?
Solved

VLAN not passing through

Posted on 2011-10-24
12
Medium Priority
?
899 Views
Last Modified: 2012-05-12
We are having problems configuring VLANs on our networking switches. Clients on VLAN 50 and VLAN 60 can ping between each other but cannot go out to the internet.  Clients directly on root switch receive a DHCP address from the firewall and can go out to the internet. The clients on the far switches are not receiving a DHCP address. The switches we are using are Brocade FastIrons. Any help is greatly appreciated. I will attach a network diagram. VLAN-Issues.pdf
0
Comment
Question by:RAFF-
  • 4
  • 3
  • 2
  • +3
12 Comments
 
LVL 9

Expert Comment

by:sshah254
ID: 37022092
Presuming that you have reset all the switchtes.

Can client B and C ping client A?  Can they ping the firewall 10.25.0.1?

If not, then the traffic is not going from VLANs to the firewall, and I would troubleshoot that.  Maybe removing the VLANs could help in troubleshooting.

If yes, then you have a weird problem.  I would remove the VLANs and see if the plain switches allow traffic to get to the firewall.

SS
0
 

Expert Comment

by:willie959
ID: 37022583
client B and C can ping each gateway on the core switch  but not the firewall. Client C is an untagged port on the core switch, so it's not going to be able to ping any other client. The core switch (console) can ping the firewall and the internet. Clients untagged in the same vlan as the port that is connected to the firewall are able to go online okay, that's the same as removing the vlans. Removing the vlans probably would fix the issue, but it's not an option. Inter-VLAN routing is okay. Port to firewall is set as Dual (Native VLAN), Default network is set as 0.0.0.0 0.0.0.0 10.25.0.1/22.
0
 
LVL 6

Expert Comment

by:RootsMan
ID: 37023785
Can you ping clients B and C from the firewall?
Can you do a tracert to the firewall from clients B and C to see how far they get?
0
Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

 
LVL 2

Expert Comment

by:adrianuta2004
ID: 37024163
link between firewall and main switch is in trunk mode ? vlans 50 and 60 are allowed on that trunk ?
0
 
LVL 6

Expert Comment

by:penguinjas
ID: 37025086
What device is doing the routing on your network?  Is it a layer 3 switch or is the firewall expected to route traffic and are you using static routes?

If your core switch is a layer 3 switch and does routing I'm assuming you have a default route like 0.0.0.0 0.0.0.0 10.25.0.1 configured.

Look into the core switch setting under the vlans 50 and 60 and verify you have a dhcp helper address configured to allow the DHCP traffic from the firewall to reach the vlans.  If you want to post teh model of the core switch I could help you find the commands necessary.

On the firewall you would need a static route for vlan 50 and 60 basically something like 10.50.0.0/22 GW: (Core IP Addres) and 10.60.0.0/22 GW: (Core IP Address).

Again this is assuming your core is handling routing.
0
 

Expert Comment

by:willie959
ID: 37028277
Link between firewall and main switch is tagged (which is the same as a Cisco trunk). 50 and 60 allowed.

Yes, core switch is layer 3 and does the routing. There are static routes. Yes a default route is defined 0.0.0.0 0.0.0.0 10.25.0.1.

No dhcp helper address needed. The switch the dhcp server to each network 50 and 60. DHCP works. When you connect to an access point or a hardware on an access layer switch (or anywhere), you get the correct DHCP address from that network.  The client can ping other networks and other clients on that network, but not the default g/w (10.25.0.1) or beyond (internet).

I'm going to check the routing on the firewall and get back. (Cisco ASA 5505).
0
 
LVL 6

Expert Comment

by:penguinjas
ID: 37028380
I have a similar setup. Create static routes on the ASA.


static-route-asa.pdf
0
 

Author Comment

by:RAFF-
ID: 37037575
We have created static routs on the ASA and still cant get it to work. Attched are our config files for the ASA and L3 switch. ASA.txt MDF-L3-Switch.txt IDF.txt
0
 
LVL 6

Expert Comment

by:penguinjas
ID: 37038000
With the addition of the routes at the firewall are you now able to ping from clients B or C to the firewall?

I don't understand this "Link between firewall and main switch is tagged (which is the same as a Cisco trunk). 50 and 60 allowed."  Since your core switch does routing, trunking multiple vlans to the firewall is unnecessary.  The core will forward the traffic to the firewall regardless since there is a route configured and with the return route in the firewall responses are returned to the core.

Also, I didn't see a NAT for traffic on the 10.50 or 10.60 networks in your firewall config.  
0
 

Author Comment

by:RAFF-
ID: 37048199
Penquinjas, I've added a static NAT for both 10.50.0.1 and 10.60.0.1 to the Inside interface. This is where we are at right now. Users with a 10.25.0.x address from the firewall are able to go out to the internet and ping clients on both 10.50.0.x and 10.60.0.x. Clients on 10.50.0.x and 10.60.0.x can ping each other but can not ping anything else nor go out to the internet. If I do a trace route from the switch to yahoo.com, it goes out successfully. Any ideas?
0
 
LVL 6

Accepted Solution

by:
penguinjas earned 1500 total points
ID: 37066242
Ok so looking at your MDF config.

Why is this destination 10.50.0.1?  In the visio file you added the switch IP at the edge is 10.50.0.2?
ip route 10.50.0.0 255.255.248.0 10.50.0.1 - why not 10.50.0.0 255.255.248.0 10.50.0.2?

Why are you sending everything else to 192.168.6.1?  
ip route 0.0.0.0 0.0.0.0 192.168.6.1  

Why is this here?
ip route 10.21.0.0 255.255.252.0 192.168.6.1

Why is this here?
ip route 10.50.0.0 255.255.248.0 192.168.6.1

Why is this here?
ip route 10.60.0.0 255.255.248.0 192.168.6.1

What is at 10.25.0.99 and why route 10.25.0.0 traffic to it?
ip route 10.25.0.0 255.255.252.0 10.25.0.99

Again why is this here?
ip route 0.0.0.0 0.0.0.0 10.25.0.99

Why is this here?
ip route 10.60.0.0 255.255.252.0 10.25.0.99

Why is this here?
ip route 10.50.0.0 255.255.252.0 10.25.0.99

This route is correct assuming your firewall IP is 10.25.0.1
ip route 0.0.0.0 0.0.0.0 10.25.0.1

From what I can see these routes would fix the MDF switch to edge switch assuming the edge switches are also layer 3 switches.  If they aren't then this is a combination routing vlan problem, not just routing.  If you can answer some of the other questions about the routes above and why they exist I could offer more.

ip route 10.60.0.0 255.255.255.252 10.60.0.2
ip route 10.50.0.0 255.255.255.252 10.50.0.2
ip route 0.0.0.0 0.0.0.0 10.25.0.1

Sorry for the delay in response, busy weekend.

0
 

Author Closing Comment

by:RAFF-
ID: 37089184
We have figured out our problem. The switch was used from a previous production environment and placed in this test lab with the configurations inherited. Once the switch was reloaded and reconfigured, we go the switch to do what we need it to do. We also found that the ASA5505 was not licensed for VLAN trunking and replaced it with a Juniper firewall. Thanks for all the help.
0

Featured Post

Independent Software Vendors: We Want Your Opinion

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Use of TCL script on Cisco devices:  - create file and merge it with running configuration to apply configuration changes
In this article, the configuration steps in Zabbix to monitor devices via SNMP will be discussed with some real examples on Cisco Router/Switch, Catalyst Switch, NAS Synology device.
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…
Suggested Courses
Course of the Month16 days, 6 hours left to enroll

850 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question