cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1341
Views
0
Helpful
14
Replies

Core switch VLAN Migration

dazza007
Level 1
Level 1

I have 2 4900Ms, Cisco 1 - trunked to a new Juniper EX4600 and am testing a migration strategy. 

I setup IRBs with IP address on the Junos and trunked to the Cisco - works perfectly!  (IRB's are junos equivalent of interface vlan )

The migration test was to test the transfer, shutdown L3 VLAN on CISCO pair and change IP address on Junos Irb to that what was CISCO standby IP with the equivalent of dhcp relay set on junos

I get a loop...

Firewall > Core 2 > native vlan core 2 > Firewall 

The routing happens on a firewall, routes on the 2 cisco cores are C1 0.0.0.0/0 go to firewall C2 0.0.0.0/0 go to C1 

The l3 vlan is not showing - sh ip route - adding the route manually does nothing. Removed and readded nothing happening no error logs. The migrated VLAN is however under the 172.22.0.0 range that is variably subnetted is this the reason why? I can see that migrated vlan is up with show vlans - Is this the L2 vlan that is still purposely active?

I thought adding a static route would enable the migrated vlan to be routed, very confused! 

Help is very much appreciated

 

 

 

 

 

 

 

14 Replies 14

Hi

 when you say "shutdown L3 VLAN on CISCO "  you really mean shutdowm?  You got into the vlan and run shutdown? 

 If you did, I'd say you did it wrong. If you are migrating the Vlan from Cisco Core to Juniper Core, you can leave the Vlan as layer2 on Cisco and transfer the IP addressing to  Juniper.  Cisco's Cores will act like an access switch for this vlan. 

conf t

interface vlan number 

shutdown 

 

Is that correct?

Yes, this is how you shutdown the vlan but I dont believe you need to do that. Just remove the IP address

interface vlan number

 no ip add 

That's it. If you do shutdown, you are admin disabling the vlan and it will be a useless vlan. 

Thank you, your help is much appreciated, your advice is invaluable!

I think i have figured it out, all I needed to do was swap IP addresses! 

If I shutdown the vlan as you said it is wrong. 

If I put no ip address the vlan is showing but no traffic can flow as their is no route added. but vlan is up. I added a manual route but there was still a loop between the firewall and the second core.

If I just add a random ip address in the range then vlan range, then vlan routing occurs from laptop (access vlan) > juniper >cisco

 

 

 

Thank you, your help is invaluable!

I tried no ip address on the migrated vlan and the vlan appeared in routes but there was no routing (traffic from juniper>core) and I got a route loop again. 

I added a different ip address in the vlan range to the migrated vlan on the cisco and routing resolved. 

I think that the firewall needs its gateway changing  on the migrated vlan changing as without the ip address on the cisco a loop occurs to the second cisco core. (the gateway ip address of the all the vlan routes on the firewall are all the same - an ip address in the firewall vlan - it was inherited and never understood or could find any documentation)

 

dazza007
Level 1
Level 1

Posted this 3 times and vanished ignore test 

dazza007
Level 1
Level 1

Thanks your advice is invaluable

I setup the migrated vlan with no ip address and the vlan appeared in sh ip route but there was no routing. I manually added the route and still nothing, the loop persisted.

I then added an different Ip address back in the migrated vlan range and routing resolved (+sh arp vlan shows ip addresses)

The routing is on the firewall and it has all its' vlans setup with the same gateway address as an ip in the IP vlan of the firewall. I inherited this and never understood or could find docs why this is so. If shutting down L3 routing on the cisco vlan is having no op address then tech support is needed for the firewall. I can't figure out without a route on the cisco the traffic gets dropped off on the second core. 

Thanks again.

dazza007
Level 1
Level 1

test reply 5 times post vanished...

 

dazza007
Level 1
Level 1

Test reply number 7 - please ignore

dazza007
Level 1
Level 1

test please ignore - posts not appearing

dazza007
Level 1
Level 1

Test post number 8 please ignore

 

No I see your post, it OK.
so finally your issue solve with assign different IP. 
thanks for update us 
have a nice day 
MHM

Thanks, all my posts came through at once apologies. 

So to close L3 on the old switch what is the correct procedure? 

dazza007
Level 1
Level 1

https://community.cisco.com/t5/switching/shut-down-vlan-and-interface-vlan-shutdown/td-p/1945949

I have found where I got the original information from. the post states

conf t

vlan 123

shut

This changes L3 to L2?

 

Review Cisco Networking for a $25 gift card