Cannot ping the gateway

Hi
Network:
One firewall where the IP address is the gateway for all the internal computers and server
From one if the internal computers I can ping the the gateway
From the server I can ping all the internal computers but I cannot ping the gateway
On the server I can ping:
-  127.0.0.1, 
- the IP address on the server
- All the internal computers
A hint would be nice
Best Regards
John B

Arp -a
Interface: 10.0.0.2 on Interface 0x1000003
  Internet Address      Physical Address      Type
  10.0.0.1              10-7b-ef-3a-58-09     dynamic  
  10.0.0.26             00-01-e6-b4-e1-fe     dynamic  
Ipconfig /all
Windows 2000 IP Configuration
 Host Name . . . . . . . . . . . . : krogh01
 Primary DNS Suffix  . . . . . . . : Krogh.local
 Node Type . . . . . . . . . . . . : Hybrid
 IP Routing Enabled. . . . . . . . : No
 WINS Proxy Enabled. . . . . . . . : No
 DNS Suffix Search List. . . . . . : Krogh.local
Ethernet adapter Inside:
 Connection-specific DNS Suffix  . :
 Description . . . . . . . . . . . : HP NC7760 Gigabit Server Adapter
 Physical Address. . . . . . . . . : 00-0B-CD-1C-7C-D9
 DHCP Enabled. . . . . . . . . . . : No
 IP Address. . . . . . . . . . . . : 10.0.0.2
 Subnet Mask . . . . . . . . . . . : 255.255.255.0
 Default Gateway . . . . . . . . . : 10.0.0.1
 DNS Servers . . . . . . . . . . . : 10.0.0.2
                                     212.242.40.3
                                     212.242.40.51
Ping 10.0.0.1
Pinging 10.0.0.1 with 32 bytes of data:
Request timed out.
Request timed out.
Request timed out.
Request timed out.
Ping statistics for 10.0.0.1:
    Packets: Sent = 4, Received = 0, Lost = 4 (100% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum =  0ms, Average =  0ms
Ping 10.0.0.26
Pinging 10.0.0.26 with 32 bytes of data:
Reply from 10.0.0.26: bytes=32 time=1ms TTL=64
Reply from 10.0.0.26: bytes=32 time<10ms TTL=64
Reply from 10.0.0.26: bytes=32 time<10ms TTL=64
Reply from 10.0.0.26: bytes=32 time<10ms TTL=64
Ping statistics for 10.0.0.26:
    Packets: Sent = 4, Received = 4, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum =  1ms, Average =  0ms
I can ping every computer on internal network without any problems, it is only the gateway I have problem with.
I have now made a ping session from a computer on the internal network:
Microsoft Windows [version 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. Alle rettigheder forbeholdes.
C:\Users\lh>ipconfig /all
Windows IP-konfiguration
   Værtsnavn. . . . . . . . . . . . . . . . . . : NUC-lone
   Primært DNS-suffiks. . . . . . . . . . . . . : Krogh.local
   Nodetype . . . . . . . . . . . . . . . . . . : Hybrid
