cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2161
Views
0
Helpful
21
Replies

Ping across VLAN's

Andrew D
Level 1
Level 1

I'm having problems pinging across VLAN's on my stacked switches. Any help would be appreciated.

!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log datetime localtime
service password-encryption
service sequence-numbers
!
!
no aaa new-model
clock timezone EST -5
clock summer-time EST recurring
switch 1 provision ws-c3750g-24t
switch 3 provision ws-c3750g-24t
system mtu routing 1500
ip routing
!
!
!
!
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
!
!
interface GigabitEthernet1/0/1
 description SAN
 switchport access vlan 102
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet1/0/2
 description SAN
 switchport access vlan 102
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet1/0/3
 description SAN
 switchport access vlan 102
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet1/0/4
 description SAN
 switchport access vlan 102
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet1/0/5
 description iSCSI
 switchport access vlan 102
 switchport mode access
!
interface GigabitEthernet1/0/6
 description iSCSI
 switchport access vlan 102
 switchport mode access
!
interface GigabitEthernet1/0/7
 description iSCSI
 switchport access vlan 100
 switchport mode access
!
interface GigabitEthernet1/0/8
 description iSCSI
 switchport access vlan 102
 switchport mode access
!
interface GigabitEthernet1/0/9
 description LAN
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 100,102,103
 switchport mode trunk
!
interface GigabitEthernet1/0/10
 description LAN
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 100,102,103
 switchport mode trunk
!
interface GigabitEthernet1/0/11
!
interface GigabitEthernet1/0/12
!
interface GigabitEthernet1/0/13
 description esxi1 - mgmt
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 100,102,103
 switchport mode trunk
!
interface GigabitEthernet1/0/14
 description esxi1 - vmotion
 switchport access vlan 101
 switchport mode access
!
interface GigabitEthernet1/0/15
 description esxi1 - iDrac
 switchport access vlan 103
 switchport mode access
!
interface GigabitEthernet1/0/16
 description esxi3 - mgmt
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 100,102,103
 switchport mode trunk
!
interface GigabitEthernet1/0/17
 description LAN
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 100,102,103
 switchport mode trunk
!
interface GigabitEthernet1/0/18
!
interface GigabitEthernet1/0/19
 description esxi3 - iDrac
 switchport access vlan 103
 switchport mode access
!
interface GigabitEthernet1/0/20
!
interface GigabitEthernet1/0/21
 description Laptop - Mgmt
 switchport access vlan 103
!
interface GigabitEthernet1/0/22
!
interface GigabitEthernet1/0/23
 description esxi - uplink
 switchport access vlan 999
 switchport mode access
!
interface GigabitEthernet1/0/24
 description Primary Uplink
 switchport access vlan 999
 switchport mode access
!
interface GigabitEthernet3/0/1
 description SAN
 switchport access vlan 102
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet3/0/2
 description SAN
 switchport access vlan 102
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet3/0/3
 description SAN
 switchport access vlan 102
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet3/0/4
 description SAN
 switchport access vlan 102
 switchport mode access
 spanning-tree portfast
!
interface GigabitEthernet3/0/5
 description iSCSI
 switchport access vlan 102
 switchport mode access
!
interface GigabitEthernet3/0/6
 description iSCSI
 switchport access vlan 102
 switchport mode access
!
interface GigabitEthernet3/0/7
 description iSCSI
 switchport access vlan 100
 switchport mode access
!
interface GigabitEthernet3/0/8
 description iSCSI
 switchport access vlan 102
 switchport mode access
!
interface GigabitEthernet3/0/9
 description LAN
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 100,102,103
 switchport mode trunk
!
interface GigabitEthernet3/0/10
 description LAN
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 100,102,103
 switchport mode trunk
!
interface GigabitEthernet3/0/11
!
interface GigabitEthernet3/0/12
!
interface GigabitEthernet3/0/13
 description esxi2 - mgmt
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 100,102,103
 switchport mode trunk
!
interface GigabitEthernet3/0/14
 description esxi2 - vmotion
 switchport access vlan 101
 switchport mode access
!
interface GigabitEthernet3/0/15
 description esxi2 - iDrac
 switchport access vlan 103
 switchport mode access
!
interface GigabitEthernet3/0/16
!
interface GigabitEthernet3/0/17
!
interface GigabitEthernet3/0/18
!
interface GigabitEthernet3/0/19
!
interface GigabitEthernet3/0/20
!
interface GigabitEthernet3/0/21
 description esxi - Uplink
 switchport access vlan 999
 switchport mode access
!
interface GigabitEthernet3/0/22
 description Laptop - Prod
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 100,102,103
 switchport mode trunk
!
interface GigabitEthernet3/0/23
 description esxi - Uplink
 switchport access vlan 999
 switchport mode access
!
interface GigabitEthernet3/0/24
 description Backup Uplink
 switchport access vlan 999
 switchport mode access
!
interface Vlan1
 no ip address
!
interface Vlan100
 ip address 10.10.100.253 255.255.255.0
!
ip default-gateway 10.10.100.1

ip route 0.0.0.0 0.0.0.0 10.10.100.1
ip classless
no ip http server
ip http secure-server
!
logging trap debugging
logging facility local2
!
!
line con 0
!
end

21 Replies 21

ASA firewall? Could you post config?

Is the ASA configured with Sub Interfaces? Are there ACLs applied, what are the security levels?

Its a Juniper SRX. I have an any/any policy between the VLANs and i see the traffic allowed through that. It has sub interfaces with VLAN ids. If I unplug the FW and try to ping 2 physical devices it still doesnt work. Testing pings from 100 to 103 i can ping 103.1 my FW vlan interface but nothing else

Im missing something simple im sure

I think the juniper fw is connected to this port, right?

interface GigabitEthernet3/0/22
 description Laptop - Prod
 switchport trunk encapsulation dot1q
 switchport trunk allowed vlan 100,102,103
 switchport mode trunk

Not sure how Juniper works but have you checked the security levels on each subinterface? or any inspect policy. 

Are the subinterfaces able to ping to their hosts? have you checked the window firewall on the computers?. 




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<

I see 5 interfaces with description LAN and trunked. How are these connected to the Juniper device? 

On the switch can you see the mac addresses of the firewall L3 interfaces?

do you have diagram?

Yep the FW is on any of the trunk interfaces with a desc of LAN. This is all virtual sitting on ESXi. I can see all the macs of the esxi interfaces on show mac on the switch. I will work on a diagram. Physical devices are so much easier to deal with.

Hi

I see you have a static route on your switch, check if ip routing command is enabled, now you need to verify if the other device knows how to reach the vlan 100 on this device. The ping is reciprocal, when the source send a request to a destination, the destination must send a response to the source. 




>> Marcar como útil o contestado, si la respuesta resolvió la duda, esto ayuda a futuras consultas de otros miembros de la comunidad. <<
Review Cisco Networking for a $25 gift card