cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2725
Views
3
Helpful
7
Replies

9800-CL VLAN interfaces

SamBurgess44786
Level 1
Level 1

Hello Cisco Community,

I am building a 9800-CL which is running on ESXi but I am struggling to reach any of the configured VLAN interfaces from our core switches (except for the management(VLAN50)).

My thinking was the first vWLC port Gi1 would be routed for management purposes and the second Gi2 would be a trunk carrying all the AP control and data traffic, however this trunk configuration doesn't seem to be working. The only way I can get connectivity from my core to any other VLAN except management is to configure a second Gi2 port as routed and stick a static route in the vWLC. I also don't understand why the routed port has to be in a separate subnet to my SVI, so even then, despite being able to ping the interface, I still can't get to my SVI. 

There are clearly some gaps in my understanding here so any help would be appreciated.

IntVLAN8.pngEth2.pngVMsettings.pngVMnetwork.pngpings.png

I do recognise that in the pictures there is a trunk on Gi2 and the network adapter in vSphere is in access mode. I have tried changing Gi2 to access but saw no difference. Do I need to get our VMware guys to create a new trunked network adapter for me to use?

Thanks 

 

1 Accepted Solution

Accepted Solutions

Hi @SamBurgess44786 

 You are right related to the ports:

  • Gigabit1: Out of Band Management (Service Port)
  • Gigabit2: Main Network Interface for client traffic
  • Gigabit3: Heartbeat interface for SSO HA

But in order to support trunk, which interface must be connected in a separated vSwitch.

You may check this guide.

https://www.wifireference.com/2019/08/24/cisco-catalyst-9800-cl-deployment-guide/

 

View solution in original post

7 Replies 7

Hi @SamBurgess44786 

 You are right related to the ports:

  • Gigabit1: Out of Band Management (Service Port)
  • Gigabit2: Main Network Interface for client traffic
  • Gigabit3: Heartbeat interface for SSO HA

But in order to support trunk, which interface must be connected in a separated vSwitch.

You may check this guide.

https://www.wifireference.com/2019/08/24/cisco-catalyst-9800-cl-deployment-guide/

 

Hi @Flavio Miranda 

Thank you for your prompt response.

Yes the article has cleared things up, our VMware guys are going to create a new port group for me which I can move my vNIC to (in VM Settings) and then configure with our required VLANs.

Will hopefully sort things out!

 

  - You may find this command useful on the 9800-cl :
                          show platform hardware chassis active qfp datapath pmd ifdev

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

SamBurgess44786
Level 1
Level 1

Just a quick update, this is working after creating a port group (trunk) with the required VLANs in VMware and configuring that on network adapter 2 in the VM settings. Simply then configure vWLC Gi2 as a trunk. 

Also required - within Networking properties of VMware, the Promiscuous mode and Forged transmits are set to Reject by default. These both need to be set to Accept for the port group.

 

 - Great ! Have (final) checkup of the 9800-CL controller configuration with the CLI command show tech wireless ; feed the output into :
                                                                              https://cway.cisco.com/wireless-config-analyzer/
      Strongly advised!

 M.



-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
    When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '

Yes I was going to point that out after seeing your VMware screenshots.  That's made very clear in the config guide and the best practice guide https://www.cisco.com/c/en/us/products/collateral/wireless/catalyst-9800-series-wireless-controllers/guide-c07-743627.html#C9800CLconsiderations

Review Cisco Networking for a $25 gift card