   IP-routing aktiveret . . . . . . . . . . . . : Nej
   WINS-proxy aktiveret . . . . . . . . . . . . : Nej
   Søgeliste for DNS-suffiks. . . . . . . . . . : Krogh.local
Ethernet-netværkskort LAN-forbindelse:
   Forbindelsesspecifikt DNS-suffiks. . . . . . :
   Beskrivelse. . . . . . . . . . . . . . . . . : Intel(R) Ethernet Connection I
218-V
   Fysisk adresse . . . . . . . . . . . . . . . : C0-3F-D5-61-7A-3A
   DHCP aktiveret . . . . . . . . . . . . . . . : Ja
   Automatisk konfiguration aktiveret . . . . . : Ja
   Link-local-IPv6-adresse . . . . . : fe80::5c7a:dcbe:f8:7de7%11(Foretrukken)
   IPv4-adresse . . . . . . . . . . . . . . . . : 10.0.0.113(Foretrukken)
   Undernetmaske. . . . . . . . . . . . . . . . : 255.255.255.0
   Rettigheden opnået . . . . . . . . . . . . . : 12. december 2014 03:15:59
   Rettigheden udløber. . . . . . . . . . . . . : 19. december 2014 08:05:30
   Standardgateway. . . . . . . . . . . . . . . : 10.0.0.1
   DHCP-server. . . . . . . . . . . . . . . . . : 10.0.0.1
   DHCPv6 IAID . . . . . . . . . . . : 247480277
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1B-40-6D-C9-C0-3F-D5-61-7A-3A
   DNS-servere. . . . . . . . . . . . . . . . . : 10.0.0.2
212.242.40.3
212.242.40.51
   NetBIOS over Tcpip . . . . . . . . . . . . . : Aktiveret
Tunnel-netværkskort isatap.{B46FAFD6-A60A-48D9-967D-4081FAE7F6AE}:
   Medietilstand. . . . . . . . . . . . . . . . : Mediet afbrudt
   Forbindelsesspecifikt DNS-suffiks. . . . . . :
   Beskrivelse. . . . . . . . . . . . . . . . . : Microsoft ISATAP-netværkskort
   Fysisk adresse . . . . . . . . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP aktiveret . . . . . . . . . . . . . . . : Nej
   Automatisk konfiguration aktiveret . . . . . : Ja
Tunnel-netværkskort Teredo Tunneling Pseudo-Interface:
   Medietilstand. . . . . . . . . . . . . . . . : Mediet afbrudt
   Forbindelsesspecifikt DNS-suffiks. . . . . . :
   Beskrivelse. . . . . . . . . . . . . . . . . : Teredo Tunneling Pseudo-Interf
ace
   Fysisk adresse . . . . . . . . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP aktiveret . . . . . . . . . . . . . . . : Nej
   Automatisk konfiguration aktiveret . . . . . : Ja
C:\Users\lh>ping 10.0.0.1
Pinger 10.0.0.1 med 32 byte data:
Svar fra 10.0.0.1: byte=32 tid=1ms TTL=64
Svar fra 10.0.0.1: byte=32 tid=1ms TTL=64
Svar fra 10.0.0.1: byte=32 tid=1ms TTL=64
Svar fra 10.0.0.1: byte=32 tid=1ms TTL=64
Ping-statistikker for 10.0.0.1:
    Pakker: Sendt = 4, modtaget = 4, tabt = 0 (0% tab),
Beregnet tid for rundtur i millisekunder:
    Minimum = 1ms, Maksimum = 1ms, Gennemsnitlig = 1ms
C:\Users\lh>
A hint would be nice :-)
Best Regards
John B

