Inter-vlan routing issues (one device isn't pingable from one VLAN, is pingable from others).

Greetings network wizards, 
I'm facing an interesting issue in our enterprise network.
There is management VLAN. There are various devices in management VLAN (e.g. WLC controllers, SVIs for management on our catalysts, interfaces for management of servers, ...). 
There are also other VLANs (office100, office101, printers, technology, ...). I'm unable to ping one device on our management VLAN from office VLAN. From all other VLANs, the ping works fine.
In terms of CLI (where a.b.c.d is problematic destination addres in management VLAN): 
ping a.b.c.d. source vlan 20 = success
ping a.b.c.d source vlan 50 = success
ping a.b.c.d source vlan 90 = success
ping a.b.c.d source vlan 101 = failure
The ping is launched from either of our two L3 switches and the a.b.c.d address belongs to computer shown in the bottom of the picture. 
The excerpt of our physical topplogy can be seen below. 
The L3 switches depicted above are our two 4506 catalyst switches with SVIs for our multiple VLANs. There is also HSRP group for each VLAN on our L3 switches. 
I checked all the relevant data structures (arp, mac, fib, adjacency tables) and everything seems OK. What is also worth to mention, is the fact, that the IP address of the switch shown in the bottom of the picture is in same VLAN as the device represented by PC attached to the switch in the bottom. That management SVI of the switch is pingable and working regardless of the source VLAN. 
Any help would be appreciated. 
Best regards, 
SZ

Hi, 
I'm afraid, that the configuration you posted above won't solve my issues. It is so because of following packet flow: 
Ping from VLAN 101 (office) to VLAN 900 (management) flows to either of my L3 switches. L3 switch takes a look at the destination IP addres and assumes, he should use VLAN900. Thus, he uses VLAN900 SVI, encapsulates the frame to VLAN900 802.1q frame and sends it out of the appropriate trunk (the appropriate trunk is identified by destination IP address and corresponding MAC address). 
Please, keep in mind that the topology is only excerpt and other switches are physically present, too (but not shown here). These other switches have clients from VLAN101 attached and these clients can easily ping the access switch (VLAN900) shown in the picture, but they're unable to ping the PC (VLAN900) attached to the same access switch. PC's switchport is assigned to correct VLAN. The frame coming from VLAN101 from another switch (not shown in picture) is rerouted at L3 switch and is put on trunk as VLAN900 frame. Then it flows down to the access switch. STP and trunks are fine ... because: 
If I had STP issue or trunk misconfiguration in place, I wouldn't be able to reach the access switch (from whatever VLAN). In my current situation, I'm able to reach it easily. 
Best regards, 
SZ

Similar Messages

  • So if iMessages deleted from one device are not deleted from others why not recover deleted iMessages from iCloud?

    I accidentally deleted ALL the messages from my wife from my iPhone, nearly all of them iMessages.  Yet, I can see all of them on my iMac and on my MacPro.  Indeed, there is a discussion item (https://discussions.apple.com/message/21313040#21313040) that confirms that messages are deleted and maintained independently on each device, even though they are all ultimately resident only in Apple's cloud.
    I would dearly love to have all of them back on my iPhone.  Yet, reading about 20 or so discussions here, the only way to recover them would be a recovery from my iTunes backup.  I have a somewhat recent backup, but I'll still lose about 100 messages that way.
    So, if all the messages are still in the cloud, why CAN'T I recover them directly from the cloud to my iPhone?  Any ideas?  Any software?  Is this an App just begging to be built??
    Thanks

    It depends on the type of email account you are using, not on iCloud.  If you are using an IMAP or exchange account, when you delete from one device, it is deleted from all devices.  If you are using a POP (POP3) account, it won't.  (iCloud email, Gmail and Yahoo are all IMAP accounts.)

  • Server not responding internet Only works when sitting next to the router all over devices work fine apart from iPhone 5

    I Have a iPhone 5 and the internet doesn't connect when im not sitting right next to then router I have put it back to factory settings and it still can't connect , all of my other devices are fine what shall I do?

