Solved

New VPN route crashing network

Posted on 2010-09-17
2
577 Views
Last Modified: 2012-05-10
Have a network with several vlans running.  Recently added Nortel 1100 Contivity VPN's that are at each end of a GRE Tunnel.
Location 1 - 3750 router enabled
Vlan 10 Network A 191.168.0.1/16
Vlan 42 Network B 172.50.0.1/27
Vlan 99 Management Network 10.1.0.1/24
GW 10.1.0.2

Port g1/0/24 connected to Nortel
Switchport access vlan 99
Ports g1/0/25
trunked port allowing all vlans through

Connected to Nortel 1100 Contivity
Private IP 10.1.0.2/24
Public IP 10.191.X.X/24
GW 10.1.0.1

Connected to Telus device going out into a cloud GRE Tunnel to Location 2 - IP's unknown (config'd by other dept)

Location 2 - 3750 router enabled
Vlan 10 Network A 191.169.1.1/24
Vlan 42 Network B 172.50.1.1/27
Vlan 99 Management Network 10.1.1.1/24
GW 10.1.1.2

Port g1/0/24 Connected to Nortel
switchport access vlan 99
Ports g1/0/25
trunked port allowing all vlans through (HP2524 hangs off this for workstations)

Connected to Nortel 1100 Contivity
Private IP 10.1.1.2/24
Public IP 10.23.X.X/24
GW 10.1.1.1

Connected to Telus device going out into a cloud GRE Tunnel to Location 1 - IP's unknown (config'd by other dept)

Am able to ping, connectivity is not the problem.

Main network is at location 1. At this location there is several switches with similar config as below.

Switch 1 - 3750-12S switch from Port Location 1 - 3750 Router G1/0/25
Connected on Port g1/0/12
Vlan 10 Network A 191.168.0.19/16
Vlan 42 Network B 172.50.0.4/27
Vlan 99 Mgmt Network 10.1.0.4/24
Trunked port allowing all three vlans through

The native VLAN on Cisco's is Native VLAN 10.  I have no IP address on VLAN 1, it is shutdown.

There is nowhere on the Nortel's to set native vlan, or to add vlans.  It only has vlan 1.

Problem:
When I open port g1/0/12 on Location 1 3750-12S to allow the feed to go through, the network becomes congested and starts dropping workstations.  As soon as I shutdown the port, the workstations come back up.  This is very important to get this feed going, and I do not have much time left before the deadline.  Currently there is nothing being fed, just the switches, routers are in place.  The workstations at location 2 are not even connected.

Please find attached the sh ip route of both Cisco's in location 1 and 2.

I have tried running sh logging on all Cisco's and see no errors logged.



 ip-routing-captures.txt
0
Comment
Question by:hayesie
2 Comments
 
LVL 4

Accepted Solution

by:
bjove earned 500 total points
ID: 33707455
1. According route table on Loc1
C   191.168.0.0/24 is directly connected, Vlan10  ---> VLAN 10 has IP: 191.168.0.1/24 (not /16)
S   191.168.0.0/16 [1/0] via 10.1.0.2                    ---> you have static route for 191.168.0.0/16 toward Loc2 --- this is not OK
And on Loc2
S   191.168.0.0/16 [1/0] via 10.1.1.2                     ----> you have static route for 191.168.0.0/16 toward Loc1
C   191.169.1.0/24 is directly connected, Vlan10   ----> VLAN 10 has IP: 191.169.1.1/24
What subnets do you have on both locations?
IP range 191.0.0.0/8 should not be used for private addressing. http://tools.ietf.org/html/rfc1918
You should use IP addresses from subnets:
     10.0.0.0 - 10.255.255.255  (10/8 prefix)
     172.16.0.0 - 172.31.255.255  (172.16/12 prefix)
     192.168.0.0 - 192.168.255.255 (192.168/16 prefix)
2. If you want to connect more than one 3750 on each location, then assign IP addresses to VLANS only on one 3750 on the location, and don't assign IP addresses on VLANs on other 3750s. Use VLAN IP as default gateway for your PCs.
Another possibility is to stack your 3750s on the location, so they will function as one big L2/L3 switch. http://www.cisco.com/en/US/prod/collateral/switches/ps5718/ps5023/prod_white_paper09186a00801b096a.html
 
0
 

Author Comment

by:hayesie
ID: 33708737
Thanks bjove, it is up and running....feel foolish missing the VLAN mask mistake, but sometimes it takes fresh eyes to see the issue.
0

Featured Post

Free camera licenses with purchase of My Cloud NAS

Milestone Arcus software is compatible with thousands of industry-leading cameras for added flexibility. Upon installation on your My Cloud NAS, you will receive two (2) camera licenses already enabled in the software. And for a limited time, get additional camera licenses FREE.

Join & Write a Comment

This article is focussed on erradicating the confusion with slash notations. This article will help you identify and understand the purpose and use of slash notations. A deep understanding of this will help you identify networks quicker especially w…
There are times where you would like to have access to information that is only available from a different network. This network could be down the hall, or across country. If each of the network sites have access to the internet, you can create a ne…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

16 Experts available now in Live!

Get 1:1 Help Now