Similar Messages

  • I can SSH from the outside but cannot ping ISP gateway from 2911

    Hello all,
    I came across a rather strange issue. I am able to SSH to the device from my home but while I am consoled in, I cannot ping the ISP gateway or any other IP's. As expected, all trace-routes fail without hitting the gateway as the first hop. I have been reading about the NVI0 interface and I decided to use it. Most of the sample cofigs on here use the "old" ip nat inside / outside on the appropriate interfaces. What do you guys suggest?
    Here is the running config. It is rather simple since i did not add all the access-lists except the ones I thought necessary to test the circuit. Please point out any mistakes or errors. Thanks in advance!
    Current configuration : 1679 bytes
    ! Last configuration change at 04:05:17 UTC Fri Sep 12 2014
    version 15.1
    service timestamps debug datetime msec
    service timestamps log datetime msec
    no service password-encryption
    hostname StandbyGZ-2911
    boot-start-marker
    boot-end-marker
    enable secret 5 $1$BRaM$igChPMXLeHjgYR7EGk/Nb/
    no aaa new-model
    no ipv6 cef
    no ip source-route
    ip cef
    no ip domain lookup
    ip domain name StandbyGZ.local
    ip name-server 211.136.20.203
    ip name-server 211.139.136.68
    multilink bundle-name authenticated
    license udi pid CISCO2911/K9 sn FGL174410H9
    username StandbyGZ secret 5 $1$CXWC$m6kqTGbf0HDLCvkfU7.RA/
    ip ssh version 2
    interface GigabitEthernet0/0
     no ip address
     shutdown
     duplex auto
     speed auto
    interface GigabitEthernet0/1
     description UPLINK TO CHINA MOBILE
     ip address 183.x.x.x 255.255.255.128
     ip access-group REMOTE-ADMIN-ACL in
     no ip redirects
     ip nat enable
     duplex auto
     speed auto
    interface GigabitEthernet0/2
     description CONNECTION TO LAN SWITCH 3650-CORE
     ip address 10.10.1.254 255.255.254.0
     no ip redirects
     ip nat enable
     duplex auto
     speed auto
    ip forward-protocol nd
    no ip http server
    no ip http secure-server
    ip nat source list LAN-NAT-ACL interface GigabitEthernet0/1 overload
    ip route 0.0.0.0 0.0.0.0 183.x.x.x
    ip access-list standard LAN-NAT-ACL
     permit 10.10.0.0 0.0.1.255
    ip access-list extended REMOTE-ADMIN-ACL
     permit tcp host 68.107.195.213 any eq 22 log
    control-plane
    line con 0
     exec-timeout 0 0
     logging synchronous
    line aux 0
    line vty 0 4
     exec-timeout 0 0
     logging synchronous
     login local
     transport input ssh
     transport output ssh
    scheduler allocate 20000 1000
    end
    StandbyGZ-2911# sh ip int br
    Interface                            IP-Address        OK?   Method      Status                  Protocol
    GigabitEthernet0/0         unassigned        YES    NVRAM     administratively  down down
    GigabitEthernet0/1         183.x.x.x             YES    NVRAM     up                         up
    GigabitEthernet0/2         10.10.1.254       YES    NVRAM     up                         up
    NVI0                                 183.x.x.x             YES    unset          up                         up
    StandbyGZ-2911#sh ip route
    Codes: L - local, C - connected, S - static, R - RIP, M - mobile, B - BGP
           D - EIGRP, EX - EIGRP external, O - OSPF, IA - OSPF inter area
           N1 - OSPF NSSA external type 1, N2 - OSPF NSSA external type 2
           E1 - OSPF external type 1, E2 - OSPF external type 2
           i - IS-IS, su - IS-IS summary, L1 - IS-IS level-1, L2 - IS-IS level-2
           ia - IS-IS inter area, * - candidate default, U - per-user static route
           o - ODR, P - periodic downloaded static route, + - replicated route
    Gateway of last resort is 183.233.184.129 to network 0.0.0.0
    S*    0.0.0.0/0 [1/0] via 183.233.184.129
          10.0.0.0/8 is variably subnetted, 2 subnets, 2 masks
    C        10.10.0.0/23 is directly connected, GigabitEthernet0/2
    L        10.10.1.254/32 is directly connected, GigabitEthernet0/2
          183.233.0.0/16 is variably subnetted, 2 subnets, 2 masks
    C        183.x.x.x/25 is directly connected, GigabitEthernet0/1
    L        183.x.x.x/32 is directly connected, GigabitEthernet0/1

    Hi Chris,
    That is what how I am used to configure the NAT, but IOS 12.3 and on introduced interface NVI0, which according to cisco documentation should make applying the NAT statements "easier". IP nat enable has to be enabled on all interfaces and then NVI0 makes the "inside" and "outside" decisions. I was hoping that someone could clarify the real use of that NVI0 interface and if it causes problems. Apparently it cannot be removed from the config. 

  • Clients cannot ping the default gateway when connected to SSID

    Here is my environment,
    My controller is vWLC installed in ESXi which has to vNet Cards configured with all vlans(4095), then it is connected to a 3560 switch with trunk. The configuration of the switch interface is as belows:
    LS3560CG#sh run int fa0/1
    Building configuration...
    Current configuration : 138 bytes
    interface FastEthernet0/1
    description To_WLC
    switchport trunk encapsulation dot1q
    switchport mode trunk
    spanning-tree portfast
    end
    The IP of management interface of WLC is 10.10.10.90, VLAN is 10, DHCP primary is 10.10.10.1 which is in the 3560, the DHCP pool is configured as blows:
    LS3560CG#sh run int fa0/1
    Building configuration...
    Current configuration : 138 bytes
    interface FastEthernet0/1
    description To_WLC
    switchport trunk encapsulation dot1q
    switchport mode trunk
    spanning-tree portfast
    end
    The SSID is BYOD and I can connect the SSID and get the IP address such as 10.10.10.118/24, but for now, i cannot ping 10.10.10.1, but i can ping 10.10.10.90:
    Can anyone help me with this? Thanks

    Hi Scott
    Correct! I have resolved this a few minutes earlier. I have assigned the vSwitch to Promiscuous Mode but forgot to switch it to "Accept", the default value is "Reject"
    Thanks so much!