    That could be a hardware problem with the WiFi antenna. Contact Apple Support for assistance: Contact Us

  • Package assigning issue to object which is moved from other system

    Hi Experts,
    We have moved one develoment (workflow development) from one server to another server with basis people help and
    can see everything perfecly in my system . But , i need to save them under my own requyest ,then only i can move them to produciton. I am doing in a way by reassigning under my package but it is saving under request only with different
    naming as not same of source system .
    For ex:
    For my stem: Saving like below :
    Object Directory Entry
        R3TRPDTS91000189
        R3TRPDTS91000191
    But for source system :
    91000188
    will all of them move without any issues or am i doing in wrong way ?
    Tahnk you in advance.

    Hi,
    If i understand your question right then you want to ask why transport name is different between different system.
    Answer is when you create transport request in any system then it is created like <SID><transport number>. So, if you are creating it in different system then it will give you different name as SID and transport sequence number will differ.
    If you want to save it in your own request then make a copy of transport in development system from your user id and then move it to test and production.
    Thanks
    Sunny

  • PC as a bluetooth Device and accept input from other devices

    I need to set my PC up as a bluetooth device by use of a bluetooth dongle connected to my PC. I need to have a program running on my PC that will detect other bluetooth devices and connect with them, accept input from them. Please help me do this. anyone got code for this? Thank you a gazillion in advance !! :)

    There's no way to do is with standard Java as far as i know. You'll have to use JNI to use native libraries.

  • How can I delete e-mails from one IPad without removing them from other IPads on same icloud? I'ved tried switching off mail sync on all devices but this only works when deleting on IPhone

    We have several portable devices and a mini mac on our system and have found that if we delete an email on one device it is removed from others.
    We don't want this, but at the same time we need to keep our devices clear of clutter.
    It was suggested that switch off the sync mail switch in settings - Icloud, but this only works on IPads & Ipods
    anybody got any better ideas ??

    We have several portable devices and a mini mac on our system and have found that if we delete an email on one device it is removed from others.
    We don't want this, but at the same time we need to keep our devices clear of clutter.
    It was suggested that switch off the sync mail switch in settings - Icloud, but this only works on IPads & Ipods
    anybody got any better ideas ??

  • NO HELP WITH ROUTING ISSUES FROM VERIZON

    Spend 2 hours with technical support to no avail. Have routing issues where I can’t get from my FIOS residential account to remote web site abroad. Trace route fails at so-0-0-0.XT1.AMS2.ALTER.NET [146.188.14.209]. FIOS technical support is incapable of doing any troubleshooting beyond basic customer premises equipment, refusing to escalate the case to network engineering team. I was basically told by FIOS tech support supervisor {edited for privacy} that this is not Verizon’s problem and no help will be provided. What is even more frustrating that Verizon agents are not capable of receiving emails from customers with details such as trace route.
    Is there anyone at Verizon monitoring this and able to help? Just in case, ticket number that I have with Verizon is {edited for privacy}
    Here is trace route details.
    tracert 212.44.136.226
    Tracing route to brserv.bridgetour.ru [212.44.136.226]
    over a maximum of 30 hops:
      1     1 ms    <1 ms     1 ms  Wireless_Broadband_Router.home [192.168.1.1]
      2    12 ms     9 ms     9 ms  L100.BSTNMA-VFTTP-71.verizon-gni.net [98.118.28
    1]
      3    16 ms    19 ms    19 ms  G0-6-4-1.BSTNMA-LCR-21.verizon-gni.net [130.81.
    75.132]
      4    45 ms    15 ms     8 ms  ae3-0.BOS-BB-RTR1.verizon-gni.net [130.81.151.6
      5    19 ms    19 ms    19 ms  0.xe-3-2-0.IL1.NYC9.ALTER.NET [152.63.26.81]
      6    21 ms    19 ms    19 ms  0.ge-1-2-0.IL1.NYC12.ALTER.NET [152.63.26.86]
      7   107 ms   108 ms   107 ms  so-0-0-0.XT1.AMS2.ALTER.NET [146.188.14.209]
      8     *        *        *     Request timed out.
      9     *        *        *     Request timed out.
     10     *        *        *     Request timed out.
     11     *        *        *     Request timed out.
     12     *        *        *     Request timed out.
     13     *        *        *     Request timed out.

