Cisco configuration on L2 WAN links

Posted on 2015-02-18
Last Modified: 2015-04-09
Hi Guys

We recently have a layer 2 service put in between multiple sites.

We have setup a range on the router (eg. Router 1 -, Router 2 -, Router 3 - etc)

At the main site, we have set to (This is the cisco device, our core switch).

We are not able to ping each other for some reason. Unsure if this is the configuration issue or our WAN provider.

Can anyone advise?

Question by:goraek
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 3
  • 2
  • +1
LVL 18

Expert Comment

ID: 40618249
You may want to check with your ISP.

What type of connection do you have between the sites?

The only way your setup will work is if you have direct layer 2 connection between the sites (Ethernet Handoff)
If not, you will need layer 3 switches or routers, but then you'll have to use separate vlans at each site
LVL 29

Expert Comment

by:Predrag Jovic
ID: 40618313
Of course that does not work. ISP must block any private IP on internet - it is mandatory. Check with your ISP for possibilities.

Maybe you can use Cisco L2 over L3

Author Comment

ID: 40618354
We have a Layer 2 connection between sites. Its basically an ethernet handoff.
There's no routing, so long we have a vlan setup and route them, we should be able to see it.

We have checked with them, and they say they can see MAC addresses flowing.

We have a Sonicwall at remote site, and a Cisco core switch. Obviously theres the NTU for bridging.

Unsure whats going on. Could be configuration issue? But cant seem to track it.
Webinar: Aligning, Automating, Winning

Join Dan Russo, Senior Manager of Operations Intelligence, for an in-depth discussion on how Dealertrack, leading provider of integrated digital solutions for the automotive industry, transformed their DevOps processes to increase collaboration and move with greater velocity.

LVL 18

Assisted Solution

Akinsd earned 250 total points
ID: 40620851
Does VTP work? (Are the vlans propagated to the switches or did you create them manually on all switches)
What is allowed on the trunk ports?

It's also possible that what you have is Private Transport.
The ISP assigns a VLAN (transparent to your devices but configured on the firewall or edge router) for traffic redirection.
You will need a L3 switch at the remote sites for this though.

Check with your ISP and they can tell you if your setup can work or not.
If VTP does not work, then you will need separate vlans at remote sites

Accepted Solution

Daniel Sheppard earned 250 total points
ID: 40621460
As you are saying Layer 2 (without defining exactly what service your ISP is providing: MPLS, VPLS, Metro Ethernet) here are a couple of questions:

- Is it a straight VLAN (You may need to tag all traffic on that VLAN) or is it QinQ?
- Check your MTU with your ISP, ping should work but when using QinQ I did have to drop the MTU by about 8 bytes (for one site only due to a third party backhaul for the ISP).
- Not strictly related to this, but when configuring our private MPLS, I ran into a problem with Multicast traffic being blocked (EIGRP would start the handshake but not fully come up).  Again, not strictly related but something to ensure.

If you only have a straight VLAN, it may be expecting the "native" VLAN (untagged traffic) or a specific tagged VLAN.  If this is the case, get your ISP to migrate to Q-in-Q (VLAN tunnelling).

Author Comment

ID: 40624911
Cool thanks, I've contacted the ISP, and its been escalated to their network engineer.

I'll keep you guys posted.

Author Comment

ID: 40714351
There was an issue with the ISP, VLAN wasnt configured at their end.

Author Comment

ID: 40714688
I've requested that this question be closed as follows:

Accepted answer: 0 points for goraek's comment #a40714351

for the following reason:

Resolved, ISP end.

Expert Comment

by:Daniel Sheppard
ID: 40714689
I pointed him to the ISP...

Expert Comment

by:Daniel Sheppard
ID: 40714718
Rather both myself and Akinsd pointed towards the ISP.  For differing reasons, but still points should be awarded.

Featured Post

Enroll in May's Course of the Month

May’s Course of the Month is now available! Experts Exchange’s Premium Members and Team Accounts have access to a complimentary course each month as part of their membership—an extra way to increase training and boost professional development.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Voice VLANs across Metro-E 4 52
Objects in Cisco ASA 2 57
Cisco 3650x ACL 8 51
Cisco ACS Adding Root and Intermediate Certs 2 64
Data center, now-a-days, is referred as the home of all the advanced technologies. In-fact, most of the businesses are now establishing their entire organizational structure around the IT capabilities.
Shadow IT is coming out of the shadows as more businesses are choosing cloud-based applications. It is now a multi-cloud world for most organizations. Simultaneously, most businesses have yet to consolidate with one cloud provider or define an offic…
After creating this article (, I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
As a trusted technology advisor to your customers you are likely getting the daily question of, ‘should I put this in the cloud?’ As customer demands for cloud services increases, companies will see a shift from traditional buying patterns to new…

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question