  • WS2012 cannot access the Gateway/DHCP

    Hi All,
    For some reason by Windows Server 2012 machine cannot access my gateway (router). I got a new modem/router from ATT (NVG589) so I got rid of my dlink DGL4500 router. For some reason my server cannot get an IP from the DHCP off the router (windows
    is currently giving it a private ip address). The dlink gateway was 192.168.0.1 while the new one is 192.168.1.254. I've tried setting a static IP, flushed the dns, set it to automatic and searched online, nothing seems to work. When I hook up the dlink
    again, the server is able to get a ip from it. Am I missing something that i have to specially setup in the NVG589? or is there something on the server I have to change?

    Hi,
    I want to confirm with you -- have you enabled DHCP function and used the router to assign IP address? Or there is a DHCP server on other subnet?
    Do the other devices on the same subnet with the server work well after change the router?
    You have mentioned that assigned statics IP address does not work. Does that mean to ping the DG failed?
    If there is a DHCP server on different subnet and the server can’t obtain IP from it after changing router, check to see if a DHCP relay function is enable on the new router.
    Best Regards,
    Eve Wang
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]
    Would there be a reason why the Server would work with the IP 192.168.0.100 rather than 192.168.1.100?192.168.0.100 uses to be part of my old subnet, but it has changed to 192.168.1.100. All my other computers adjusted properly to the new subnet, but the
    server doesn't...what's up with that?
    Ok for some reason the server doesn't like it when I switch the subnet to 192.168.1.x it only seems to work on the 192.168.0.x subnet.

  • Main Server cannot ping the 2nd server in another location but the 2nd server can ping the main server

       
    I have 3  servers :  Main server, and 2 file servers in another country.
    My main server can only ping the 2nd file server.
    But both of  our 2 file servers from another country can ping the main server.
    In short, I cannot remote to the first file server.
    The settings on both file servers are the same. And I don't have issues in accessing the 2nd file server using the Main server.
    Can somebody have the patience to help me figure out the issue?

    Being able to ping the server does not mean that you remotely access it.
    If you are trying to RDP a server then you need to check that RDP is enabled on the server and that traffic to port 3389 is not blocked or filtered. You can use PortQryUI for checking.
    For testing, you can temporary disable security software running on the servers and try again. Also, check the filtering done on network equipment in between your servers.
    This posting is provided AS IS with no warranties or guarantees , and confers no rights.
    Ahmed MALEK
    My Website Link
    My Linkedin Profile
    My MVP Profile

  • ACE 4700 - Cannot Ping the Alias

    I cannot ping my alias addresses. I can ping the actual interface addresses but not the alias. When I look at the ARP entry on the switch it's connected to for the alias, it comes up INCOMPLETE.
    Below is my config.
    interface gigabitEthernet 1/1
    description Fault Tolerant Port
    ft-port vlan 990
    no shutdown
    interface gigabitEthernet 1/2
    shutdown
    interface gigabitEthernet 1/3
    shutdown
    interface gigabitEthernet 1/4
    switchport trunk allowed vlan 10,112,200,254
    no shutdown
    resource-class RC1
    limit-resource all minimum 20.00 maximum unlimited
    limit-resource sticky minimum 8.00 maximum unlimited
    boot system image:c4710ace-mz.A1_7b.bin
    hostname atl-ace-01
    access-list ALL line 8 extended permit ip any any
    class-map type management match-any PING
    2 match protocol icmp any
    class-map type management match-all SNMP-ALLOW_CLASS
    2 match protocol snmp source-address 10.150.100.202 255.255.255.255
    class-map type management match-any remote_access
    2 match protocol xml-https any
    4 match protocol icmp any
    5 match protocol telnet any
    6 match protocol ssh any
    7 match protocol http any
    8 match protocol https any
    9 match protocol snmp any
    policy-map type management first-match AllowICMP
    class PING
    permit
    policy-map type management first-match SNMP-ALLOW_POLICY
    class SNMP-ALLOW_CLASS
    policy-map type management first-match remote_mgmt_allow_policy
    class remote_access
    permit
    interface vlan 200
    ip address 10.10.200.110 255.255.254.0
    alias 10.10.200.120 255.255.254.0
    peer ip address 10.10.200.111 255.255.254.0
    access-group input ALL
    service-policy input remote_mgmt_allow_policy
    service-policy input SNMP-ALLOW_POLICY
    service-policy input AllowICMP
    no shutdown
    ft interface vlan 990
    ip address 192.168.254.1 255.255.255.0
    peer ip address 192.168.254.2 255.255.255.0
    no shutdown
    ft peer 1
    heartbeat interval 250
    heartbeat count 10
    ft-interface vlan 990
    ip route 0.0.0.0 0.0.0.0 10.10.201.254
    context Exchange-CAS
    allocate-interface vlan 112
    allocate-interface vlan 254
    member RC1
    ft group 1
    peer 1
    priority 200
    peer priority 190
    associate-context Exchange-CAS
    inservice

