Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

Managed Configure VLAN, Unable to Issue DHCP out

Posted on 2008-10-13
22
1,872 Views
Last Modified: 2011-10-19
Currently I POCing Fortigate UTMS with plan to split company network to several vlan for ease of management. I got 3 3COM Switch 4400 SuperStack 3 3C17203 aggregated together into 1 VLAN. To start the test small, I configured 2 free ports on of the switch into VLAN 2  and configured the DMZ port on the Fortigate firewall to issue DHCP. I tested it with a cross cable connect to my laptop the DHCP issue is with no issue. I connect cross cable from the Fortigate DMZ  to one VLAN 2 port while the other VLAN 2 port is connected to the test laptop.

I can ping to the dhcp server using static ip neither can I grab any ip from the dhcp server set at the fortigate DMZ port. Any 3COM switch experts out there can lend me a hand. Thanks.
0
Comment
Question by:aneky
  • 11
  • 11
22 Comments
 
LVL 21

Accepted Solution

by:
from_exp earned 500 total points
ID: 22709139
Hi!
I know 3com 4400 rather well, however I can't remember any feature in it to block some traffic. Try to use unmanaged switch to check this. My initial assumption is incorrect switch config (check if both ports added to this vlan 2 untagged) and check fortigate for logs. try also to release ip on client and then to renew it.
0
 
LVL 1

Author Comment

by:aneky
ID: 22709477
Actually I installed the 3com Network Device Manager login into the 3COM switch and configured the VLAN to both tagged or untagged, without any luck. If it doesn't ping to the fortigate gateway the issue should lie on the 3com switch. I enclosed the screenshot of my config in here for a look.

One thing need to note is if I access directly to the switch using IE, I will not be able to see the VLAN configuration as I see in 3com Network Device Manager. I no idea if it is because of the firmware of the switch might be obsolete that causes this issue.


VLAN-Config.JPG
0
 
LVL 21

Assisted Solution

by:from_exp
from_exp earned 500 total points
ID: 22709595
try to configure vlans using console/telnet - it is rather straight forward
both ports should be untagged in vlan 2 with pvid 2, as you have on the picture.
0
Easy, flexible multimedia distribution & control

Coming soon!  Ideal for large-scale A/V applications, ATEN's VM3200 Modular Matrix Switch is an all-in-one solution that simplifies video wall integration. Easily customize display layouts to see what you want, how you want it in 4k.

 
LVL 1

Author Comment

by:aneky
ID: 22709628
Problem it doesn't work as it should. Unless, you wan me connect 1 pc at 1 port with pre-assigned IP and another with the same and try ping to each other to isolate maybe the problem might be at the fortigate portion.
0
 
LVL 1

Author Comment

by:aneky
ID: 22709656
I telnet into the switch I checked the vlan settings still there. as I configured using the GUI.
0
 
LVL 21

Assisted Solution

by:from_exp
from_exp earned 500 total points
ID: 22709664
sorry, but can you, please, connect to the switch with telnet and verify if there is vlan 2 and it is assigned to correct ports
and if there isn't then try to create it
0
 
LVL 1

Author Comment

by:aneky
ID: 22709712
Yeah I just did as you ask when I post the previous message. Let me enclosed screenshot to explain it better.


TELNET-VLAN-Config.JPG
0
 
LVL 21

Assisted Solution

by:from_exp
from_exp earned 500 total points
ID: 22709883
ok, seems you have vlan 2 on the switch.
now, please, connect both devices and check ports status. if ports are enabled and marked as active, check mac addresses learned by switch on those ports and in vlan 2
0
 
LVL 21

Assisted Solution

by:from_exp
from_exp earned 500 total points
ID: 22709889
it is also useful to check if both ports (and both network cards) are configured with auto negotiation
0
 
LVL 1

Author Comment

by:aneky
ID: 22709978
How to check if both ports are configured auto negotiation. I thought by default all switch port is configured for auto negotiation
0
 
LVL 21

Expert Comment

by:from_exp
ID: 22710016
in the ports menu via telnet, however, if both ports are active (green led), then port is up with correct settings.
0
 
LVL 1

Author Comment

by:aneky
ID: 22717459
If that the case both ports are up with green led, but I cannot ping to the the fortigate. I manually configure the 2 static ip on 2 laptop within the same subnet and ip range (with firewall and antivirus disabled) and tried ping to each other. Both reply with timeout. I running out of ideas what going wrong with the vlan.
0
 
LVL 21

Expert Comment

by:from_exp
ID: 22718241
please issue arp -an on both laptops - I want to check whether pc's can get macs of the second side
0
 
LVL 1

Author Comment

by:aneky
ID: 22718286
When I run the command arp -a on  both laptop. The laptop configure with the IP 192.168.1.4 respond

Interface 192.168.1.4 ---- 0x3
   Internet Address            Physical Address                  Type
   192.168.1.5                    00-00-00-00-00-00                invalid

The laptop configure with IP 192.168.1.5 respond

There are no arp entries.

0
 
LVL 21

Expert Comment

by:from_exp
ID: 22718497
so it means, you don't have both ports in the same vlan.....
is it possible you are using incorrect ports/unit?
0
 
LVL 1

Author Comment

by:aneky
ID: 22718533
No I specifically configure it under unit 1 port 4 & 8. If they are not in the same VLAN 2 then if I use a laptop plug to the port I should able to grab the IP from the original VLAN 1. I had tried both ports are unable to grab IP from my DHCP server.
0
 
LVL 21

Expert Comment

by:from_exp
ID: 22718585
yes, but from the other hand if those ports are within the same vlan, pcs should be able to see each other.
can you reboot your stack?
0
 
LVL 1

Author Comment

by:aneky
ID: 22718623
I will have to wait after office working hour to do that. If reboot is the only choice.
0
 
LVL 21

Expert Comment

by:from_exp
ID: 22718627
if you say that you have created vlan, and assigned ports to it and it still not working - I would try rebooting device....
0
 
LVL 1

Author Comment

by:aneky
ID: 22754914
Ok I rebooted the switch. The problem still persist. arp -a still unable to see each other neither can ping or grabing IP from the dhcp server.
0
 
LVL 21

Expert Comment

by:from_exp
ID: 22755090
hmmmmm
please, check mac addresses learned by switch on both ports.
do both macs are within the same vlan?
0
 
LVL 1

Author Comment

by:aneky
ID: 23033344
from_exp

Thanks for your help. The problem still the same. Anyway, I give up on the VLAN as my management pull the plug on my network upgrade plans so I no longer need this .
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

We sought a budget ($5,000) firewall solution that would provide all the performance we needed with no single point of failure.  Hosting a SAAS web application in our datacenter, it was critical that we find a way to keep connectivity up and inbound…
Optimal Xbox 360 connectivity requires "OPEN NAT". If you use Juniper Netscreen or SSG firewall products in a home setting, the following steps will allow you get rid of the dreaded warning screen below and achieve the best online gaming environment…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…
In an interesting question (https://www.experts-exchange.com/questions/29008360/) here at Experts Exchange, a member asked how to split a single image into multiple images. The primary usage for this is to place many photographs on a flatbed scanner…

860 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question