    BT help aren't always that helpful, but BT engineers claim that it is a BT sales issue and nothing to do with them seems a bit extreme.
    Are you sure your daily speed is 8Mbits, not 8Mbytes?  How are you measuring this?  Is it the number coming from the BT speedtest?
    If it really is 8Mb, then I think it's worth checking with the mods;  at: http://bt.custhelp.com/app/contact_email/c/4951 .  But be aware they take 3 working days to reply: sometimes more if busy. 

  • MY IPAD IS DISABLED I TRIED TO RESTORE IT BUT ITS SHOWING MESSAGE "The iPad could not be restored. the device isn't eligible for the request build"

    MY IPAD IS DISABLED I TRIED TO RESTORE IT BUT ITS SHOWING MESSAGE "The iPad could not be restored. the device isn't eligible for the request build"

    Follow the steps here:
    Error 3194, Error 17, or "This device isn't eligible for the requested build" - Apple Support

  • Ipod touch cannot be updated or restored. getting a pop up which says 'the device isn't eligible for the requested build'. How do i restore?

    ipod touch cannot be updated or restored. getting a pop up which says 'the device isn't eligible for the requested build'. How do i restore?

    Error 3194, Error 17, or "This device isn't eligible for the requested build" - Apple Support

  • RV130W Inter-VLAN Routing occurs even when disabled

    On my RV130W I have two VLANs set up:
    VLAN1:
    VLAN100:
    Inter-VLAN Routing is NOT enabled:
    Why then am I able to ping hosts in a different VLAN?
    Does this require a bug fix?

    I put my theory to the test and it worked as I thought
    which is that vlan 101 could get to vlan 102 and vice versa
    but vlan 1 could get to either and vice versa
    I take it that this is probably due to how the router os is setup and hardware options on it
    based on that there is probably only a couple of real interfaces
    and that the vlan 1 is assigned to the one of them or to the switch interface
    and the other vlans are just attached to it, 
    vlan 1 has to be able to cross communicate due to my guess that there aren't enough real interfaces
    in that vlan is the end gateway and the other vlans are just virtual gateways if you will
    This is what I did with the ports
    In my lab I actually don't assign vlan 1 to any ports at all, nothing is on it except that actual router
    but I left it on a port for you to see, as it might be handy to connect to in worst case scenarios
    which works because of routing
    as to whether its a feature or a bug or a limitation is hard to say without more info from cisco

  • ACE design with inter-Vlan routing

    Hello all.
    I'm working on a design for a customer where the ACE will perform inter vlan routing.
    A few questions about that :
    - is routed traffic enforced in hardware with some kind of CEF-like mechanism ? (I suppose yes because there is a FIB ? per
    https://supportforums.cisco.com/docs/DOC-19253 ) we expect a certain load and routing is software will not be acceptable
    - if I put my VIPs within the VLANs hosting the application, is there any restriction on accesses made to this VIP (if the VIP is reached after the routing process is performed) ?
    example :
    VLAN2 (client) ----- ACE ----- VLAN3 (servers)192.168.2.0/24                 192.168.3.0/24
    If I try to access the VIP (192.168.3.20) from a PC in the VLAN2 (192.168.2.15) does it work ?
    I assume yes because the VIP appears as a connected /32 in the routing table, I just want to be sure to not fall into some tricky part of code because the access to the VIP is done after the routing process. I just want to be sure there is no drawback / restriction about that.
    Thanks in advance.

