Solved

ping with source specified

Posted on 2014-03-27
6
433 Views
Last Modified: 2014-04-08
When I ping the remote site from my core switch, it does not work. But when I specify "source vlan 10", it works. Why is that?
0
Comment
Question by:leblanc
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
  • 2
6 Comments
 
LVL 9

Accepted Solution

by:
rfportilla earned 167 total points
ID: 39960320
Because whichever vlan the switch is using by default does not have access to the Internet, but VLAN 10 does.  Are you familiar with VLAN's?  They are used to segment traffic like a router.
0
 
LVL 1

Author Comment

by:leblanc
ID: 39960540
My layer 3 core switch has a default route pointed to the distribution WAN layer 3 switch, then to the FW to access the internet. I have SVIs configured on my core switch. I believe all of my VLAN can access the Internet.
I did not have to specify the source vlan with the ping before I moved from layer 2 to layer 3 between the core switch and the distribution WAN layer 3 switch.
0
 
LVL 57

Assisted Solution

by:giltjr
giltjr earned 333 total points
ID: 39960664
What IP address does your L3 core use by default?

Maybe your WAN L3 switch or your firewall does not have a route back to that address/subnet?
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 1

Author Comment

by:leblanc
ID: 39960679
On my L3 core, my default route is pointed to the next hop /30 of the WAN distribution L3 switch interface. All subnets are /24.
0
 
LVL 9

Expert Comment

by:rfportilla
ID: 39961338
I don't know your switch.  Is there a command to determine the default network interface and/or vlan?  I think there might be a default vlan that is used internally that might be default in the management if.  I've seen many switches with extra interfaces and vlans that don't seem like they are needed, but they exist (and not always easily visible).  

In either case, is this just a curiosity or is there an issue stemming from this?
0
 
LVL 57

Assisted Solution

by:giltjr
giltjr earned 333 total points
ID: 39961362
Assuming your setup is like:

CORE-L3 < -- > WAN-L3 <----> Firewall

Typically a L3 switch (your CORE-L3) will use the IP address of the SVI based on your routing table.  So if you are ping'ing 1.1.1.1, what is the IP address of the router it will use as the next hop.

I would assume that it would be the IP address in CORE-L3 that is on the subnet between CORE-L3 and WAN-L3.

So first thing to check is does the firewall have a route back to that subnet.
Second thing to check is does the firewall have a policy that would allow ICMP to/from that subnet.
0

Featured Post

Manage your data center from practically anywhere

The KN8164V features HD resolution of 1920 x 1200, FIPS 140-2 with level 1 security standards and virtual media transmissions at twice the speed. Built for reliability, the KN series provides local console and remote over IP access, ensuring 24/7 availability to all servers.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

If you're not part of the solution, you're part of the problem.   Tips on how to secure IoT devices, even the dumbest ones, so they can't be used as part of a DDoS botnet.  Use PRTG Network Monitor as one of the building blocks, to detect unusual…
Most of the applications these days are on Cloud. Cloud is ubiquitous with many service providers in the market. Since it has many benefits such as cost reduction, software updates, remote access, disaster recovery and much more.
Viewers will learn how to connect to a wireless network using the network security key. They will also learn how to access the IP address and DNS server for connections that must be done manually. After setting up a router, find the network security…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

730 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question