01-25-2025 04:29 PM
Hey,
I am currently working on a ccna prep lab which is supposed to be on ACLs.
But I am having errors setting up the basic topology.
I have redone the lab from scratch several times now, and I cannot determine the main issue; which is PC-B cannot connect to anything. Everything else has total inter-connectivity.
Something that may be helpful:
PC-B in VLAN 40, connected to Switch 2, I notice that the vlan is down. But the port is up (pc -> sw2). If I turn the vlan 'on', no difference. When I shut it back down, move the PC-B port to another sw2 port, enable the port, and assign to vlan40, still nothing. Which from my understanding the vlan should come up if there is a device plugged in. I try anyway to manually bring the vlan40 up, but still nothing in or out of PC-B.
I have checked all interface ports, VLANs, changed the VLANs allowed on trunks. Nada.
Any assistance, and troubleshooting advice would be greatly appreciated.
Thanks,
Mitch
My Topology:
SW1 Running-Conif:
S1#sh running-config
Building configuration...
Current configuration : 2982 bytes
!
version 15.0
no service timestamps log datetime msec
no service timestamps debug datetime msec
service password-encryption
!
hostname S1
!
enable secret 5 $1$mERr$9cTjUIEqNGurQiFU.ZeCi1
!
!
!
no ip domain-lookup
!
!
!
spanning-tree mode pvst
spanning-tree extend system-id
!
interface FastEthernet0/1
switchport trunk native vlan 1000
switchport mode trunk
!
interface FastEthernet0/2
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/3
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/4
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/5
switchport trunk native vlan 1000
switchport mode trunk
!
interface FastEthernet0/6
switchport access vlan 30
switchport mode access
!
interface FastEthernet0/7
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/8
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/9
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/10
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/11
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/12
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/13
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/14
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/15
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/16
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/17
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/18
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/19
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/20
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/21
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/22
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/23
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/24
switchport access vlan 999
switchport mode access
shutdown
!
interface GigabitEthernet0/1
switchport access vlan 999
switchport mode access
shutdown
!
interface GigabitEthernet0/2
switchport access vlan 999
switchport mode access
shutdown
!
interface Vlan1
no ip address
shutdown
!
interface Vlan20
ip address 10.20.0.2 255.255.255.0
!
ip default-gateway 10.20.0.1
!
banner motd ^CUnauthorized access is prohibited!!^C
!
!
!
line con 0
password 7 0822455D0A16451B1D0C050A
!
line vty 0 4
password 7 0822455D0A16451B1D0C050A
login
line vty 5 15
password 7 0822455D0A16451B1D0C050A
login
!
!
!
!
end
S1#
SWITCH 2 Running Config:
S2#sh running-config
Building configuration...
Current configuration : 2975 bytes
!
version 15.0
no service timestamps log datetime msec
no service timestamps debug datetime msec
service password-encryption
!
hostname S2
!
enable secret 5 $1$mERr$9cTjUIEqNGurQiFU.ZeCi1
!
!
!
no ip domain-lookup
!
!
!
spanning-tree mode pvst
spanning-tree extend system-id
!
interface FastEthernet0/1
switchport trunk native vlan 1000
switchport mode trunk
!
interface FastEthernet0/2
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/3
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/4
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/5
switchport access vlan 20
switchport mode access
!
interface FastEthernet0/6
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/7
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/8
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/9
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/10
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/11
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/12
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/13
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/14
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/15
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/16
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/17
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/18
switchport access vlan 40
switchport mode access
!
interface FastEthernet0/19
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/20
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/21
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/22
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/23
switchport access vlan 999
switchport mode access
shutdown
!
interface FastEthernet0/24
switchport access vlan 999
switchport mode access
shutdown
!
interface GigabitEthernet0/1
switchport access vlan 999
switchport mode access
shutdown
!
interface GigabitEthernet0/2
switchport access vlan 999
switchport mode access
shutdown
!
interface Vlan1
no ip address
shutdown
!
interface Vlan20
ip address 10.20.0.3 255.255.255.0
!
ip default-gateway 10.20.0.1
!
banner motd ^CUnauthorized access is prohibited!!^C
!
!
!
line con 0
password 7 0822455D0A16451B1D0C050A
!
line vty 0 4
password 7 0822455D0A16451B1D0C050A
login
line vty 5 15
password 7 0822455D0A16451B1D0C050A
login
!
!
!
!
end
S2#
Solved! Go to Solution.
01-25-2025 05:54 PM - edited 01-25-2025 06:16 PM
Switch 2 will not ping PC2 as It doesnt have IP address on vlan 40. It Will ping host on vlan 20.
If PC2 is able to ping 10.40.0.1 but nothing else, then the PC2 does not have default-gateway configured.
If PC2 can not ping 10.40.0.1, you may have layer2 problem and traffic is not making It from switch 2 to router
01-25-2025 04:45 PM
Because R1 is doing the inter-vlan routing, vlan 40 must reach the R1. From the config of switch1 it appears that vlan 40 is not defined on switch1.
Configure it on switch1 with the following commands:
conf t
vlan 40
You should have connectivity after that if R1 is configured correctly.
HTH
01-25-2025 05:26 PM
Thanks for your feedback.
Did not work.
So maybe I did configure the R1 incorrectly then.
Wouldn't I be able to ping from S2 -> PC-B even if the R1 was incorrectly configured?
Anything look wrong in my config commands?
Activate interface G0/0/1:
int g0/0/1
no shut
Config sub-interfaces as per table:
int g0/0/1.20
no shut
encapsulation dot1q 20
ip address 10.20.0.1 255.255.255.0
int g0/0/1.30
no shut
encapsulation dot1q 30
ip address 10.30.0.1 255.255.255.0
int g0/0/1.40
no shut
encapsulation dot1q 40
ip address 10.40.0.1 255.255.255.0
int g0/0/1.1000
no shut
encapsulation dot1q 1000
Configure Loopback1 as per table:
int Loopback1
no shut
ip address 172.16.1.1 255.255.255.0
01-25-2025 05:54 PM - edited 01-25-2025 06:16 PM
Switch 2 will not ping PC2 as It doesnt have IP address on vlan 40. It Will ping host on vlan 20.
If PC2 is able to ping 10.40.0.1 but nothing else, then the PC2 does not have default-gateway configured.
If PC2 can not ping 10.40.0.1, you may have layer2 problem and traffic is not making It from switch 2 to router
01-25-2025 06:20 PM
@Flavio MirandaThanks for taking the time, appreciate it.
I added another device and attached it to the other vlans connected to Switch2, and they worked.
That narrowed it down to do vlan 40, f0/18, and as per @liviu.gheorghe suggest: R1's g0/0/1.40
Ashamed to say, that it would appear that the issue was that PC2's IP was set to 10.40.0.1 and not 10.40.0.10
I've spent way more time than I would like to admit over the past couple days working on this. Good re-fresher I guess.
Thanks again.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide