Solved

Troubleshooting IP helper configuration on an L3 switch

Posted on 2006-06-25
3
1,299 Views
Last Modified: 2008-02-01
So having struggled for a fortnight on an otherwise (persumably) simple problem, here I am, seeking experts advise!

In a nutshell..the network is simple. To explain in words might seem a bit lengthy.

Two VLANS on L2 Switch 1. We will call them VLAN 220 and VLAN 222.

VLAN10 serves IP subnet 10.20.220.0/23, giving an IP broadcast address of 10.20.221.255
DNS/DHCP/Default gateway to outside public network...all reside here.
DHCP address is 10.20.220.30 (it's a Netware Server) and DG is 10.20.220.50 which is the inside interface of a PIX doing a PAT on the outside. From within VLAN 220, everything is just perfect. Clients are getting leases and accessing internet.

I want to configure another VLAN222 which would limit broadcasts of IP subnet of 10.20.222.1/24
The clients here will recieve a subnet IP range of 10.20.222.50-255 from DHCP at 10.20.220.30/23.


I am using two interfaces on my Foundry's L3 switch 2, to serve as intervlan routing interfaces:
One cross cable from 'interface e1 (10.20.220.1/23)' of Switch 2 is connected to VLAN220 port of Switch1
One cross cable from 'interface e2 (10.20.222.1/24)' of switch 2 is connected to VLAN 222 of Switch 1.
The respective LED's are up on both the switches.
Ip Helper address is configured on 'Interface e2' of switch 2 pointing towards DHCP on VLAN220.

Problem:

Yes..Clients connected to VLAN 222 on Switch 1 are not getting an IP lease.

I manually assign an IP to a Client connected to a port on VLAN 222, in the range of 10.20.222.x with gateway set to 10.20.222.1, and I can ping 10.20.220.1 (interface e1) but cannot ping beyond to other hosts on my 10.20.220.x/23 network.

From within the console terminal of my L3 Switch 2, I can ping my DHCP server @ 10.20.220.30 and also the DG @ 10.20.30.50). I can also ping my client where I manually gave an IP address of the 10.20.222.x range.

Foundry's manual informs me that IP Routing is enabled by default on all it's Layer 3 switches. I have added 'ip forward-protocol udp echo', command in order to facilitate troubleshooting.

I also relate the details of Subnet configured to serve new VLAN222 on Netware DHCP server (just in case someone feels that here might lie the problem), though Netware configuration has no gotchas and is supposed to be straightforward.

A subnet by the name of vlan222 is configured and residing within an OU (abc.edu)
Address: 10.20.222.0
Mask: 255.255.255.0
Type: LAN
Start Address:10.20.222.10
End Address: 10.20.222.255
Range Type: Dynamic BOOTP and DHCP
Default gateway: 10.20.222.1

Below is the [sh run] and [sh ip route] on Switch 2.
-------------------------------------------------------
abc-net2#sh run
Current configuration:
!
ver 07.1.26mT13
global-stp
global-protocol-vlan
!
!
vlan 1 name DEFAULT-VLAN by port
 spanning-tree
!
hostname abc-net2
ip forward-protocol udp echo
ip route 10.20.220.0 255.255.254.0 ethernet 1
ip route 10.20.222.0 255.255.255.0 ethernet 2
ip route 0.0.0.0 0.0.0.0 10.20.220.50
snmp-server community ..... rw
router rip
!
interface e 1
 ip address 10.20.220.1 255.255.254.0
!
interface e 2
 ip address 10.20.222.1 255.255.255.0
 ip helper-address 1 10.20.220.30
!
interface e 3
!
interface e 4
!
interface e 5
!
interface e 6
!
interface e 7
!
interface e 8
!
interface e 9
!
interface e 10
!
interface e 11
!
interface e 12
!
interface e 13
!
interface e 14
!
interface e 15
!
interface e 16
!
!
!
!
end

abc-net2#
euc-net2#sh ip route
Total number of IP routes: 2
Start index: 1  D:Connected  R:RIP  S:Static  O:OSPF *:Candidate default
      Destination       NetMask           Gateway           Port   Cost   Type
1     10.20.220.0      255.255.254.0     0.0.0.0           1      1      D
2     10.20.222.0      255.255.255.0     0.0.0.0           2      1      D
3     0.0.0.0             0.0.0.0               10.20.220.50   1      1     D
abc-net2#
----------------------------------------------------------------------------

0
Comment
Question by:fahim
  • 2
3 Comments
 
LVL 43

Accepted Solution

by:
Steve Knight earned 200 total points
ID: 16979759
Do the hosts such as the netware server use the L3 switch as default gateway or do they point to the internet router?

If they use the internet router and it isn't learning routes from Swicth 2 it will not know how to get there.

Try load ping 10.20.222.xxx from your netware server.  

Now try adding a static route to the netware server, a windows box or ideally the PIX

For windows: route -p add 10.20.222.0 255.255.255.0 10.20.220.1

If they are using swicth2 as their default gateway then we'll have to think again!

Steve
0
 

Author Comment

by:fahim
ID: 16998815
Yes...inetcfg on Netware's DHCP server did the task. Added a static route to VLAN 222 with DG set to 10.20.220.1.

Also did the same on PIX and it all seems to work now.
Thanks

Points granted!
0
 
LVL 43

Expert Comment

by:Steve Knight
ID: 16998891
No problem, thanks for the points.

Steve
0

Featured Post

Do You Know the 4 Main Threat Actor Types?

Do you know the main threat actor types? Most attackers fall into one of four categories, each with their own favored tactics, techniques, and procedures.

Join & Write a Comment

Hi there, This article summarizes what you need if you are going to set up your home or small business Network Attached Storage (NAS) to be accessible from the internet. Of course there are configuration differences based on your NAS or router ma…
Let’s list some of the technologies that enable smooth teleworking. 
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
In this tutorial you'll learn about bandwidth monitoring with flows and packet sniffing with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're interested in additional methods for monitoring bandwidt…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

18 Experts available now in Live!

Get 1:1 Help Now