4500 Not routing a subnet after Reboot -

The issue we're having is that the 4506 doesn't route traffic to one specific subnet properly. Traffic coming from subnet on the 4506 side to on the Nexus side should be routed through the port channel. We have a static ip route entry defining that. What is actually happening is the 4506 is routing traffic to to the gateway of last resort. We can't figure out why.
Attached is the Config from the Nexus and 4506, and also a quick pdf of the topology.
Support EngineerAsked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Don JohnstonInstructorCommented:
I love it when the OP puts up relevant information!!!  Thank you!

First thing that jumps out at me is a discrepancy in the channel (not saying this is the cause, but it's definitely not right).  On the 4506, the allowed VLANs for port channel 50 include VLAN 11. On the N5K, it does not.

To the matter at hand, why do you say that the 4506 is forwarding them to  According to your output, traffic is going to and then dying there.

Are you having any of these problems with any other destinations behind the N5K?
Support EngineerAuthor Commented:
Currently there are not any issues with other destinations just this one. what would your recommendation be?
Don JohnstonInstructorCommented:
I don't see the issue you're describing.

Why do you say that the 4506 is forwarding them to  According to your output, traffic is going to and then dying there.
Price Your IT Services for Profit

Managed service contracts are great - when they're making you money. Yes, you’re getting paid monthly, but is it actually profitable? Learn to calculate your hourly overhead burden so you can master your IT services pricing strategy.

Support EngineerAuthor Commented:
We're thinking that the problem is on the 4506 because traceroutes go from the 4506 to the gateway of last resort. They're not hitting the Nexus. But if you see something that suggests the issue is with the Nexus, we have that on a Cisco maintenance contact and we can contact Cisco.

here is a trace route from each of the two systems

Tracing route to over a maximum of 30 hops

  1     1 ms     2 ms     1 ms
  2     1 ms     1 ms     1 ms  66-193-133-129.static.tw []
  3     *        *        *     Request timed out.
  4     *        *        *     Request timed out.
  5     *        *        *     Request timed out.
  6     *        *        *     Request timed out.
  7     *        *        *     Request timed out.
  8     *        *        *     Request timed out.
  9     *        *        *     Request timed out.
 10     *        *        *     Request timed out.
 11     *        *        *     Request timed out.
 12     *        *        *     Request timed out.
 13     *        *        *     Request timed out.
 14     *        *        *     Request timed out.
 15     *        *        *     Request timed out.
 16     *        *    

Tracing route to ads02.nu.com []
over a maximum of 30 hops:

  1     1 ms     1 ms     1 ms
  2    <1 ms    <1 ms    <1 ms  ads02.nwfcu.com []

Trace complete.
Don JohnstonInstructorCommented:
My confusion comes from your 4506 config post where on the bottom you have:


Type escape sequence to abort.
Tracing the route to

  1 12 msec 8 msec 4 msec
  2  *  *  * 
  3  *  *  * 
  4  *  *  * 

Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to, timeout is 2 seconds:
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms

Open in new window

This shows that it was forwarded to the N5K

So I'm guessing that this latest traceroute was done from a workstation.

To your latest post, it shows a first hop of which is the Virtual IP of an HSRP group.  

interface Vlan30
 ip address
 ip helper-address
 standby 0 ip

Open in new window

But I don't see any other switch that could be on that HSRP group. In fact, there are a bunch of SVI's with HSRP configurations.  So I'm guessing that there's another routing device that is an HSRP peer and maybe that device is misrouting the traffic?

All of this would indicate that pings from the 4506 work connectly but from a workstation they do not.  Which would lead me to think that this has something to do with HSRP.

Please post the output of a "show standby brief" from the 4506.
Support EngineerAuthor Commented:
4506-01#sh standby brief
                     P indicates configured to preempt.
Interface   Grp  Pri P State   Active          Standby         Virtual IP
Vl3         0    100   Active  local           unknown
Vl5         0    100   Standby      local 
Vl10        0    90    Standby     local 
Vl15        0    100   Active  local 
Vl16        0    100   Standby     local 
Vl20        0    90    Standby     local 
Vl25        0    100   Active  local 
Vl29        0    100   Init    unknown         unknown
Vl30        0    100   Standby     local 
Vl35        0    100   Active  local 
Vl40        0    90    Active  local 
Vl45        0    100   Active  local 
Vl50        0    90    Active  local           unknown
Vl70        0    100   Active  local 
Vl95        0    100   Active  local           unknown
Vl100       0    100   Active  local 
Vl102       0    100   Active  local 
Vl139       0    100   Active  local           unknown
Vl192       0    100   Active  local 
Vl200       0    100   Active  local           unknown
Vl900       0    100   Active  local 
Vl901       0    100   Active  local 
Vl902       0    100   Active  local 
Don JohnstonInstructorCommented:
Yep, there's your problem... at least a clue as to the problem.

Interface   Grp  Pri P State   Active          Standby         Virtual IP
Vl30        0    100   Standby     local 

Open in new window

Traffic from the network is being forwarded by the device.  Whatever that is.

Check the routing table, route maps, PBR, etc. on that device to why it's forwarding the traffic to the internet.

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today

From novice to tech pro — start learning today.