cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1309
Views
1
Helpful
12
Replies

Switch unable to ping its local SVI

Ismail Ilyas
Level 1
Level 1

Hello switching experts!

I have deployed a pair of Cat 9300 switches i.e 9300-48T-E running IOS 17.9.4. These switches are stacked. Everything is working fine. However, a strange issue is being faced i.e. switch is unable to ping its local SVI. The protocol and line protocol of SVI is UP. and the switch uplinks are connected to firewall through  trunked etherchannel  carrying multiple VLANs along with problematic SVI. The downstream servers are connected to other switch ports and there is no issue in server traffic. For testing, connected a laptop with switch on an access port. The laptop was also unable to ping SVI, however able to ping other IP of same subnet configured on firewall. Laptop mac-address was discovered on switch in correct VLAN but no arp. Switch has ARP of local SVI but no ARP of firewall end. For test purpose, created another Test SVI which also had same response as problematic one. If anyone faced such issue, please assist.

 

 

12 Replies 12

balaji.bandi
Hall of Fame
Hall of Fame

Not that i am aware this issue was reported nor we encounter this issue on any of Cat 9300 switch.

Is this SVI working one, went down, or new SVI not working ?  (Hope this is not extended VLANS ?)

can you post information realted to SVI configuration ?

Make sure VLAN created associated with SVI.

post below output :

show vlan

show run interface vlanX

show interface vlanX ?

Note : may be worth remove SVI and add back and check ?

Make sure Look the logs always give some information.

 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Checked show VLAN ? VLAN is active 

sh run interface ? Only has ip address and unshut

sh interface vlan  ? both protocols UP

SVI removed and added. Even VLAN removed and recreated.

Currently, dont have access to devices.

post below output :

show vlan

show run interface vlanX

show interface vlanX ?

Note : may be worth remove SVI and add back and check ?

Make sure Look the logs always give some information.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

ping using interface VLAN (same vlan of SVI)
MHM

Checked but no response.

when I face like this issue, I replace ping with traceroute maybe the next-hop is not SW but FW or any L3 device with ACL 
check traceroute 
share it here 
MHM

If you look at the actual problem, the switch is unable to ping local SVI. Ping and tracing other directly connected devices is next step.

friend I know 
if traceroute your local IP then it must appear as next-hop or appear as * meaning not reachable 
if either of above cases then there is issue
share traceroute let me check 
MHM

to be honest, I've seen several perfectly running IOS releases in the last years, where "pinging local IP" was not working, but everything else.

Since, "pinging your local IP" is just a software-hack like if I'd ask myself "are you alive?" - If I'm able to ask, I don't need the answer

For my understanding:

(a) put a laptop directly into a local switchport (stp portfast, mode access, access vlan xxx)

(b) use the laptop to ping the SVI (needs to be directly connected to the subnet of the SVI, check subnet-masks...)

(c) check the MAC-Table at the switch => did the laptop really sent something into the switch?

(d) check the arp-entry locally at the laptop (windows "arp -a", linux "ip n" or "cat /proc/net/arp")

=> even if ping fails for some reason, did ARP work?

This is a very simple setup, imho no need to simplify further with pinging to yourself.

(ping from switch to laptop is often prohibited by personal firewalls - but ARP should always work!)

(e) is there anything in the "show logging" log of the switch?

(f) are special features (dot1x, dhcp-snooping, arp-inspection) or control-plane-policing (copp) configured?

(g) are packet counters incremented at SVI-Level?

Thanks for the reply. Yea, one of the first things I tried was the good ole laptop plugged directly into a switchport configured in the Vlan- no luck. Do an arp -a on the laptop and all of the IP's in that Vlan show up, except for the Vlan interface IP. I can ping all of the IP's that show up in the ARP table that connect through the switch, but cannot ping the Vlan int. Nothing in switch logs, but logging is set at "warning" level right now, so unlikely to pick up something like this. Switch has VERY basic config... out of the box, plus the vlan configs and an Etherchannel configured to talk upstream. No "special features" whatsoever. Again, weird thing is we have many other switches on a different network, running the same software, that work fine. The two Cat9500's are redundant, so I literally wiped one clean (wr erase) and rebuilt from scratch, out of frustration. Crazy thing is that when I re-configured the Vlan int after wiping the config clean, I got three pings through on my very first attempt, and then nothing after that.  We'll upgrade the software next week, as a final attempt, and then I'm gonna reach out to Cisco.

kevjam5
Level 1
Level 1

Did you ever resolve this issue? I've had the exact same issue on two Cat 9500's and two Cat 9300's running 17.3.3 for days. This is one of the strangest things I've ever seen. All traffic, i.e., downstream iLO ports on servers can communicate through the switches to hit our core switch (Nexus 7710). But it is just not possible to ping the UP/UP SVI on the switches (using these SVI's as in-band management), not from directly connected device, or trying to ping the interface from the device/switch itself. Only other issue I saw in the forums was resolved by upgrading software, but I have other 95/9300's, with the same code, that do not have this issue. Again, incredibly strange!

vinhtran427
Level 1
Level 1

Same question/issue here. Has anyone able to resolve this? I have the same issue, and the only arp entries I see on the switch is its own SVIs. This tells me that it can't even send or receive arp information. Upgrading software remotely might be a challenge here if SVI is not working.

Review Cisco Networking for a $25 gift card