Can't Assign Static IP on Cisco switch, but DHCP works

I have several stacks of cisco 3750x switches at the school I am working at. Each stack is configured the same, just on different Vlan's.

On one of the stacks I can't assign a static IP address to anything, even though DHCP is working fine. I can pull a DHCP address. and it works, but if I statically assign that address to a laptop it won't work, I have tried multiple ports/ multiple vlans.

this is not a subnet or gateway mistake on my end.

I am attaching the running config for the stack.  

I have tried multiple ports but the most recent was gi4/0/33 It's currently  set to vlan 32, however I had the same problem while it was set to vlan 24.

Thanks for your expertise.
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

NetExpert Network Solutions Pte LtdTechnical SpecialistCommented:
While you assign the static ip address to the workstation, will you able to ping to your gateway ip address?

do you able to see the workstation mac address on the core switch?

Did you hard-coded anything like auto-discover mac address on the core switch ?
sattermcAuthor Commented:
I was not able to ping the gateway address. I did not do a search for the mac address..  nothing like that is hardcoded.  
NetExpert Network Solutions Pte LtdTechnical SpecialistCommented:
Lets troubleshoot the issue for one PC

connect your laptop to the stack switch
assign static ip address to the laptop
check the laptop mac address in both stack switch as well as on the core switch.

if you can't see the mac address on the switch,  remove the port-security command on the switch port and try again
Discover the Answer to Productive IT

Discover app within WatchGuard's Wi-Fi Cloud helps you optimize W-Fi user experience with the most complete set of visibility, troubleshooting, and network health features. Quickly pinpointing network problems will lead to more happy users and most importantly, productive IT.

sattermcAuthor Commented:
not only can't i see the mac address.. port shows not connect. (i never disconnected it) and while the local lan is showing a configured IP the same as the dhcp, when i do an ip config it gives me a 169.x.x.x. address.

I change the nic back to dhcp .. it re-identifys grabs an address and the port shows connected.

it has to be some kind of security setting right ??

current  port configuration

interface GigabitEthernet3/0/33
 description Client Access Port
 switchport access vlan 32
 switchport mode access
 switchport nonegotiate
 switchport voice vlan 25
 ip arp inspection trust
 srr-queue bandwidth share 10 10 60 20
 queue-set 2
 priority-queue out
 mls qos trust device cisco-phone
 mls qos trust cos
 macro description CLIENTPORT | CLIENTPORT
 auto qos voip cisco-phone
 storm-control broadcast level bps 50m 25m
 storm-control multicast level bps 50m 25m
 storm-control action shutdown
 service-policy input AutoQoS-Police-CiscoPhone
NetExpert Network Solutions Pte LtdTechnical SpecialistCommented:
It's pretty much clear that the port security blocking you if you  static ip on the laptop.

If you would like to confirm ,  remove the macro configuration under the interface and try
Craig BeckCommented:
You're not running port-security on the port, so it can't be that.  You are running DAI somewhere though and possibly IP source-guard and DHCP snooping.

On the client switchport you have the ip arp inspection trust parameter configured.  You shouldn't be running this on a client port unless you want to exempt that device from having to have ARP packets inspected.  The client connected to this port should be able to use a static IP address.

If you enter the following at global config on the switch:

no ip arp inspection vlan 32

...what happens?

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
sattermcAuthor Commented:
I have removed the macro and no-change.

I will run the no ip arp inspection vlan 32 on the port first thing tomorrow.

Craig BeckCommented:
Run it in global config, not on the port.
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Switches / Hubs

From novice to tech pro — start learning today.