cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
236
Views
1
Helpful
4
Replies

Unable to SSH into Switch through Management VLAN

IT1Andy
Level 1
Level 1

Good evening!

I am new to networking and attempting to build out a basic network. I have a Cisco 4431 Router and two Cisco 3850's. I have multiple VLANS place to separate data paths, but utilizing VLAN 99 as a management. I am unable to ping or SSH into one of the 3850s which is trunked. I can pass normal data, but I want a way so I can SSH into it in the event I need to make a modification. Can someone give me a hand?

Hub SWITCH: 

interface Loopback0
ip address 192.168.100.8 255.255.255.0
no ip route-cache
!
interface GigabitEthernet0/0
vrf forwarding Mgmt-vrf
no ip address
no ip route-cache
negotiation auto
!
interface GigabitEthernet1/0/1
switchport access vlan 69
switchport mode access
!
interface GigabitEthernet1/0/2
switchport access vlan 10
switchport mode access
switchport nonegotiate
!
interface GigabitEthernet1/0/3
!
interface GigabitEthernet1/0/4
!
interface GigabitEthernet1/0/5
!
interface GigabitEthernet1/0/6
!
interface GigabitEthernet1/0/7
!
interface GigabitEthernet1/0/8
!
interface GigabitEthernet1/0/9
!
interface GigabitEthernet1/0/10
!
interface GigabitEthernet1/0/11
!
interface GigabitEthernet1/0/12
!
interface GigabitEthernet1/0/13
switchport access vlan 99
switchport mode access
!
interface GigabitEthernet1/0/14
!
interface GigabitEthernet1/0/15
!
interface GigabitEthernet1/0/16
!
interface GigabitEthernet1/0/17
!
interface GigabitEthernet1/0/18
!
interface GigabitEthernet1/0/19
!
interface GigabitEthernet1/0/20
!
interface GigabitEthernet1/0/21
!
interface GigabitEthernet1/0/22
!
interface GigabitEthernet1/0/23
!
interface GigabitEthernet1/0/24
!
interface GigabitEthernet1/0/25
switchport mode access
!
interface GigabitEthernet1/0/26
!
interface GigabitEthernet1/0/27
!
interface GigabitEthernet1/0/28
!
interface GigabitEthernet1/0/29
!
interface GigabitEthernet1/0/30
!
interface GigabitEthernet1/0/31
!
interface GigabitEthernet1/0/32
!
interface GigabitEthernet1/0/33
!
interface GigabitEthernet1/0/34
!
interface GigabitEthernet1/0/35
!
interface GigabitEthernet1/0/36
!
interface GigabitEthernet1/0/37
switchport mode access
speed 1000
duplex full
!
interface GigabitEthernet1/0/38
!
interface GigabitEthernet1/0/39
!
interface GigabitEthernet1/0/40
!
interface GigabitEthernet1/0/41
!
interface GigabitEthernet1/0/42
!
interface GigabitEthernet1/0/43
!
interface GigabitEthernet1/0/44
!
interface GigabitEthernet1/0/45
!
interface GigabitEthernet1/0/46
!
interface GigabitEthernet1/0/47
switchport trunk allowed vlan 10,99
switchport mode trunk
switchport nonegotiate
!
interface GigabitEthernet1/0/48
switchport trunk allowed vlan 10
switchport mode trunk
!
interface GigabitEthernet1/1/1
!
interface GigabitEthernet1/1/2
!
interface GigabitEthernet1/1/3
!
interface GigabitEthernet1/1/4
switchport trunk allowed vlan 10
switchport mode trunk
!
interface TenGigabitEthernet1/1/1
!
interface TenGigabitEthernet1/1/2
!
interface TenGigabitEthernet1/1/3
switchport trunk allowed vlan 15
switchport mode trunk
!
interface TenGigabitEthernet1/1/4
!
interface Vlan1
no ip address
no ip route-cache
!
interface Vlan10
description Higgins Connection
no ip address
no ip route-cache
!
interface Vlan99
description Management
ip address 192.168.99.1 255.255.255.252
no ip route-cache
!
ip default-gateway 192.168.1.1
ip forward-protocol nd
ip http server
ip http authentication local
ip http secure-server
ip ssh authentication-retries 2
ip ssh version 2
!
!
!
!
!
!
!
line con 0
password 7 08134342052D0C13175A54577B6A65
logging synchronous
login authentication exit
stopbits 1
line aux 0
stopbits 1
line vty 0 4
transport input ssh
line vty 5 15
transport input ssh
!
!
ap group default-group
end

 

Trunked Switch: 

