11-25-2014 12:30 AM - edited 03-07-2019 09:39 PM
Hi
We have a little Problem with two Switches. The Problem is that we can't connect to these switches via ssh or Network Assistant from the Computer, but it works perfectly from another switch.
VLAN or IP shouldn't be a the problem, because we can connect to the other switches without any problem.
Does anyone have a solution for that Problem?
11-25-2014 12:43 AM
Hi,
What error message do you get when you are trying to connect, also its worth checking your TACACs/RADIUS logs to see why you are being denied access.
11-25-2014 01:33 AM
I think i didn't explain the problem properly.
The Problom is that i can't even ping the switch, so if try to connect via ssh, i get a connection timeout error.
Sorry should have explained that better.
11-25-2014 01:41 AM
Sounds like a routing issue, a tracert to the switch will show where the problem lies ?
11-25-2014 02:37 AM
Hi
A tracert doesnt help much, there is one hop, the core switch, then the nex hop should be the swich but it doesnt reply. All other switches are connected the same way and are also routed via the core switch.
11-25-2014 02:42 AM
Can you post the config of both switch's ?
11-25-2014 03:23 AM
Switch 1
Current configuration : 10428 bytes
!
! Last configuration change at 04:20:41 UTC Mon Mar 29 1993 by cisco
!
version 15.0
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname SWITCH-A316-01
!
boot-start-marker
boot-end-marker
!
enable secret 5
!
username cisco privilege 15 secret 5
no aaa new-model
clock timezone UTC 1 0
clock summer-time UTC recurring last Sun Mar 2:00 last Sun Oct 3:00
system mtu routing 1500
ip domain-name gibwintra.ch
!
!
!
!
crypto pki trustpoint TP-self-signed-3186553600
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-3186553600
revocation-check none
rsakeypair TP-self-signed-3186553600
!
!
crypto pki certificate chain TP-self-signed-3186553600
certificate self-signed 01
30820246 308201AF A0030201 02020101 300D0609 2A864886 F70D0101 04050030
31312F30 2D060355 04031326 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 33313836 35353336 3030301E 170D3933 30333031 30303033
32385A17 0D323030 31303130 30303030 305A3031 312F302D 06035504 03132649
4F532D53 656C662D 5369676E 65642D43 65727469 66696361 74652D33 31383635
35333630 3030819F 300D0609 2A864886 F70D0101 01050003 818D0030 81890281
8100BCFA 8D440D26 1FA33F72 933EEA23 E16878F3 B0D21DC6 ED99519B 57A36C35
4D9F78EE 132996FE C8D7E589 FF41D7D0 2CA75155 DE112E52 1118A336 CD04B876
6EC5AF83 19D87BAE DBAB596C A4204838 8217ED3C 3CEB5805 44BEE55F 7937FD0F
05EFB477 163A744F 19B73A07 05940350 504F5683 BC9F8590
069562F1 350AE342 EF072463 191781FD 6B3B2487 14FE9516 F9247FA2 CBED6ADC
0199E79E 7F12ABA8 1013A657 8C6F7D1D 4DF78370 BFBAA4FD FD19F608 B2E39109
587A92C9 13E65B8B ACBB
quit
!
!
!
port-channel load-balance src-dst-ip
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
vlan dot1q tag native
!
ip ssh time-out 90
ip ssh authentication-retries 2
ip ssh version 2
interface Port-channel1
switchport access vlan 10
switchport trunk encapsulation dot1q
switchport trunk native vlan 10
switchport mode trunk
!
interface GigabitEthernet0/1
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/2
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/3
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/4
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/5
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/6
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/7
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/8
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/9
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/10
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/11
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/12
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/13
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/14
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/15
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/16
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/17
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/18
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/19
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/20
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/21
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/22
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/23
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/24
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/25
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/26
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/27
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/28
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/29
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/30
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/31
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/32
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/33
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/34
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/35
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/36
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/37
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/38
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
interface GigabitEthernet0/39
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/40
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/41
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/42
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/43
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/44
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/45
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/46
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/47
description Extron A413
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/48
description Extron A405
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/49
switchport access vlan 10
switchport trunk native vlan 10
spanning-tree portfast
!