    Hello Surya!
    Yes this is possible. You can reach the VIP from one VLAN to another (The VIP is not really inside of the VLAN). Important is to check your ACLs and you need to have the service-policy either globally or local on both VLAN-interfaces.
    And I guess there is nothing like CEF implemented in the ACE, because it is not needed there.
    Cheers,
    Marko

  • 881 - How to configure inter-VLAN routing

    I hesitate to post here -- I know that I should know my job. But here goes...
    Small business wants to use an ASA 5505 firewall on the edge connected to VDSL modem, and then an 881 to route internally (see attachment). The 881 has a downstream link to a 2960.
    Want the following "blocks":
    VLAN 33 - CLIENTS
    VLAN 55 - SERVERS
    VLAN 101 - CDLAB
    The lab is for testing, and will be connected via Cisco 2500 series router. The server farm (Server 2008 domain +) will be connected via layer 2 switch over VLAN. A DMZ is anticipated after basic connectivity is established. Connectivity is already verified from a client connected to the INSIDE interface of the ASA going to the OUTSIDE and back.
    Before I started I wiped the devices in order to start clean. Both the router and the switch are in vtp mode transparent.
    To build a trunk link, I connected the 881 and the 2960 using a crossover cable from int fa0 to int fa0/8 respectively.
    On both devices' interfaces I set switchport mode trunk.
    I configured the 3 VLANs on the 881, assigned IP addresses to them, and used switchport trunk allowed vlan add 33,55,101 to assign them to the trunk but that doesn't appear in the sh run output under the interface.
    I set both devices' to switchport nonegotiate (best practices?). Once again, on the 881 this command doesn't appear in the running config.
    I configured the 3 VLANs on the 2960, then used the same switchport commands as above to assign them to the trunk.
    Here's the deal.
    From a client connected to a VLAN 33 access port on the 2960, I can't ping, for example, the VLAN 55 IP address. I can ping the VLAN 33 IP address. I also can't ping the IP address of the interface on the far side of the router headed to the ASA (int fa4).
    What am I doing wrong? I'll gladly post the running configs if anyone wants to see. I've spent most of the day on this racking my brain and literally scouring the Internet. I'd be very grateful for some assistance.
    Help!

    Thanks, Mike.
    Yeah, I might not have been too clear. But on the router, each VLAN was created using the vlan 33 command (for example) and given a name. Then I went to int vlan 33 (for example) and used ip address 10.0.33.xx 255.255.255.0 for the address and subnet mask. Those have been in place since I started. And like I said, I can ping the SVI for VLAN 33, which is mapped to the client access port I'm on.
    The problem is, I still can't ping inter-VLAN and I still can't ping the far side interface.
    Bummer...

  • Inter VLAN Routing for IEC 61850

    Hello,
    Hoping someone can help me with this query.  I'm in the process of configuring two CGS2520 switches located in two electrical substations.  Each of these switches have Protection Relays and Remote Terminal Units (RTUs) connected to them.  These devices communicate with each other as follows:
    IEC 61850 GOOSE: http://en.wikipedia.org/wiki/Generic_Substation_Events
    IEC 61850 MMS: http://en.wikipedia.org/wiki/IEC_61850
    - Protection Relay to Protection Relay communication within either substation (Using IEC 61850 GOOSE - VLAN 11 and VLAN 21)
    - Protection Relay to Protection Relay communication between substations (Using IEC 61850 GOOSE - VLAN 50)
    - RTU to Protection Relay (Using IEC 61850 MMS - VLAN 10 and VLAN 20)
    I've attached an image (hope that clears things out).  Basically GOOSE traffic is VLAN tagged and and the MMS traffic is untagged.
    I need to be able to route between VLAN 10 and VLAN 20 between the substations and I want to allow VLAN 50 between the substations.  How do I go about configuring this?
    So far I've configured the interfaces as follows:
    Switch A2:
    Fa0/5 and Fa0/7 (Protection Relay Ports)
    port type nni
    switchport trunk native vlan 10
    switchport trunk allowed vlan 11, 50
    switchport mode trunk
    Fa0/3 (RTU Port)
    port type nni
    switchport access vlan 10
    Switch B1
    Fa0/4 and Fa0/5 (Protection Relay Ports)
    port type nni
    switchport trunk native vlan 20
    switchport mode allowed vlan 21, 50
    switchport mode trunk
    Fa0/3 (RTU Port)
    port type nni
    switchport access vlan 20
    Locally at each substation this seems to work (I can ping the Protection Relays from the RTU port and the Protection Relays send each other GOOSE messages).  However I don't know how to configure the inter vlan routing (I want to be able to ping a Protection Relay Substation B from the RTU Port at Substation A) at  and how to configure the switch interfaces that connect to each other?
    Any help is much appreciated.
    Thanks
    Darsh