    Nevermind. I found an old Context on the redundant ACE with overlapping info.

  • Cannot ping the IP of the NET MGT Port

    Dear all,
    I configred the console port of the servers sunfire v440, v210
    v240
    as follow
    netsc_ipaddr =172.17.0.x
    netsc_ipnetmask= 255.255.255.0
    netsc_ipgateway =172.17.0.1
    netsc_tpelinktest="true"
    netsc_dhcp="false"
    I couldn't ping the IP address,
    When I put a cable between the NET MGT port and the switch the light is not on in the switch and climbing in the server
    H\akim

    Not sure what you mean by
    "climbing in the server". But
    the NET-MGMT port is
    10Mbit so if your switch port
    is set to 100-FULL and
    autonegotiation is turned
    off it won't work.
    Or else you have a bad cable
    or switch port, which is actually
    fairly common.

  • Cannot Ping the ACS

    I am unable to ping the ACS solution engine 4.0 from my Win 2003 Server with AD installed. But the ACS can access and ping my Win 2003 server.
    I can also access the ACS Console using the same server through the browser on the 2002 port.
    Wat am i doing wrong.. please help.

    Try this link:
    http://www.cisco.com/en/US/products/sw/secursw/ps5338/products_tech_note09186a008071bdf9.shtml
    Looks to be your issue

  • I cannot ping the WWW via the shell with SWPS

    hi
    I have installed sun web proxy server, this work fine and i can access with my browser to whatever page but when i do it by example
    -bash-3.00# ping www.google.com
    no answer from www.google.com

    this is my routing table netstat -nr
    Routing Table: IPv4
    Destination Gateway Flags Ref Use Interface
    default 172.24.0.1 UG 1 4265449
    172.24.0.0 172.24.0.3 U 1 2191 vnet0:4
    224.0.0.0 172.24.0.3 U 1 0 vnet0:4
    but if i do traceroute www.google.com i receive this
    traceroute: Warning: www.google.com has multiple addresses; using 209.85.133.99
    traceroute to www.google.com (209.85.133.99), 30 hops max, 40 byte packets
    1 * * *
    2 * * *

  • Ontap 8.3 lif cannot ping gateway

    Hi all, I have c-mode cluster with 1 node (DR filer).  It's on subnet 172.16.230.0/24. Gateway is 172.16.230.1/24I created an intercluster LIF (172.16.230.35)  to comm. with filer (production ) in another subnet. (10.1.198.0/24).I can ping 10.1.198.35. But I cannot ping the gateway 172.16.230.1 from the intercluster LIF on the DR-filer.I can also not ping from 10.1.198.35 (prod. filer) to 172.16.230.35 (dr filer) If I connect a laptop in the same subnet and give it 172.16.230.18, I can ping both ways. Thus, ping to 10.1.198.35, 172.16.230.1 and vice versa.  Just as expected. So routing seems correct. BUT, if i ping from the laptop to the LIF (172.16.230.35) of the filer,  I have no response, altough it's on the same subnet. So it looks like 'something' is preventing the LIF on the Dr-filer to respond to the ping(?)  I spend hours of searching the internet but I'm completly lost now. If somebody could give me only a direction to search in, it would be great! Thanks!  

    Solved! Weird cabling issue... :-(

  • Guest VLAN cannot ping gateway

    Hi Sir,
         I have an issue wherein my guest vlan cannot ping its gateway thus it cant go through the web auth page. I have been given an ip address with corresponding gateway, subnet and dns for the guest vlan. I have allowed all the vlans in the trunk port for wlc and ap connection.
         wat do you think is the problem? hope you could help on this.
    thanks.
    Regards,
    Neri

    Hi Neri
    The way this should work is that the client connects to the guest network and gets an IP address from DHCP. The DHCP configuration should include the default gateway and must include a DNS address.
    When the client opens a web browser the browser tries to connect to the configured home page. This means that a DNS lookup is sent out and the controller intercepts it and forwards it on. Providing there is a response from the DNS server the controller will cause the client browser to re-direct to the web authentication login page.
    It is therefore essential that the controller can see the DNS server. Forget the PING for now - DNS is a must. You can prove the rest of the system by ensuring the guest client has an IP address. Open the client browser and try and connect to http://1.1.1.1 (assuming your virtual interface on the controller is 1.1.1.1). If you get re-directed to the web authentication login page then the issue is a DNS issue.
    Regards
    Roger

  • Cannot ping windows 2008 r2 while it is possible for another machine in the same network

    Hi,
    Recently I have set up a new server with windows 2008 r2 enterprise OS which is a domain member server. 
    At network layer I have two networks one with 192.168.1.0/22 and another with 10.0.0.0/24 network IDs.
    My problem is that I cannot ping the newly installed server from a specific machine. Server's IP address is 192.168.1.56 and the specific machine's IP address is 10.0.0.12 and it is a windows XP machine. Of course I have to say that this problem belongs
    only to this WinXP machine and all the layer 3 issues are tested and correct. This issue happens while at the same time I can ping domain controller which also is a windows 2008 r2 enterprise box and its IP address is 192.168.1.53. It turns more complicated
    when I learned I can ping the winxp machine and connect to it from new server through remote desktop. Firewall also is not the obstacle because I turned it off completely. 
    Can anybody help me fix the problem?
    TIA
    Bijan

    Hi,
    Check the path ping from xp machine to server its timing out after reaching 192.168.1.254 , What kind of a device is 192.168.1.254 IP belongs to.
    Tracing
    route to sp45newfs.ph45.local [192.168.1.56]
    over
    a maximum of 30 hops:
    0  B15-333.PH45.LOCAL [10.0.0.12]
    1  192.168.1.254
    2     *        *        *
    Computing
    statistics for 50 seconds...
              Source to Here   This Node/Link
    Hop
     RTT    Lost/Sent = Pct  Lost/Sent = Pct  Address
    0                                           B15-333.PH45.LOCAL [10.0.0.12]
                                  0/ 100 =  0%   |
    1    0ms     0/ 100 =  0%     0/ 100 =  0%  (192.168.1.254)----------(Which device has this IP)
                                100/ 100 =100%   |
    2  ---     (100/ 100 =100% )---(100% loss)    0/ 100 =  0%  B15-333.PH45.LOCAL [0.0.0.0]
    Trace
    complete.
    Regards,
    Srivishnu.K

  • Cannot ping gateway once RE is plugged in?

    setup utility didn't work, so i configured it manually.
    set the same SSID as my wireless network, same channel, and setup the same WEP security as well. left the static IP the same, and made the gateway my router (192.168.1.1).
    when i plug in the RE, signal boosts up as it should, but i lose network connectivity and can't ping the gateway. i can still ping the RE, but nothing else. this computer was set to a static address, so i put back to DHCP and rebooted. It picked up a valid IP, but still couldn't ping the gateway?!?
    should've already known that linksys products can be extremely frustrating, but help me out!!
    thanks

    try and change change few settings under the advanced wireless settings on router .....reduce the beacon to 50, reduce the RTS and fragmentation by 40 each....
    Also verify that you are using the latest firmware on the router and RE...

  • Ping to gateway fails

    Hi,
    We have a vlan 10 - 192.168.5.1 /24 ( Static IP subnet ) on the core switch.
    One pc is connected to a port (fa1/0/11) on an edge switch-ES01 ( which has this vlan 6 ) & assigned to vlan 6
    Pc is given the ip 192.168.5.25 & gateway as 192.168.5.1
    But, the pc is unable to ping the gateway. We tried with different laptop & also changed the fa1/0/11 interface to manual speed.
    The configurations are as below:
    On edge switch-ES01 where PC is connected ,
    Int fa1/0/11
    switch access vlan 6
    desc test
    On edge switch-ES01 port which uplinks to core ,
    interface GigabitEthernet2/0/1
    des Uplink to Core switch
    switchport trunk encapsulation dot1q
    switchport mode trunk
    ip arp inspection trust
    srr-queue bandwidth share 10 10 60 20
    srr-queue bandwidth shape 10 0 0 0
    queue-set 2
    priority-queue out
    mls qos trust cos
    auto qos voip trust
    channel-group 12 mode active
    ip dhcp snooping trust
    end
    ip dhcp snooping vlan 1-999 is enabled on this edge switch
    ip arp inspection is enabled for this vlan 6 in this edge switch
    On Core Switch port connecting port to above edge switch:
    interface GigabitEthernet2/3
    switchport
    switchport trunk encapsulation dot1q
    switchport mode trunk
    no ip address
    wrr-queue bandwidth 5 25 70
    wrr-queue queue-limit 5 25 40
    wrr-queue random-detect min-threshold 1 80 100
    wrr-queue random-detect min-threshold 2 100 10
    wrr-queue random-detect min-threshold 3 50 60
    wrr-queue random-detect max-threshold 1 100 10
    wrr-queue random-detect max-threshold 2 100 10
    wrr-queue random-detect max-threshold 3 60 70
    wrr-queue cos-map 1 1 1
    wrr-queue cos-map 2 1 0
    wrr-queue cos-map 3 1 4 7
    wrr-queue cos-map 3 2 2
    wrr-queue cos-map 3 3 3
    wrr-queue cos-map 3 4 6
    mls qos trust cos
    storm-control broadcast level 5.00
    storm-control multicast level 5.00
    channel-group 12 mode active
    Please help on this. thanks in advance.

    Hi,
    I see that you have the laptop on vlan 6, and the gateway of that laptop is vlan 10 ip add 192.168.5.1/24 ?? Your gateway should be on the same vlan, you cannot have a laptop on vlan 6 and his gateway is vlan 10 there is no way this can ping its gateway since you they are on different vlans. You will need to have a SVI for vlan 6 on the core switch with a different subnet to achieve this.
    What about if you put that laptop on vlan 10 an try again with the same ip on the laptop.
    Regards,

  • Cannot ping/telnet/ssh to GigabitEthernet interface of Cisco AP2602

    I have a Cisco 2602 (ios ver 15.0)
    I can connect trough it's SSID normally but I can't access to the AP itself. From the AP cannot ping to gateway, even though the AP can be seen on cdp from the switch.
    But my other AP Cisco 1140 (ios 12.4) can be accessed with the same configuration on the switch (switchport mode trunk, allowed vlan 1 & 2)
    vlan 1 is for user, vlan 2 for management...
    Below is the configuration of the gigabitethernet interface of the AP 2602
    interface GigabitEthernet0
     no ip address
     no ip route-cache
     duplex auto
     speed auto
     no keepalive
    interface GigabitEthernet0.1
     encapsulation dot1Q 1 native
     no ip route-cache
     bridge-group 1
     no bridge-group 1 source-learning
     bridge-group 1 spanning-disabled
    interface GigabitEthernet0.2
     encapsulation dot1Q 2
     ip address 10.32.2.98 255.255.255.0
     no ip route-cache
     bridge-group 2
     no bridge-group 2 source-learning
     bridge-group 2 spanning-disabled
    interface BVI1
     no ip address
     no ip route-cache
    ip default-gateway 10.32.2.1
    please help

    With autonomous access point, the management has to be the native vlan.  The issue is that your vlan 1 is native and that is for users, but your management is on vlan 2 which is management. This will not work as it is a requirement to keep management on a native vlan.  You would have to move the users to a different vlan since vlan 1 is typically tagged so that you can define on the trunk port on the switch that vlan 2 is native.
    -Scott

Maybe you are looking for