interface GigabitEthernet0/50
switchport access vlan 10
switchport trunk native vlan 10
spanning-tree portfast
!
interface GigabitEthernet0/51
switchport access vlan 10
switchport trunk encapsulation dot1q
switchport trunk native vlan 10
switchport mode trunk
channel-group 1 mode active
!
interface GigabitEthernet0/52
switchport access vlan 10
switchport trunk encapsulation dot1q
switchport trunk native vlan 10
switchport mode trunk
channel-group 1 mode active
!
interface Vlan1
no ip address
no ip route-cache
!
interface Vlan10
ip address 172.30.1.24 255.255.255.0
no ip route-cache
!
interface Vlan20
no ip address
no ip route-cache
!
ip http server
ip http secure-server
!
!
logging esm config
!
!
line con 0
logging synchronous
line vty 0 4
logging synchronous
login local
transport input ssh
line vty 5 15
logging synchronous
login local
transport input ssh
!
end
11-25-2014 03:27 AM
Switch 2
Current configuration : 2425 bytes
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log uptime
no service password-encryption
!
hostname SWITCH-M104-01
!
enable secret 5
enable password
!
no aaa new-model
system mtu routing 1500
ip subnet-zero
ip routing
!
!
!
!
no file verify auto
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
vlan dot1q tag native
!
interface GigabitEthernet0/1
switchport access vlan 15
switchport mode access
!
interface GigabitEthernet0/2
switchport access vlan 20
!
interface GigabitEthernet0/3
switchport access vlan 20
!
interface GigabitEthernet0/4
switchport access vlan 51
!
interface GigabitEthernet0/5
!
interface GigabitEthernet0/6
!
interface GigabitEthernet0/7
switchport access vlan 15
switchport mode access
!
interface GigabitEthernet0/8
!
interface GigabitEthernet0/9
switchport access vlan 20
!
interface GigabitEthernet0/10
!
interface GigabitEthernet0/11
switchport access vlan 30
!
interface GigabitEthernet0/12
!
interface GigabitEthernet0/13
switchport access vlan 50
!
interface GigabitEthernet0/14
!
interface GigabitEthernet0/15
switchport access vlan 20
!
interface GigabitEthernet0/16
!
interface GigabitEthernet0/17
switchport access vlan 20
!
interface GigabitEthernet0/18
switchport access vlan 20
!
interface GigabitEthernet0/19
switchport access vlan 51
!
interface GigabitEthernet0/20
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/21
switchport access vlan 901
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/22
switchport access vlan 10
switchport mode access
!
interface GigabitEthernet0/23
switchport access vlan 15
switchport mode access
!
interface GigabitEthernet0/24
switchport access vlan 901
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/25
description To Rack 3.OG
switchport trunk encapsulation dot1q
switchport mode trunk
!
interface GigabitEthernet0/26
!
interface GigabitEthernet0/27
!
interface GigabitEthernet0/28
!
interface Vlan1
no ip address
shutdown
!
interface Vlan10
ip address 172.30.1.2 255.255.255.0
!
ip default-gateway 172.30.1.1
ip classless
ip http server
!
!
control-plane
!
!
line con 0
line vty 0 4
password
logging synchronous
login
length 0
line vty 5 15
password
logging synchronous
login
!
end
11-25-2014 03:51 AM
Your missing ip default-gateway, the I.P should be in the same network as VLAN10 pointing to your Core switch.
ip default-gateway 172.30.1.?
11-25-2014 04:04 AM
We haven't set the default gateway on the other switches either...
11-25-2014 04:08 AM
yes you have...
Switch 2
interface Vlan10
ip address 172.30.1.2 255.255.255.0
!
ip default-gateway 172.30.1.1
11-25-2014 04:39 AM
Didn't see that, but doesn't matter anyway because Switch 2 doesn't work and we haven't set it on the other switches we are using.