    Hello DarshanaD,
    Could you fix this? Im asking because I have the same problem right now.
    I'll appreciated if you can tell me how did you configure the inter VLAN routing.
    Thanks
    Ali

  • Inter-VLAN routing, Auto-Voice VLAN and IP Address-Helper

    Hope that somebody can help me with the setup in the screenshot. 
    Planning to use Auto-Voice VLAN and Smartports to configure VOIP
    LLDP-MED will be enabled on the switch to detect the IP phones so they will be moved to the Voice VLAN (If not the first 6 signs will be added to the OID table). The Voice VLAN ID will be 2 >> Voice VLAN will be automatically enabled once a device is recognized as a IP phone right? 
    Workstations will be connected to the Cisco switch, VLAN data will be untagged and will remain on the native VLAN.
    Smartports will be used to configure the ports (Macro's) >> Should configure the ports as trunks as assigns the correct VLANs right?
    But how do i configure the IP Helper-Address? Do i have to create the Voice VLAN on both switches and then run the command "IP Helper Address" to specify a DHCP server? From what i've been reading it's required, when using Inter-VLAN routing, to configure the VLAN interface with an IP address. But it's going to give problems when both switches are connected to eachother and both have the same VLAN configured including the same IP address assigned to their VLAN interface?
    Normal data should pass  the ASA firewall, VOIP traffic should go through the Vigor modem to a hosted VOIP provider. The best way, i assume, is to configure 2 separate scopes on the DHCP server?
    Still confused on how to set it up, hope that someone can point me in the right direction

    If you're sending voice to only the Vigor modem then there is no need for a trunk between the SF-300 and the Vigor modem. You can just set that to an untag packet for the VLAN 2 between that switch and the Vigor modem.
    On the 'edge' SF300 where the IP phone/PC is it is obviously going to interoute there and of course the phone port is tagged and PC port is untagged.
    For the IP helper, it uses UDP-RELAY and it should be enabled on the port itself and enabled on the global configuration. You may also need option 82. Also keep in mind, depending how your DHCP server works, it may need option 82 configured as well or at least a route to understand the subnets in the layer 3 environment to get traffic across the VLANS.

  • RV180 Router: Cannot get Inter-VLAN Routing to work.

