Go Premium for a chance to win a PS4. Enter to Win

x
?
Solved

VLAN "flickering" - ping request timed out infrequently

Posted on 2008-10-02
3
Medium Priority
?
720 Views
Last Modified: 2013-11-09
I am setting up a VLAN on our network, mostly made up of cisco 3750 switches. It will only be used on one switch. This VLAN will be tunneled through an ASA box to another network in another company. It should not talk to any other VLANs except to be able to use the tunnel (though for starters I will keep it open to test)

I've set up:
vlan access-map map_ki 10
 action forward
 match ip address ki_acl
interface Vlan54
 description ....
 ip address 192.168.54.1 255.255.255.0
ip access-list extended ki_acl
 permit ip any any

in the asa box I added to the outside accesslist permiting this VLAN out to any on port 80

My problem:
it seems to "time out". if I ping or try to access a webpage it sometimes completes the action and sometimes not.
if I ping -t an inside ip and google side by side they might give 10 successes then 20 request timed out then again success. And the two pings are not consistent either.

I've tried changing ports on the switch as well as the cables so I've pretty much ruled those out.

how do I troubleshoot this?
0
Comment
Question by:oddny
  • 2
3 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 375 total points
ID: 22629869
Awfully odd way to structure this.
Does the ASA have an unused Ethernet port on it? If yes, just connect it to an access port in vlan54.
If no, consider trunking a port between the switch and the asa and create a sub-interface for vlan54.
This way all traffic restrictions are at the asa proper and not on the switch. As long as the vlan54 interface of the asa has a lower security level than the inside, zero traffic will be allowed, but all vlan54 traffic will be allowed out. Setting it up for the vpn to another company is piece of cake.
0
 

Author Comment

by:oddny
ID: 22643956
it's the way other vlans are structured here and I couldnt get it to work solely on the cisco guide on vlans for 3750. Probably because we have switches that are older too? 2950 and such.

anyway, it's stopped flickering now. Thank you.
0
 

Author Closing Comment

by:oddny
ID: 31502492
it's the way other vlans are structured here and I couldnt get it to work solely on the cisco guide on vlans for 3750. Probably because we have switches that are older too? 2950 and such.

anyway, it's stopped flickering now. Thank you.
0

Featured Post

Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

For months I had no idea how to 'discover' the IP address of the other end of a link (without asking someone who knows), and it drove me batty. Think about it. You can't use Cisco Discovery Protocol (CDP) because it's not implemented on the ASAs.…
Powerful tools can do wonders, but only in the right hands.  Nowhere is this more obvious than with the cloud.
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Suggested Courses

926 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question