Cisco 3560G to 2811 Router through OPT-E-Man Multilink

Posted on 2013-06-06
Last Modified: 2013-06-11
First OPT-E-Man circuit, no tagging.  I can not ping across the router to the switch, I know it has to be something simple I am missing please help me spot it.

:::: 3560G ::::

class-map match-all IP
  match access-group 100
class-map match-all OPT_E_MAN_TRUNK
  match input-interface  GigabitEthernet0/45

policy-map VLAN601-POLICER
    police 10000000 750000 exceed-action drop
policy-map VLAN601-PARENT
  class IP
   set ip precedence 1
   service-policy VLAN601-POLICER

interface GigabitEthernet0/45
switchport trunk encapsulation dot1q
switchport mode trunk
duplex full
speed 100
mls qos vlan-based

interface Vlan601
ip address
service-policy input VLAN601-PARENT

ip route

access-list 100 permit ip any any

Open in new window

:::: 2811 :::: (typing this out so some things will be abbreviated)

class-map match-any VLAN601
match access-group 1

policy-map TRACKER
class VLAN601

int FE0/0
ip address
duplex full
speed 100
service-policy input TRACKER

interface FE0/1
no ip address
duplex full
speed auto

interface FE0/1.1
encapsulation dot1q 1 native 
 ip address

int FE 0/1.2
encap dot1q 2
ip address

ip route

access-list 1 permit any

Open in new window

So I have VLAN 601 as the VLAN of choice for all of my traffic between this router and switch.  On the router side of things it will have 5 local vlans for various types of traffic (I only listed 2 because you get the picture without me boring you to death).

I have the OPT-E-Man circuit plugging into 3560G on gig0/45, and on the 2811 on fe0/0.  While logged into the 2811 via console, I can not ping across to

Thanks for the assistance.
Question by:Todd_Bain
  • 3
  • 2
LVL 20

Expert Comment

ID: 39227165
On the switch the native vlan on a trunk is, by default, 1. Since you have vlan 601 defined with the IP address, that traffic is actually hitting the opteman with vlan 601 tagged. the router is using untagged traffic currently

you can do this one of two ways.

int gig0/45
sw trunk native vlan 601


configure the router interface fe0/0 to have subinterfaces with one being fe0/0.601 tagging vlan 601.

Going the switch method is the easiest for now, but the router subinterface gives you more options for the future as you can easily add additional subinterfaces/vlans as needed across the opteman.

Author Comment

ID: 39227192
Thank you for the update, I originally thought that is what I did wrong so I put in

int fe0/0
no ip address
speed 100
duplex full

int fe0/0.601
ip address
encap dot1q 601 native
service-policy input TRACKER

Open in new window

But still had no joy.  I will definitely put it back in come Monday of next week when I can get back out to the location and see if I can at least talk across (maybe I had something else goofy that I just didn't see).

And I agree I would love to native the switch but I can't because that one port will (just like you said) eventually be shooting out to VLAN 602, 603 and 604 based upon other physical router locations.  This is just my first one to hit.

Thanks for the update, again will try this next week and update if it solved or not.
LVL 20

Accepted Solution

rauenpc earned 500 total points
ID: 39227207
the way the switch is configured, vlan 1 is the native/untagged vlan. With the subinterface you made you did define vlan 601 but made that the native/untagged vlan. This means that fe0/0.601 actually hits vlan 1 at the switch because untagged packets only know one thing - that they're untagged. You can set the native vlan on a switch to any vlan you want and you will still be able to pass tagged traffic on other vlans. Right now you need to do one of two things but not both:

int fe0/0.601
encap dot1q 601
!do not include the 'native' keyword


int gig0/45
sw trunk native vlan 601

Since you've already done the subinterface on the router I would go with the first option personally.

also, do a "show int trunk" on the switch and make sure that vlan 601 shows as "forwarding and not pruned". If it's not forwarding, you probably just to enter the command "vlan 601" from global config and then wait a minute and run the "show int trunk again".

Author Comment

ID: 39227273
Thank you very much, that definitely helps me.  What you said does make sense to me now *duh I should have saw that* and I am betting come Monday this will get me fixed up.

Thank you again, I do appreciate it.  Gives me something to look forward to for next week!

Author Closing Comment

ID: 39237811
Drove out Monday to the site and it still didn't work, so brought the router back with me plugged a CAT5 cable to it and the switch (to eliminate the OPT-E-MAN Circuit) and worked just like it should.

So the config is good now it is just figuring out the OPT-E-MAN Circuit from ATT, thank you again.

Featured Post

Live: Real-Time Solutions, Start Here

Receive instant 1:1 support from technology experts, using our real-time conversation and whiteboard interface. Your first 5 minutes are always free.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Sonicwall TZ 205- Dropping Incoming E-mail as IP Spoof 13 161
Problem to router 7 51
Setting up static routes to  sonicwll 4 27
While it is possible to put two routes in place with the secondary having a higher metric, this may not always work. In the event of a failure that does not bring down the physical interface on the router the primary route is not removed. There is a…
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

813 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now