    I have been banging at this now for two days and just cannot get Inter-VLAN routing working to work on this router.
    Here is the est-up:.
    Upgraded to latest Cisco firmware (1.0.1.9).
    Starting with factory default settings, I added 2 VLANS as follows:
        vlan default(id=1): dhcpmode=server IP=192.168.1.1/24 port 1
        vlan vlan2  (id=2): dhcpmode=server IP=192.168.2.1/24 port 2
        vlan vlan3  (id=3): dhcpmode=server IP=192.168.3.1/24 port 3
                                       (unconnected)
                                         WAN port
                                            |         
                                        Routing/NAT
                                            |
    vlan ip                   192.168.1.1   192.168.2.1   192.168.3.1
    vlan name                   default        vlan2        vlan3
    vlan id                       ID=1          ID=2         ID=3
    Inter-VLAN Routing             No           Yes          Yes
    Port 1                     Untagged       Excluded     Excluded
    Port 2                     Excluded       Untagged     Excluded
    Port 3                     Excluded       Excluded     Untagged
    Port 4(not of interest)    Untagged       Excluded     Excluded
                                Port 1         Port 2       Port 3
                                  |              |            |
                               AdminPC          PC2          PC3
                                           192.168.2.191   192.168.3.181
    PC2 gets assigned an IP Address of 192.168.2.191 (DGW=192.168.2.1) - OK
    PC3 gets assigned an IP Address of 192.168.3.181 (DGW=192.168.3.1) - OK
    PC2 with (IP 192.168.2.191) can ping 192.168.2.1 and 192.168.3.1 - OK
    PC3 with (IP 192.168.3.181) can ping 192.168.3.1 and 192.168.2.1 - OK
    BUT....
    PC2 cannot ping PC3  - NOT WORKING
    PC3 cannot ping PC2  - NOT WORKING
    (does not work in both Gateway Mode and Router Mode)
    ANYONE CAN HELP ME FIGURE OUT WHY ??????
    Your help is much appreciated.
    I bought this device specifically because it supported inter-VLAN routing!.
    Venu
    Supporting Information:
    Screen captures:
    VLAN Membership:
      VLAN ID  Description  Inter VLAN  Device   Port 1    Port 2    Port 3    Port 4  
                            Routing     Mgment
           1   Default      Disabled    Enabled  Untagged  Excluded  Excluded  Untagged  
           2   VLAN2        Enabled     Enabled  Excluded  Untagged  Excluded  Excluded  
           3   VLAN3        Enabled     Enabled  Excluded  Excluded  Untagged  Excluded 
    Multiple VLAN Subnets:
       VLAN ID IP Address   Subnet Mask    DHCP Mode    DNS Proxy Status  
            1  192.168.1.1  255.255.255.0  DHCP Server  Enabled  
            2  192.168.2.1  255.255.255.0  DHCP Server  Enabled  
            3  192.168.3.1  255.255.255.0  DHCP Server  Enabled
    Routing Table (Gateway Mode)
    Destination     Gateway   Genmask         Metric  Ref   Use   Interface   Type     Flags
    127.0.0.1     127.0.0.1   255.255.255.255 1       0     0     lo          Static   UP,Gateway,Host
    192.168.3.0     0.0.0.0   255.255.255.0   0       0     0     bdg3        Dynamic   UP
    192.168.2.0     0.0.0.0   255.255.255.0   0       0     0     bdg2        Dynamic   UP
    192.168.1.0     0.0.0.0   255.255.255.0   0       0     0     bdg1        Static   UP
    192.168.1.0 192.168.1.1   255.255.255.0   1       0     0     bdg1        Static   UP,Gateway
    127.0.0.0       0.0.0.0   255.0.0.0       0       0     0     lo          Dynamic
    Routing Table (Router Mode)
    (Same)

    cadet alain, you hit the nail on the head.    The router was doing Iner-VLAN routing, but the PCs were blocking the pings because they came from another subnet.  Thank you for your help in resolving this.
    I have a follow-up question if I may - I need to add a default route but can't seem to find a way to do that.  Tried adding a static route with IP=0.0.0.0 Mask=0.0.0.0 but it will not allow it.  My current routing table looks like this:
    Destination   Gateway     Genmask           Metric  Ref   Use  Interface  Type    Flags
    127.0.0.1     127.0.0.1   255.255.255.255   1       0     0    lo         Static  UP,Gateway,Host
    192.168.2.0   0.0.0.0     255.255.255.0     0       0     0    bdg2       Dynamic UP
    192.168.1.0   0.0.0.0     255.255.255.0     0       0     0    bdg1       Static  UP
    127.0.0.0     0.0.0.0     255.0.0.0         0       0     0    lo         Dynamic UP
    It routes all packets to VLAN2 and VLAN3 correctly; but if a packet arrives to any other network address, I would like to get it to forward to another gateway on VLAN2 (at address 192.168.2.254).  Can't seem to find a way to add a default route.

Maybe you are looking for