cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
279
Views
4
Helpful
4
Replies

WS-C4503-E with routing problem

Hi,

 

End user has a 4503 with WS-X45-SUP6L-E and cat4500e-ipbasek9-mz.151-2.SG.bin, the switch is the core and are defined 16 interface VLANs.

all interface vlan in sw core are the default Gateway for devices and the default route is a watchguard device.

The problem is that suddenly  users cannot Access to internet. If we trace to 8.8.8.8 or other external address from  laptop or desktop we see that the last hop is the ip address of the switch core (default Gateway), for some reason the sw core does not sent the traffic to watchguard, but If we trace from switch core to any external address we can see the hop the watchguard and reach the final destination.

 

 we need to reset the switch in order to clear the problem, this problem has taken place twice in this week.

any idea of this issue?

 

 

 

4 Replies 4

Reza Sharifi
Hall of Fame
Hall of Fame

There maybe something wrong with the port that connects to the watchgurad device.  Try moving the connection to a different port on the switch and the watchguard device and monitor for a week or 2.

HTH

Hi Reza,

Thanks a lot for your comments.

when the problem takes place and before the reset of sw core  if we set on PC and lap the watchguard as default Gateway they can reach to external address an internet.

which command should I type if the problem takes place once again in order to confirm if the problem is the port?

 

regards

 

 

 

 

Hi,

There isn't really a command that will show you when that is happening.  If you have configured everything correctly, this could be a bug in the IOS on the 4500.  So, you may want to upgrade to a different version and monitor for a week or 2.

HTH

Sarbjit-2014
Level 1
Level 1

Hi,

Maybe its not the Switch, try restarting/replace the watchguard FW also does it have the latest IOS. Check the FW logs to see if traffic is being denied to internet from your local LAN. Maybe your missing a permit access statement in your access-list.

Review Cisco Networking for a $25 gift card