Hi Experts,
this is my first post here. I've a small network with a Cisco 3650 as router that has a very strange behaviour, it suddently stop to ping to be back after a minute or so.
Let me give more details, the attached file show the network that I have (firewall is actually completely open for some IP addresses), using a machine located in the FTE network I start 3 Windows Command Prompt to ping three different interfaces of the router. Those are:
1) 10.1.2.51 that is the IP address of the router port that connects to the FTE
2) 10.35.1.1 that is the IP address of the router port that connects to the firewall
3) 172.21.1.4 that is a laptop connected behind the firewall.
I can ping all three IP addresses, but after some time the number 2 and 3 stops while 1 continue to get answers. So isn't a matter of hardware, because the router itself (and the cables connecting to it) are working since I'm always getting a reply from 10.1.2.51.
The 10.35.1.1 is on the router itself but it stops to recover back after some time (1-2 minutes) and both 2 and 3 stops and recover at same time.
Any suggestion?
Here below the configuration of my router:
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log uptime
service password-encryption
!
hostname CRL3R01A
!
boot-start-marker
boot-end-marker
!
enable secret 5 $1$g2tb$lTpI2Sb8bBEFxo7YZHGae0
enable password 7 020E0B550E1F18244042
!
no aaa new-model
system mtu routing 1500
vtp mode transparent
!
ip subnet-zero
ip routing
!
!
spanning-tree mode mst
spanning-tree etherchannel guard misconfig
spanning-tree extend system-id
!
spanning-tree mst configuration
name Staatsolie
revision 1
instance 1 vlan 1
instance 2 vlan 101
!
! This configuration use following VLANs
!
! Number Description
! 101 FTE Network on Fa0/1
! 301 Routers port in switching mode Fa0/11 to Fa0/23
! 302 Not used
! 303 Not used
! 304 Routing interface on Fa0/4
! 305 Routing interface on Fa0/5
! 306 Routing interface on Fa0/6
! 307 Not used
! 308 Routing interface on Fa0/8
! 309 Routing interface on Fa0/9
! 310 Routing interface on Fa0/10
!
!
!
spanning-tree mst 0-2 priority 24576
!
vlan internal allocation policy ascending
!
!
interface FastEthernet0/1
description FTE Link
no switchport
ip address 10.1.2.51 255.255.248.0
no ip redirects
no ip unreachables
standby 2 ip 10.1.0.1
standby 2 timers 1 3
standby 2 preempt
standby 2 track FastEthernet0/24
!
interface FastEthernet0/2
description Connection to Firewall 3.5
no switchport
ip address 10.35.1.7 255.255.255.0
! ip access-group 115 in
no ip redirects
no ip unreachables
standby 3 ip 10.35.1.1
standby 3 timers 1 3
standby 3 preempt
standby 3 track FastEthernet0/24
!
interface FastEthernet0/3
description OPC Skema Link
no switchport
ip address 10.9.1.7 255.255.255.0
! ip access-group 111 in
no ip redirects
no ip unreachables
standby 4 ip 10.9.1.1
standby 4 timers 1 3
standby 4 preempt
standby 4 track FastEthernet0/24
!
interface FastEthernet0/4
switchport access vlan 304
switchport mode access
!
interface FastEthernet0/5
switchport access vlan 305
switchport mode access
!
interface FastEthernet0/6
switchport access vlan 306
switchport mode access
!
interface FastEthernet0/7
description Remote Service Link
no switchport
ip address 10.10.1.7 255.255.255.0
! ip access-group 114 in
! ip access-group 113 in
no ip redirects
no ip unreachables
standby 5 ip 10.10.1.1
standby 5 timers 1 3
standby 5 preempt
standby 5 track FastEthernet0/24
!
interface FastEthernet0/8
switchport access vlan 308
switchport mode access
!
interface FastEthernet0/9
switchport access vlan 309
switchport mode access
!
interface FastEthernet0/10
switchport access vlan 310
switchport mode access
!