So this can't be causing the problem
11-25-2014 04:50 AM
Switch 2 wont work, its not running SSH.
11-25-2014 05:44 AM
I do not think that we have enough information to know whether the switch is running SSH or not. Just because you do not see SSH commands in running config does not necessarily mean that SSH is not running. If it is running SSH with all default settings then there will not be SSH commands seen in running config.
Both switches have essentially the same problem which is that they do not know how to reach remote subnets, though the details of the problems are different. Switch 1 is configured to operate as a layer 2 switch (there is no ip routing command). As a layer 2 switch it would need a default-gateway command to be able to reach remote subnets. And switch 1 does not have default-gateway. If the original poster configures a correct default-gateway then the switch will be reachable.
Switch 2 is different because switch 2 does have ip routing enabled. This makes it into a layer 3 switch. As a layer 3 switch it does not use the default-gateway that is configured but would need ip route 0.0.0.0 0.0.0.0 (or would need some dynamic routing protocol).
HTH
Rick
11-25-2014 06:04 AM
Hi
Thanks for the help so far.
Yes, on Switch 2 ssh isn't configured, so ssh won't work. But as mentioned the problem isn't only ssh. I can't connect at all: no telnet,no ssh, no CNA and it is not possible to ping the switch.
When directly connectet to VLAN10, there isn't a problem. SSH,Telnet,CNA and ping is working.
And the default gateway isn't set on other switches, wich are working. Because the switch 1 and 2 don't have to route anything. All routing is done on our coreswitch.
I have copied the config of a working switch, hope this helps.
!
! Last configuration change at 01:46:45 UTC Sat Sep 23 1995
!
version 15.0
no service pad
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname SWITCH-A316-02
!
boot-start-marker
boot-end-marker
!
enable secret 5
!
username cisco privilege 15 secret 5
no aaa new-model
clock timezone UTC 1 0
clock summer-time UTC recurring last Sun Mar 2:00 last Sun Oct 3:00
system mtu routing 1500
ip domain-name gibwintra.ch
!
!
!
!
crypto pki trustpoint TP-self-signed-2682990976
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-2682990976
revocation-check none
rsakeypair TP-self-signed-2682990976
!
!
crypto pki certificate chain TP-self-signed-2682990976
certificate self-signed 01 nvram:IOS-Self-Sig#1.cer
!
!
!
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
vlan dot1q tag native
!
ip ssh time-out 90
ip ssh version 2
!
!
!
!
!
interface GigabitEthernet0/1
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/2
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/3
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/4
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/5
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/6
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/7
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/8
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/9
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/10
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/11
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/12
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/13
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/14
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet0/15
description Embed PC 4.Stock
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/16
description Embed PC 4.Stock
switchport access vlan 260
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/17
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/18
switchport access vlan 231
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/19
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/20
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/21
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/22
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/23
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/24
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/25
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/26
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/27
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/28
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/29
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/30
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/31
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/32
switchport access vlan 20
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/33
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/34
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/35
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/36
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/37
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/38
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/39
switchport access vlan 10
switchport trunk encapsulation dot1q
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/40
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/41
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/42
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/43
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/44
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/45
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/46
switchport access vlan 10
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/47
switchport access vlan 900
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/48
switchport access vlan 900
switchport trunk native vlan 10
switchport mode access
!
interface GigabitEthernet0/49
switchport access vlan 10
switchport trunk native vlan 10
!
interface GigabitEthernet0/50
switchport access vlan 10
switchport trunk native vlan 10
!
interface GigabitEthernet0/51
switchport access vlan 10
switchport trunk native vlan 10
!
interface GigabitEthernet0/52
switchport access vlan 10
switchport trunk encapsulation dot1q
switchport trunk native vlan 10
switchport mode trunk
!
interface Vlan1
no ip address
!
interface Vlan10
ip address 172.30.1.25 255.255.255.0
!
ip http server
ip http secure-server
!
!
logging esm config
!
!
line con 0
line vty 0 4
logging synchronous
login local
transport input ssh
line vty 5 15
logging synchronous
login local
transport input ssh
!
end
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide