12-13-2019 05:06 PM
I use two L3 switches for connecting two sites on MPLS. Each switch has a GE port configured as routed interface connecting to a CE from the provider. OSPF routing appears to be working. Endpoint computers of one location can see those of the other. We can even transfer files from one computer to another over the MPLS circuit.
From the console port of the 3750 switch in Site 1 , I am able to ping the VLAN1 interface of the switch in Site 2. However, I cannot ping any endpoint computers there unless I use the extended PING command and specify the VLAN1 interface IP of the 3750 as source. What puzzles me more is that the 3650 switch in Site 2 does not have this problem. I am able to ping any computers in Site 1 over the WAN link with no issues.
Do I make any mistakes in the configuration? Is there any way to avoid the use of extended ping on the Cisco 3750?
Here is the config for each:
Site 1 - Cisco 3750 Switch
! ip routing ! interface Loopback0 ip address 1.1.1.1 255.255.255.255 ! interface GigabitEthernet1/0/2 no switchport ip address 10.10.100.106 255.255.255.252 ! interface Vlan1 ip address 172.20.5.1 255.255.255.0 ! router ospf 1 log-adjacency-changes network 1.1.1.1 0.0.0.0 area 0 network 10.10.100.104 0.0.0.3 area 0 network 172.20.5.0 0.0.0.255 area 0 ! ip classless ! |
Site 2 - Cisco 3650 Switch
! |
Solved! Go to Solution.
12-14-2019 10:55 AM
Hello,
for the sake of verification I checked what the default is for older IOS versions such as the one you are running, but even with a 12.x version, the default still is that a PING is sourced from the outgoing interface. You could actually check with your ISP to find out if they block ICMP traffic on their equipment.
12-14-2019 11:32 AM
in that case worth check with MPLS provider have any block route available with your point to point interface..looks something missing at PE / P end.
12-14-2019 01:04 AM
Can you post full configuration and show ip route output ? from 3750 ?
12-14-2019 02:53 AM
See below for the full config and sh ip route results.
Site 1 - Config
Using 1642 out of 524288 bytes
|
Site 2 - Config
Using 4349 out of 2097152 bytes |
Site1 - Show IP Route
Gateway of last resort is not set 1.0.0.0/32 is subnetted, 1 subnets |
Site2 - Show IP Route
Gateway of last resort is not set 1.0.0.0/32 is subnetted, 1 subnets |
12-14-2019 03:20 AM
I did a show ip route [target] to find out the outgoing interface. It was defaulted to the routed interface connected to the CE router. To be able to ping the target, I had to specify the VLAN1 as the source IP on 3750. The 3650 switch in Site 2 also uses the same outgoing interface but there is no need to use extended PING.
========================
Site1#sh ip route 172.20.2.14
========================
Routing entry for 172.20.2.0/24
Known via "ospf 1", distance 110, metric 1
Tag 65500, type extern 2, forward metric 1
Last update from 10.10.100.105 on GigabitEthernet1/0/2, 14:13:46 ago
Routing Descriptor Blocks:
* 10.10.100.105, from 10.10.100.105, 14:13:46 ago, via GigabitEthernet1/0/2
Route metric is 1, traffic share count is 1
Route tag 65500
=============================
Site1#ping 172.20.2.14 source vlan1
=============================
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 172.20.2.14, timeout is 2 seconds:
Packet sent with a source address of 172.20.5.1
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 50/52/58 ms
12-14-2019 02:55 AM
Hello,
make sure that the fact that both WAN interfaces in what you have posted have the same IP address is not a typo. Other than that, the only real reason I can see for the PING to be dropped is when it gets dropped by an intermediate MPLS router...
S1
interface GigabitEthernet1/0/2
no switchport
ip address 10.10.100.106 255.255.255.252
S2
interface GigabitEthernet1/0/2
no switchport
ip address 10.10.200.106 255.255.255.252
12-14-2019 03:05 AM
@Georg Pauwen i may be missed here ...but the 3rd octet is different right ? one is 100 and another one 200.
i only see the difference on your config route (which was working without extended ping was - ip route 0.0.0.0 0.0.0.0 172.20.2.1)
The other one working with extended ping don't have a route in place..not sure how your network connection. ?
12-14-2019 03:15 AM - edited 12-14-2019 03:20 AM
Hello,
good catch Balaji...
When I look at the routing tables. I don't see an L route for S1:
L 10.10.100.106/32 is directly connected, GigabitEthernet1/0/2 --> not there
This should be there as for S2:
L 10.10.200.106/32 is directly connected, GigabitEthernet1/0/2
It looks like you are running a very old IOS version on S1. Try and see if you can configure 'ip cef' globally on S1.
12-14-2019 10:37 AM
Yes, the IOS on switch1 is quite old. This switch is just used for testing. I am going to copy the config to a newer switch when go-live.
12-14-2019 10:35 AM
>>ip route 0.0.0.0 0.0.0.0 172.20.2.1
I have had a default route on these 2 switches before but later removed them for trouble-shooting. It did not make any difference whether this static router was there or not.
I guess one of the MPLS router might have blocked it then.
12-14-2019 10:55 AM
Hello,
for the sake of verification I checked what the default is for older IOS versions such as the one you are running, but even with a 12.x version, the default still is that a PING is sourced from the outgoing interface. You could actually check with your ISP to find out if they block ICMP traffic on their equipment.
12-14-2019 11:32 AM
in that case worth check with MPLS provider have any block route available with your point to point interface..looks something missing at PE / P end.
12-15-2019 03:46 AM
I will definitely raise the question with my provider. Other than the nuisance of having to specify the source IP when PINGing site2 from the site1 switch, there is no connectivity or routing issues. Therefore, I have switched over to the new circuit yesterday and completed testing with endpoint devices. Everything worked as expected.
Thanks to everyone for your insight. That eased my concern.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide