         0 7018 2386 i

*> 135.89.157.160/28

                    13.116.127.173                         0 7018 2386 i

*> 173.226.50.128/26

                    13.116.127.173                         0 7018 7018 ?

*> 193.169.222.0    13.116.127.173                         0 7018 7018 ?

*> 199.37.161.40/30 13.116.127.173                         0 7018 i

*> 199.37.161.48/30 13.116.127.173                         0 7018 i

*> 199.37.161.56/30 13.116.127.173                         0 7018 i

*> 199.37.161.64/30 13.116.127.173                         0 7018 i

*> 207.250.33.0/28  13.116.127.173                         0 7018 7018 ?

*> 207.250.33.16/28 13.116.127.173                         0 7018 7018 ?

*> 207.250.33.128/28

                    13.116.127.173                         0 7018 7018 ?

*> 207.250.33.144/28

                    13.116.127.173                         0 7018 7018 ?

SiteC#

==--==--==

SiteA#sh bgp

BGP table version is 425, local router ID is 13.116.127.82

Status codes: s suppressed, d damped, h history, * valid, > best, i - internal,

              r RIB-failure, S Stale

Origin codes: i - IGP, e - EGP, ? - incomplete


   Network          Next Hop            Metric LocPrf Weight Path

*> 11.1.1.0/24      0.0.0.0                  0         32768 i

*> 11.2.1.0/24      0.0.0.0                  0         32768 i

*> 11.2.2.0/24      11.253.0.2              20         32768 ?

*> 11.2.40.0/24     0.0.0.0                  0         32768 i

*> 11.2.70.0/24     0.0.0.0                  0         32768 i

*> 11.2.100.0/24    0.0.0.0                  0         32768 ?

*> 11.8.0.0/24      13.116.127.81                          0 7018 7018 i

*> 11.101.0.0/24    11.1.1.129               0         32768 ?

*> 11.101.1.0/24    11.1.1.129               0         32768 ?

*> 11.253.0.0/30    0.0.0.0                  0         32768 ?

*> 11.254.1.0/30    0.0.0.0                  0         32768 i

*> 11.254.2.0/30    11.253.0.2              20         32768 ?

*> 11.254.3.0/30    13.116.127.81                          0 7018 7018 i

*> 12.38.168.0/24   13.116.127.81                          0 7018 2386 i

r> 13.116.127.80/30 13.116.127.81            0             0 7018 ?

*> 13.116.127.172/30

                    13.116.127.81                          0 7018 ?

*> 73.44.242.64/26  11.254.1.1              20         32768 ?

*> 135.89.152.56/29 13.116.127.81                          0 7018 2386 i

*> 135.89.152.128/28

                    13.116.127.81                          0 7018 2386 i

*> 135.89.154.152/29

                    13.116.127.81                          0 7018 2386 i

*> 135.89.157.160/28

                    13.116.127.81                          0 7018 2386 i

*> 173.226.50.128/26

                    11.254.1.1              20         32768 ?

*> 193.169.222.0    11.1.1.70                0         32768 ?

*> 199.37.161.40/30 13.116.127.81                          0 7018 i

*> 199.37.161.48/30 13.116.127.81                          0 7018 i

*> 199.37.161.56/30 13.116.127.81                          0 7018 i

*> 199.37.161.64/30 13.116.127.81                          0 7018 i

*> 207.250.33.0/28  11.254.1.1              20         32768 ?

*> 207.250.33.16/28 11.254.1.1              20         32768 ?

*> 207.250.33.128/28

                    11.254.1.1              20         32768 ?

*> 207.250.33.144/28

                    11.254.1.1              20         32768 ?

SiteA#

==--==--==

SiteA#sh ip eigrp neigh

IP-EIGRP neighbors for process 101

H   Address                 Interface       Hold Uptime   SRTT   RTO  Q  Seq

                                            (sec)         (ms)       Cnt Num

1   11.253.0.2              Fa0/3/0           12 3d17h       4   200  0  17

0   11.254.1.1              Gi0/0             10 8w4d        1   200  0  116

SiteA#

==--==--==

SiteB#sh ip eigrp neigh

IP-EIGRP neighbors for process 101

H   Address                 Interface       Hold Uptime   SRTT   RTO  Q  Seq

                                            (sec)         (ms)       Cnt Num

1   11.253.0.1              Fa0/1/0           14 3d17h       6   200  0  542

0   11.254.2.1              Fa0/0             13 3d17h      35   210  0  11

SiteB#

After going through all of that information, I thought I knew what was wrong, I didn't see the DMZ subnet (directly connected on the Site A Firewall) on the Site A router. After adding a static route to the DMZ subnet on the Site A router, and adding the network advertisment in my EIGRP to advertise the DMZ subnet, I still could not ping across the network. In addition, now the machines in the DMZ weren't working with the local networks.

I am more confused now.

Also, I am pinging from the the DMZ subnet (173.17.1.0) to the site B and C subnets (mainly 11.8.0.0 and 11.2.2.0) with no look coming at it from either end. After making the aforementioned changes the pings coming from the Site B and C stop at the Site A router, which makes me think there's something blocking/not allowing communiction for that subnet between Site A router and Site A firewall.

Also, here is a diagram of my network.

Adam

Looking at Site A routing table there is no mention of 173.17.1.0 so it won't be advertised anywhere.

You also have firewalls at each site so are they allowing ICMP through ?

Lets concentrate on one site ie. site C using BGP to site A.

Jon

A comment on another site caused me to look at something on my config. Turns out I needed to advertise the DMZ subnet through the Site A firewall (the device it was directly attached to) instead of having the Site A router advertise the subnet.

Review Cisco Networking for a $25 gift card