Can't reach enclave switch on the MNGT network.

Created an enclave (192.168.170.0/24) on our office network using a Cisco 2921 and overload NAT to the ISP Firewall (192.168.168.1).  The enclave NAT works OK but I can't get the management network (10.10.10.0/27) out to the switch in the enclave.  I can't ping 10.10.10.11 even from the CORE switch.

See the attached diagram.  MNGT 10.10.10.0/27  OFFICE 192.168.168.0/24  ENCLAVE 192.168.170.0/24

  Network_Diagram.jpg
huffmanaSystem Admin and Network EngineerAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Soulja53 6F 75 6C 6A 61 Commented:
When you ping from the enclave router to 10.10.10.11, are you sourcing the ping from the enclave mgmt interface?
0
Andy BartkiewiczNetwork AnalystCommented:
I believe you are having issues because of a Native vlan mismatch on 7 and 8. You've got vlan 200 as the native on 8 and vlan 1 as the native on 7.
0
huffmanaSystem Admin and Network EngineerAuthor Commented:
$ ssh user@10.10.10.10
C
UNAUTHORIZED ACCESS TO THIS DEVICE IS PROHIBITED
You must have explicit, authorized permission to access or configure this device.
Unauthorized attempts and actions to access or use this system may result in civil and/or criminal penalties.
All activities performed on this device are logged and monitored.
Password:

guestrtr1>en
Password:
guestrtr1#ping 10.10.10.11 source 10.10.10.10
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.10.10.11, timeout is 2 seconds:
Packet sent with a source address of 10.10.10.10
.....
Success rate is 0 percent (0/5)
guestrtr1#
0
Determine the Perfect Price for Your IT Services

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden with our free interactive tool and use it to determine the right price for your IT services. Download your free eBook now!

Andy BartkiewiczNetwork AnalystCommented:
Also you've got interface 9 setup as a trunk when I think it's supposed to be access
0
Steven CarnahanNetwork ManagerCommented:
What is the result of a trace route from the core switch to 10.10.10.11?
0
huffmanaSystem Admin and Network EngineerAuthor Commented:
Tried the trunks with native 200 on both sides and with native 1 on both sides.... And it still doesn't ping....  How can the broadcast domain get interrupted between two switches connected by a trunk?  Maybe the vlans aren't allocated....
0
huffmanaSystem Admin and Network EngineerAuthor Commented:
Int 9 is working as a trunk.  I thought that it would be more secure than a mode access....  I think that the Firewall is tagging it's port as vlan 200.  I don't have access to the Meraki router :-(  I'm afraid to change it....
0
Soulja53 6F 75 6C 6A 61 Commented:
From the core switch vlan 200 can you ping the etherswitch vlan 200? Also, have you confirmed the vlan interface on the etherswitch module is up? Sometime an interface on the switch needs to be assigned in the same vlan for vlan svi to come up.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
huffmanaSystem Admin and Network EngineerAuthor Commented:
Got it, there was a port monitoring I forgot about!!!! All I had to do was look at UP/DOWN.

How stupid can I be - ignoring the obvious....

Thank you everyone....
0
Andy BartkiewiczNetwork AnalystCommented:
Well your not tagging vlan 200 to the router, its native. That's probably why its working. I don't think thats more secure however. Are the vlans defined on both the core and etherswitch?
0
huffmanaSystem Admin and Network EngineerAuthor Commented:
It is so much appreciated to have these professional help me out.  They are invaluable.
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Cisco

From novice to tech pro — start learning today.