interface FastEthernet0/11
switchport access vlan 301
switchport mode access
!
interface FastEthernet0/12
switchport access vlan 301
switchport mode access
!
interface FastEthernet0/13
switchport access vlan 301
switchport mode access
!
interface FastEthernet0/14
switchport access vlan 301
switchport mode access
!
interface FastEthernet0/15
switchport access vlan 301
switchport mode access
!
interface FastEthernet0/16
switchport access vlan 301
switchport mode access
!
interface FastEthernet0/17
switchport access vlan 301
switchport mode access
!
interface FastEthernet0/18
switchport access vlan 301
switchport mode access
!
interface FastEthernet0/19
switchport access vlan 301
switchport mode access
!
interface FastEthernet0/20
switchport access vlan 301
switchport mode access
!
interface FastEthernet0/21
switchport access vlan 301
switchport mode access
!
interface FastEthernet0/22
switchport access vlan 301
switchport mode access
!
interface FastEthernet0/23
switchport access vlan 301
switchport mode access
!
interface FastEthernet0/24
description HSRP_Crosslink
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 301-310
switchport mode trunk
!
interface GigabitEthernet0/1
shutdown
!
interface GigabitEthernet0/2
shutdown
!
interface Vlan1
no ip address
shutdown
!
interface Vlan301
ip address 10.7.1.7 255.255.255.0
standby 1 ip 10.7.1.1
standby 1 timers 1 3
standby 1 preempt
!
interface Vlan302
no ip address
shutdown
!
interface Vlan303
no ip address
shutdown
!
interface Vlan304
no ip address
shutdown
!
!
interface Vlan305
no ip address
shutdown
!
!
interface Vlan306
no ip address
shutdown
!
!
interface Vlan307
no ip address
shutdown
!
!
interface Vlan308
no ip address
shutdown
!
!
interface Vlan309
no ip address
shutdown
!
!
interface Vlan310
no ip address
shutdown
!
ip classless
no ip http server
!
logging trap notifications
!
! Route paths
ip route 172.21.1.0 255.255.255.192 10.35.1.9 permanent
ip route 10.11.1.0 255.255.255.0 10.35.1.9 permanent
!
! Access List for OPC Skema Devices
!access-list 111 permit ip host 10.9.1.11 host 10.1.0.11
!access-list 111 permit ip host 10.9.1.12 host 10.1.0.11
!access-list 111 permit ip host 10.9.1.13 host 10.1.0.11
!access-list 111 permit ip host 10.9.1.14 host 10.1.0.11
!access-list 111 permit ip host 10.9.1.11 host 10.1.0.13
!access-list 111 permit ip host 10.9.1.12 host 10.1.0.13
!access-list 111 permit ip host 10.9.1.13 host 10.1.0.13
!access-list 111 permit ip host 10.9.1.14 host 10.1.0.13
!access-list 111 permit ip host 10.9.1.11 host 10.1.0.61
!access-list 111 permit ip host 10.9.1.12 host 10.1.0.61
!access-list 111 permit ip host 10.9.1.13 host 10.1.0.61
!access-list 111 permit ip host 10.9.1.14 host 10.1.0.61
!access-list 111 permit ip host 10.9.1.11 host 10.9.1.7
!access-list 111 permit ip host 10.9.1.12 host 10.9.1.7
!access-list 111 permit ip host 10.9.1.13 host 10.9.1.7
!access-list 111 permit ip host 10.9.1.14 host 10.9.1.7
!access-list 111 permit ip host 10.9.1.11 host 10.9.1.8
!access-list 111 permit ip host 10.9.1.12 host 10.9.1.8
!access-list 111 permit ip host 10.9.1.13 host 10.9.1.8
!access-list 111 permit ip host 10.9.1.14 host 10.9.1.8
!access-list 111 permit ip host 10.9.1.11 host 10.9.1.1
!access-list 111 permit ip host 10.9.1.12 host 10.9.1.1
!access-list 111 permit ip host 10.9.1.13 host 10.9.1.1
!access-list 111 permit ip host 10.9.1.14 host 10.9.1.1
!access-list 111 deny ip any any
!
