08-16-2017 09:50 AM - edited 03-08-2019 11:46 AM
Hello All,
I'm looking for a solution. I have a 4331 ISR that is currently in production and working fine. Though I have some very specific pings that fail and I'm trying to figure out why as it is making it difficult to troubleshoot other things. I've attached a simple Net Diagram below to help me think through this and to make it easy to see my situation.
The problem:
Router @ Branch 1 cannot ping to any address in HQ.
Considerations:
Branch 1 can ping anywhere on its local LAN and even within the MPLS to other Branches.
Everyone can ping Branch 1, whether from HQ, LAN, or neighboring branch.
I have checked access-lists and ruled that out. I'm fairly sure that the routes are fine (I'm using BGP across the MPLS and EIGRP for my LAN). Like I said, Branch 1 is operation and is communicating with HQ, receiving updates and actively contacting a number of servers. Not sure where to go from here.
Any ideas would be greatly appreciated!
08-16-2017 09:57 AM
When you ping from the router it will use the source IP of it's WAN interface.
Can you ping this from HQ ?
Jon
08-16-2017 10:05 AM
No I can't, not from HQ. Nor can I ping that WAN interface's gateway.
Though I can ping these addresses from other branches connected to our MPLS.
So these IPs are controlled by my ISP. Could this be an issue on their end?
08-16-2017 10:11 AM
So there is no route for that IP or subnet ?
If so is there an interface on the router you do have a route for at HQ ?
If there can you ping that IP.
Jon
08-16-2017 11:27 AM
Your questions got me on the right path.
There were two problems. A routing issue on our HQ Core Switch where traffic being sent to the public address interface of Branch 1 was being redirected with a static route.
The second problem rested with our HQ MPLS router. There was an Access-List that hadn't been updated to allow traffic from Branch 1 public address.
I'm not 100% certain how any traffic was passing between the two locations to begin with, though. There is only this one active interface with that configured public address.
Either way, thank you for the help!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide