Interconnect Cisco 2960 and HP 5412
Posted on 2011-10-21
We are working on a Pix removal project. Time to retire the old pix and move to the hosted ASA at my ISP.
We are having an interconnect issue between the HP and the Cisco. My ISP is trying to hand me 2 ports on the 2960 (DMZ and Private)
We are connecting VLAN 2 (DMZ port L23) to port 6 on the Cisco with no problems.
We cannot get the VLAN3 (Private port L21) to port 5 on the Cisco to link. Starts amber 30 seconds, green for about 8 then back to amber. The light blinks like it is passing traffic but it is not. The HP is green and thinks it is up.
Vlan 2 DMZ on the HP side has no routes, just a simple class c with 5 devices.
VLAN 3 is routed and also has a seperate subnet on it. Internal routes stay up the entire time.
We have tried all the easy stuff. Patch cables, speeds, duplex, different ports, Different Cisco, Flow control, Spanning tree. Reboot, Clear Arps
These are not trunk ports. Untagged traffic only on both sides. If we hard IP a laptop and connect it to either port (Cisco or HP) it will talk to the network it is connected to. Link the HP and Cisco and nada.
Running configuration: (Ports are coded 100 full below since we are back on the old pix.)
; J8698A Configuration Editor; Created on release #K.14.60
hostname "ProCurve Switch 5412zl"
time timezone -300
time daylight-time-rule Continental-US-and-Canada
ip access-list extended "management"
10 permit ip 10.126.1.50 0.0.0.0 10.1.252.0 0.0.0.255
15 permit ip 10.1.252.0 0.0.0.255 10.1.252.0 0.0.0.255
20 deny ip 10.126.0.0 0.0.255.255 10.1.252.0 0.0.0.255
30 deny ip 10.128.0.0 0.0.255.255 10.1.252.0 0.0.0.255
module 1 type J8702A
module 2 type J8706A
module 3 type J8702A
module 4 type J8702A
module 9 type J8702A
module 11 type J9307A
module 12 type J8702A
name "IT IDF"
name "BAT IDF"
name "CAD IDF"
name "EE IDF"
name "Admin Office"
name "8e6 reply"
name "Firewall Inside"
name "8e6 Mobile"
name "DMZ Firewall"
name "VLAN1 MGMT"
ip default-gateway 10.126.0.1
ip address 10.1.252.5 255.255.255.0
no untagged A1-A24,C1-C24,I1-I24,K1-K24,L1-L23
ip access-group "management" out
no ip address
ip address 10.126.1.3 255.255.0.0
ip address 10.128.0.1 255.255.0.0
no ip address
no ip address
mirror 1 port L19
sntp server priority 1 10.126.1.101 3
ip authorized-managers 10.126.1.50 255.255.255.255 access manager
ip authorized-managers 10.126.1.51 255.255.255.255 access manager
ip authorized-managers 10.126.1.16 255.255.255.255 access manager
ip timep manual 10.126.1.25
ip route 0.0.0.0 0.0.0.0 10.126.0.1
ip route 10.129.0.0 255.255.0.0 10.126.0.1
ip route 172.31.252.0 255.255.255.0 10.126.0.1
monitor all both mirror 1