! Access List for OPC Skema Devices
!access-list 112 permit ip host 10.1.0.11 host 10.9.1.11
!access-list 112 permit ip host 10.1.0.11 host 10.9.1.12
!access-list 112 permit ip host 10.1.0.11 host 10.9.1.13
!access-list 112 permit ip host 10.1.0.11 host 10.9.1.14
!access-list 112 permit ip host 10.1.0.13 host 10.9.1.11
!access-list 112 permit ip host 10.1.0.13 host 10.9.1.12
!access-list 112 permit ip host 10.1.0.13 host 10.9.1.13
!access-list 112 permit ip host 10.1.0.13 host 10.9.1.14
!access-list 112 permit ip host 10.1.0.61 host 10.9.1.11
!access-list 112 permit ip host 10.1.0.61 host 10.9.1.12
!access-list 112 permit ip host 10.1.0.61 host 10.9.1.13
!access-list 112 permit ip host 10.1.0.61 host 10.9.1.14
!access-list 112 permit ip host 10.9.1.7 host 10.9.1.11
!access-list 112 permit ip host 10.9.1.7 host 10.9.1.12
!access-list 112 permit ip host 10.9.1.7 host 10.9.1.13
!access-list 112 permit ip host 10.9.1.7 host 10.9.1.14
!access-list 112 permit ip host 10.9.1.8 host 10.9.1.11
!access-list 112 permit ip host 10.9.1.8 host 10.9.1.12
!access-list 112 permit ip host 10.9.1.8 host 10.9.1.13
!access-list 112 permit ip host 10.9.1.8 host 10.9.1.14
!access-list 112 permit ip host 10.9.1.1 host 10.9.1.11
!access-list 112 permit ip host 10.9.1.1 host 10.9.1.12
!access-list 112 permit ip host 10.9.1.1 host 10.9.1.13
!access-list 112 permit ip host 10.9.1.1 host 10.9.1.14
!access-list 112 deny ip any any
!
! Access List for L3 Switched devices
!access-list 113 permit ip 10.7.1.0 0.0.0.255 10.1.0.0 0.0.0.255
!access-list 113 permit ip 10.1.0.0 0.0.0.255 10.7.1.0 0.0.0.255
!access-list 113 deny ip any any
!
! Access List for Remote Support L3
!access-list 114 permit ip 10.10.1.0 0.0.0.255 10.1.0.0 0.0.0.255
!access-list 114 permit ip 10.1.0.0 0.0.0.255 10.10.1.0 0.0.0.255
!access-list 114 deny ip any any
!
! Access List for MES/PHD devices
!access-list 115 permit ip host 172.21.1.6 host 10.1.0.71
!access-list 115 permit ip host 172.21.1.4 host 10.1.0.11
!access-list 115 permit ip host 172.21.1.4 host 10.1.0.13
!access-list 115 permit ip host 172.21.1.4 host 10.1.0.61
!access-list 115 permit ip host 172.21.1.3 host 10.7.1.91
!access-list 115 permit ip host 10.1.0.71 host 172.21.1.6
!access-list 115 permit ip host 10.1.0.11 host 172.21.1.4
!access-list 115 permit ip host 10.1.0.13 host 172.21.1.4
!access-list 115 permit ip host 10.1.0.61 host 172.21.1.4
!access-list 115 permit ip host 10.7.1.91 host 172.21.1.3
!access-list 115 deny ip any any
!
!
!
snmp-server community public RO
snmp-server location CR Network Cabinet
snmp-server enable traps snmp linkdown linkup coldstart warmstart
snmp-server host 10.1.0.11 SURFTE snmp
!
control-plane
!
!
line con 0
line vty 0 4
password 7 082943400C0012121E075D
login
line vty 5 15
login
!
end