interface GigabitEthernet0/0
vrf forwarding Mgmt-vrf
no ip address
negotiation auto
!
interface GigabitEthernet1/0/1
no switchport
ip address 192.168.1.2 255.255.255.0
!
interface GigabitEthernet1/0/2
switchport access vlan 50
switchport mode access
!
interface GigabitEthernet1/0/3
!
interface GigabitEthernet1/0/4
!
interface GigabitEthernet1/0/5
!
interface GigabitEthernet1/0/6
!
interface GigabitEthernet1/0/7
!
interface GigabitEthernet1/0/8
!
interface GigabitEthernet1/0/9
!
interface GigabitEthernet1/0/10
!
interface GigabitEthernet1/0/11
!
interface GigabitEthernet1/0/12
!
interface GigabitEthernet1/0/13
!
interface GigabitEthernet1/0/14
switchport access vlan 15
switchport mode access
duplex full
!
interface GigabitEthernet1/0/15
!
interface GigabitEthernet1/0/16
!
interface GigabitEthernet1/0/17
!
interface GigabitEthernet1/0/18
!
interface GigabitEthernet1/0/19
!
interface GigabitEthernet1/0/20
!
interface GigabitEthernet1/0/21
!
interface GigabitEthernet1/0/22
!
interface GigabitEthernet1/0/23
!
interface GigabitEthernet1/0/24
!
interface GigabitEthernet1/0/25
!
interface GigabitEthernet1/0/26
switchport access vlan 10
switchport mode access
duplex full
!
interface GigabitEthernet1/0/27
speed 1000
duplex full
!
interface GigabitEthernet1/0/28
!
interface GigabitEthernet1/0/29
!
interface GigabitEthernet1/0/30
!
interface GigabitEthernet1/0/31
!
interface GigabitEthernet1/0/32
!
interface GigabitEthernet1/0/33
!
interface GigabitEthernet1/0/34
!
interface GigabitEthernet1/0/35
!
interface GigabitEthernet1/0/36
!
interface GigabitEthernet1/0/37
!
interface GigabitEthernet1/0/38
switchport access vlan 20
switchport mode access
!
interface GigabitEthernet1/0/39
!
interface GigabitEthernet1/0/40
!
interface GigabitEthernet1/0/41
!
interface GigabitEthernet1/0/42
!
interface GigabitEthernet1/0/43
!
interface GigabitEthernet1/0/44
!
interface GigabitEthernet1/0/45
!
interface GigabitEthernet1/0/46
!
interface GigabitEthernet1/0/47
switchport access vlan 10
switchport trunk allowed vlan 10,99
switchport mode trunk
switchport nonegotiate
!
interface GigabitEthernet1/0/48
switchport trunk allowed vlan 10,99
switchport mode trunk
!
interface GigabitEthernet1/1/1
description From Starlink
no switchport
ip address 192.168.100.2 255.255.255.252
!
interface GigabitEthernet1/1/2
!
interface GigabitEthernet1/1/3
!
interface GigabitEthernet1/1/4
description To CC256
switchport trunk allowed vlan 10
switchport mode trunk
switchport nonegotiate
!
interface TenGigabitEthernet1/1/1
no switchport
no ip address
shutdown
!
interface TenGigabitEthernet1/1/2
!
interface TenGigabitEthernet1/1/3
!
interface TenGigabitEthernet1/1/4
!
interface Vlan1
no ip address
shutdown
!
interface Vlan10
ip address 192.168.10.1 255.255.255.0
!
interface Vlan15
ip address 192.168.15.1 255.255.255.0
!
interface Vlan20
ip address 192.168.20.1 255.255.255.0
!
interface Vlan25
description Starlink
no ip address
!
interface Vlan50
description Andersen
ip address 192.168.50.1 255.255.255.0
!
interface Vlan99
description Management
ip address 192.168.99.10 255.255.255.252
!
ip default-gateway 192.168.1.1
ip forward-protocol nd
ip http server
ip http authentication local
ip http secure-server
ip route 0.0.0.0 0.0.0.0 192.168.100.1
ip ssh version 2
ip scp server enable

 

!
line con 0
password 7 113B16091B260208017B7377797274
logging synchronous
stopbits 1
line aux 0
stopbits 1
line vty 0 4
login local
transport input ssh
line vty 5 15
login local
transport input ssh
!
!
!
!
!
!
!
end

 

4 Replies 4

Hello,

If you are unable to ping it then you need to fix that reachability first. Your VLAN 99s are on different networks so you need to make sure there is routing between them so they can find each other. either static or a routing protocol. Once you can ping tehn move onto SSH.

Secondly, I dint see where SSH is enabled. You have the protocol allowed on the VTY lines but that doesn't enable it to function on the device. Neither does ip ssh version 2. You need a t a minimum a hostname, domain name and you need to generate an SSH Crypto key with the command:

conf t

crypto key generate rsa modulus <#>  <-- where # needs to be more than 786 I believe.

 

-David

 

 

Sir,

I am not able to ping each switch, but still unable to SSH into the switch which is trunked. 

Hello
The hub and switch mgt vlan (99) subnet addressing is incorrect - amend that and you should be able to reach both switches.

Hub
no ip default-gateway 192.168.1.1
ip default-gateway 192.168.99.10

interface Vlan99
description Management
no ip address 192.168.99.1 255.255.255.252
ip address 192.168.99.1 255.255.255.0


switch
interface Vlan99
no ip address 192.168.99.10 255.255.255.252
ip address 192.168.99.10 255.255.255.0


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul

mohamedlamine
Level 1
Level 1

It sounds like you may need to check the configuration settings on your network devices to ensure that the VLAN configurations and trunking settings are correctly configured. Here are some steps you can take to troubleshoot the issue:

  1. Verify that the VLANs are properly configured on both the Cisco 4431 Router and the Cisco 3850 switches. Make sure that VLAN 99 is allowed on the trunk port connecting the two switches.

  2. Check the IP address settings on the Cisco 3850 switch that you are unable to ping or SSH into. Ensure that the management VLAN interface has the correct IP address and subnet mask configured.

  3. Verify that the default gateway is correctly set on the Cisco 3850 switch so that it can communicate with other devices on the network, including the device you are trying to SSH from.

  4. Check the firewall settings on the Cisco 3850 switch to ensure that SSH traffic is allowed. You may need to configure an access control list (ACL) to permit SSH traffic to the switch.

  5. If you are still unable to SSH into the Cisco 3850 switch, you may want to check the logging and debugging information on both the router and the switch to see if there are any error messages that can help pinpoint the issue.

By following these steps, you should be able to troubleshoot the issue and establish a successful SSH connection to the Cisco 3850 switch. Good luck with your networking setup!

 
 
 
Review Cisco Networking for a $25 gift card