cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
403
Views
1
Helpful
10
Replies

Cisco 3750 Switch not forwarding mac address learnt from Firewall

HTD
Level 1
Level 1

Hello, I have a Cisco 3750 switch which is connected to a Juniper Firewall on an access port, the switch can learn mac address from the Firewall. The switch uplink is a Cisco 6504 router. The 6504 router cannot learn the mac address of the firewall connected to the switch even though the vlan is passed on the connection between the router and switch. 

 

I have been troubleshooting this with no headway, any assistance will be appreciated

1 Accepted Solution

Accepted Solutions

HTD
Level 1
Level 1

Thank you all for your input, the issue is resolved, it was from the firewall. The mastership had moved to the secondary which was not connected to the 3750, hence arp was not successful. I changed the mastership to the primary and it got resolved.

View solution in original post

10 Replies 10

can you ping from FW to any IP in C6000 ?

MHM

The FW is currently unreachable, there is actually a point to point IP between Firewall and C6000, the point to point is unreachable, hence I cannot access the FW

balaji.bandi
Hall of Fame
Hall of Fame
Cisco 3750 switch which is connected to a Juniper Firewall on an access port, the switch can learn mac address from the Firewall. 

in this case the switch port up that connected to Firewall, so Switch learning MAC address, what VLAN is that ?

The switch uplink is a Cisco 6504 router.

how is the configuration looks like between (6504 - Router or switch ?) 6K to 3750 share the configuration here to understand

 The 6504 router cannot learn the mac address of the firewall connected to the switch even though the vlan is passed on the connection between the router and switch. 

can we know the VLAN and configuration asked above.

Do you learn any other MAC address from 3750 to 65XX ?

The FW is currently unreachable, there is actually a point to point IP between Firewall and C6000, the point to point is unreachable, hence I cannot access the FW

firewall not reachable, but its powered on right ?

P2P - Do you have any other connection or all go via 3750 Switch here ?

is P2P IP via VLAN SVI ? or Layer 3 Physical interface connection ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

in this case the switch port up that connected to Firewall, so Switch learning MAC address, what VLAN is that ? Vlan 865

 

how is the configuration looks like between (6504 - Router or switch ?) 6K to 3750 share the configuration here to understand

configuration is trunk between the the router and switch, passing multiple Vlans

Do you learn any other MAC address from 3750 to 65XX ? Yes, other mac address for different vlans from 3750 is learnt on 65xx

firewall not reachable, but its powered on right ? Yes, it is powered on , cable connection between firewall and switch is up

P2P - Do you have any other connection or all go via 3750 Switch here ? No, only one, from firewall to 3750

is P2P IP via VLAN SVI ? or Layer 3 Physical interface connection ? P2P on 65xx is vlan SVI, I actually created SVI on 3750 to test for the vlan and I could ping IP on 65xx .

 

 

 

 

 

 

P2P on 65xx is vlan SVI, I actually created SVI on 3750 to test for the vlan and I could ping IP on 65xx .

you created SVI on switch and then you able to ping SVI of 6500, then you should see arp table of Firewall also in the switch since it got ip in that switch.

firewall may be not pinging due to ACL ?

try from firewall to 3750 Switch IP you configured ?

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Would you post the configuration of 3750? Also the output of theses commands:

show cdp neighbor

show interface trunk

HTH

Rick

Can you draw topolgy 

MHM

HTD
Level 1
Level 1

Thank you all for your input, the issue is resolved, it was from the firewall. The mastership had moved to the secondary which was not connected to the 3750, hence arp was not successful. I changed the mastership to the primary and it got resolved.

Sure we assumed same as i was mentioned when you able to reach all devices, and you see the MAC then i suspect configuration issue, any way glad all good.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Thanks for the update. Glad that you have solved the issue.

HTH

Rick
Review Cisco Networking for a $25 gift card