07-01-2017 05:45 PM - edited 03-08-2019 11:10 AM
I'm having problems pinging across VLAN's on my stacked switches. Any help would be appreciated.
!
version 12.2
no service pad
service timestamps debug uptime
service timestamps log datetime localtime
service password-encryption
service sequence-numbers
!
!
no aaa new-model
clock timezone EST -5
clock summer-time EST recurring
switch 1 provision ws-c3750g-24t
switch 3 provision ws-c3750g-24t
system mtu routing 1500
ip routing
!
!
!
!
spanning-tree mode pvst
spanning-tree extend system-id
!
vlan internal allocation policy ascending
!
!
!
interface GigabitEthernet1/0/1
description SAN
switchport access vlan 102
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet1/0/2
description SAN
switchport access vlan 102
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet1/0/3
description SAN
switchport access vlan 102
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet1/0/4
description SAN
switchport access vlan 102
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet1/0/5
description iSCSI
switchport access vlan 102
switchport mode access
!
interface GigabitEthernet1/0/6
description iSCSI
switchport access vlan 102
switchport mode access
!
interface GigabitEthernet1/0/7
description iSCSI
switchport access vlan 100
switchport mode access
!
interface GigabitEthernet1/0/8
description iSCSI
switchport access vlan 102
switchport mode access
!
interface GigabitEthernet1/0/9
description LAN
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 100,102,103
switchport mode trunk
!
interface GigabitEthernet1/0/10
description LAN
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 100,102,103
switchport mode trunk
!
interface GigabitEthernet1/0/11
!
interface GigabitEthernet1/0/12
!
interface GigabitEthernet1/0/13
description esxi1 - mgmt
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 100,102,103
switchport mode trunk
!
interface GigabitEthernet1/0/14
description esxi1 - vmotion
switchport access vlan 101
switchport mode access
!
interface GigabitEthernet1/0/15
description esxi1 - iDrac
switchport access vlan 103
switchport mode access
!
interface GigabitEthernet1/0/16
description esxi3 - mgmt
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 100,102,103
switchport mode trunk
!
interface GigabitEthernet1/0/17
description LAN
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 100,102,103
switchport mode trunk
!
interface GigabitEthernet1/0/18
!
interface GigabitEthernet1/0/19
description esxi3 - iDrac
switchport access vlan 103
switchport mode access
!
interface GigabitEthernet1/0/20
!
interface GigabitEthernet1/0/21
description Laptop - Mgmt
switchport access vlan 103
!
interface GigabitEthernet1/0/22
!
interface GigabitEthernet1/0/23
description esxi - uplink
switchport access vlan 999
switchport mode access
!
interface GigabitEthernet1/0/24
description Primary Uplink
switchport access vlan 999
switchport mode access
!
interface GigabitEthernet3/0/1
description SAN
switchport access vlan 102
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet3/0/2
description SAN
switchport access vlan 102
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet3/0/3
description SAN
switchport access vlan 102
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet3/0/4
description SAN
switchport access vlan 102
switchport mode access
spanning-tree portfast
!
interface GigabitEthernet3/0/5
description iSCSI
switchport access vlan 102
switchport mode access
!
interface GigabitEthernet3/0/6
description iSCSI
switchport access vlan 102
switchport mode access
!
interface GigabitEthernet3/0/7
description iSCSI
switchport access vlan 100
switchport mode access
!
interface GigabitEthernet3/0/8
description iSCSI
switchport access vlan 102
switchport mode access
!
interface GigabitEthernet3/0/9
description LAN
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 100,102,103
switchport mode trunk
!
interface GigabitEthernet3/0/10
description LAN
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 100,102,103
switchport mode trunk
!
interface GigabitEthernet3/0/11
!
interface GigabitEthernet3/0/12
!
interface GigabitEthernet3/0/13
description esxi2 - mgmt
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 100,102,103
switchport mode trunk
!
interface GigabitEthernet3/0/14
description esxi2 - vmotion
switchport access vlan 101
switchport mode access
!
interface GigabitEthernet3/0/15
description esxi2 - iDrac
switchport access vlan 103
switchport mode access
!
interface GigabitEthernet3/0/16
!
interface GigabitEthernet3/0/17
!
interface GigabitEthernet3/0/18
!
interface GigabitEthernet3/0/19
!
interface GigabitEthernet3/0/20
!
interface GigabitEthernet3/0/21
description esxi - Uplink
switchport access vlan 999
switchport mode access
!
interface GigabitEthernet3/0/22
description Laptop - Prod
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 100,102,103
switchport mode trunk
!
interface GigabitEthernet3/0/23
description esxi - Uplink
switchport access vlan 999
switchport mode access
!
interface GigabitEthernet3/0/24
description Backup Uplink
switchport access vlan 999
switchport mode access
!
interface Vlan1
no ip address
!
interface Vlan100
ip address 10.10.100.253 255.255.255.0
!
ip default-gateway 10.10.100.1
ip route 0.0.0.0 0.0.0.0 10.10.100.1
ip classless
no ip http server
ip http secure-server
!
logging trap debugging
logging facility local2
!
!
line con 0
!
end
07-02-2017 06:05 AM
ASA firewall? Could you post config?
Is the ASA configured with Sub Interfaces? Are there ACLs applied, what are the security levels?
07-02-2017 06:18 AM
Its a Juniper SRX. I have an any/any policy between the VLANs and i see the traffic allowed through that. It has sub interfaces with VLAN ids. If I unplug the FW and try to ping 2 physical devices it still doesnt work. Testing pings from 100 to 103 i can ping 103.1 my FW vlan interface but nothing else
07-02-2017 06:20 AM
Im missing something simple im sure
07-02-2017 06:26 AM
I think the juniper fw is connected to this port, right?
interface GigabitEthernet3/0/22
description Laptop - Prod
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 100,102,103
switchport mode trunk
Not sure how Juniper works but have you checked the security levels on each subinterface? or any inspect policy.
Are the subinterfaces able to ping to their hosts? have you checked the window firewall on the computers?.
07-02-2017 06:52 AM
I see 5 interfaces with description LAN and trunked. How are these connected to the Juniper device?
On the switch can you see the mac addresses of the firewall L3 interfaces?
do you have diagram?
07-02-2017 07:13 AM
Yep the FW is on any of the trunk interfaces with a desc of LAN. This is all virtual sitting on ESXi. I can see all the macs of the esxi interfaces on show mac on the switch. I will work on a diagram. Physical devices are so much easier to deal with.
07-02-2017 05:28 AM
Hi
I see you have a static route on your switch, check if ip routing command is enabled, now you need to verify if the other device knows how to reach the vlan 100 on this device. The ping is reciprocal, when the source send a request to a destination, the destination must send a response to the source.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide