Intervlan netboot issue

Cisco 6500 switch does the intervlan routing. MS Windows Server 2003 is the DHCP server for all subnets and works just fine handing out addresses to normal DHCP clients. IP helper address on vlan interfaces point to the W2K3 server. We can ping the OSX server from all subnets. The problem is that we can only image clients when they are in the same vlan as the OSX server. I've seen several other posts, but no resolution other than calling Apple support.
Do we need to add anything else other than the ip helper address on the vlan interfaces of the 6500? Or does something need to change on the OSX server?
Thanks!
Kevin

If someone has put another DHCP server out on your network it can (and will) intercept the packets returned from the client, thus convincing the server that the client did not respond to its offer of service.
If you can get the server and client on a closed network, this is easy enough to rule out.
Another thing you can do is to completely tear down and reset the NetBoot server. Stop AFP, NFS, and NetBoot, and restart them. Sometimes, if something is stuck on the server, this will reset it.

Similar Messages

  • NetBoot issue macbook pro 13" i5 2.3Ghz

    Hi,
    Actually i work on deployment for os x via netboot. (debian dhcp/pxe)
    First :
    Since last update EFI 2.6 my macbook(s) pro don't want to boot via netboot ...
    i have macbook too and they correctly netboot via deploystudio !
    The 2.7 update doesn't anything new ...
    As anyone got the same issue ?
    Second :
    i use this config in my dhcpd.conf :
    class "AppleNBI-i386" {
        match if substring (option vendor-class-identifier, 0, 14) = "AAPLBSDPC/i386";
        option dhcp-parameter-request-list 1,3,17,43,60;
        if (option dhcp-message-type = 1) { option vendor-class-identifier "AAPLBSDPC/i386"; }
        if (option dhcp-message-type = 1) { option vendor-encapsulated-options 08:04:81:00:00:67; }
        filename "macnbi-i386/booter";
      #option root-path "nfs:192.168.1.1:/nbi:DeployStudioRuntime.sparseimage";
            option root-path "nfs:192.168.1.1:/nbi:NetInstall-Restore.dmg";
    but it doesn't work and i don't understand why ...
    i have to do this in order to make it work :
    hostname toto {
    hadware ethernet x:x:x:x;
    fixed-address x:x:x:x;
    filename "path/to/booter";
    option root-path "http://path/to/sparseimage";
    The class definition doesn't match
    THX
    ps: i'm french and my english is a little bit rusty ...

    There is a long thread on this problem over on the Lion forum, I think it was.
    Most everyone on that other tread said the newer firmware fixed the NetBoot issue.
    If you have installed the most recent firmware and it still isn't working try Re-Intsalling that firmware.
    Then try a re-Set of the SMC and PRAM. Not sure if that is needed but won't hurt.

  • Netboot Issue - White Imac to 2007 AL Imac

    Hi
    We have just purchased 20 Mid 2007 Aluminium iMac's to add to our existing network. - The one i have taken out of the box was pre-installed with 10.4.11 with a Leopard Upgrade Disk inside (said that Leopard is not installed on the machine but can be upgraded by use of this disc).
    We have a 10.4.10 Netboot image (built on a 17" 2006 White Intel iMac) on our XServe that I have tried to restore onto one of the new Aluminium Imac's.
    The actual netboot operation worked fine and the operating system booted up on the new Aluminium Imac - but then i have found;
    a) the onboard LAN port is greyed out and cant be configured
    b) the isight camera does not work
    c) the sound does not work
    I downloaded the 10.4.11 combo updater and ran that on the machine hoping that it would replace drivers, etc - no chance.
    Is there a way i can get the specific drivers for this hardware, as I dont want to have to install all of the programs and settings that we have for our network. then have to clone it 20 times.
    Or is there a way i can remove the settings for the missing items (network, isight, sound) from the computer prefs and get them rebuilt on system startup?
    Frustrated that Apple support has been less than forthcomming, with the reply of
    "upgrade to Leopard" - Upgrading to Leopard is not an option.
    Not understanding the problem which i was facing.
    I might have to return the 20 and just get hold of 20 of the White Imac's - which are on sale from our reseller.
    Message was edited by: jszkud

    Thank you so much for your information.  I have been using a Seagate GoFlex portable drive as my back up disc with TimeMachine on my iMac.  The AirPort Time Capsule is arriving tomorrow with my new iMac.  My question to you is this:  Will it be easier to wait till tomorrow, set up my AirPort Time Capsule and back up my old iMac to it and then use it with the Startup Assistant to transfer my stuff or will it be easier just to use my GoFlex back up disc?  I have had some issues in the last year where Time Machine send me a message that the (daily) back up failed because the file got corrupted and I have been unable to fix it so that I have to reformat the disc and back up everything I have.  Just an FYI, I don't have a huge amount of stuff on my iMac even if is almost 7 years old....I have 900 GB out of 1TB available.  This is one of the reasons I felt it's time to replace my iMac.
    Right now I have a clean encrypted back up on the GoFlex but I don't want to transfer anything I shouldn't to my new iMac.  Please advice and thank you.

  • Cross Subnet Netboot Issues

    Hello,
    I've been working to set up a netboot and Open Directory server in school district. We have the network segmented into VLANs by campus with different subnets for each. The changes have been made to the router to allow bootp/bsdp (IPHelper address set and relay agent on) to communicate across subnets, but I am still unable to netboot/netinstall across subnets.
    Watching the logs on the server when I attempt to, it seems to be communicating partially as seen here:
    Jul 19 12:48:37 axposeidon bootpd[1822]: BSDP DISCOVER [en1] 1,0:16:cb:8e:50:a6 NetBoot035 arch=i386 sysid=MacBookPro1,1
    Jul 19 12:48:37 axposeidon bootpd[1822]: BSDP OFFER sent [1,0:16:cb:8e:50:a6] pktsize 369
    Jul 19 12:48:37 axposeidon bootpd[1822]: BSDP DISCOVER [en1] 1,0:16:cb:8e:50:a6 NetBoot035 arch=i386 sysid=MacBookPro1,1
    Jul 19 12:48:37 axposeidon bootpd[1822]: BSDP OFFER sent [1,0:16:cb:8e:50:a6] pktsize 369
    Unfortunately it fails to actually boot the machine. Im not positive what's going on but it seems like its sending a response back to the netbooting machine but the machine is not getting it and its resending?
    The OS X Server is an Intel Xserve running 10.4.10 (though we've been experiencing this issue since as far back as I've been trying with 10.4.8), the image was created in 10.4.8, and works on the local subnet (including multicast ASR). The booting machine is, as noted above, a Macbook Pro.
    As a side note, when booted into the OS, the machines can see the server in the Startup Disk preference pane.
    Any suggestions or ideas? Let me know if there's more information I can give that will help.

    In our district there are multiple public and private subnets. The public and private combination I have the server on currently just happen to be on this physical network, so they are sharing the same router.
    I think Im getting a little lost on what you're asking so I'll explain our network structure a little further. The district runs a VLANed network with a different public and private subnet for each campus (the private subnets function mostly as IP address overflow when the public subnet IP limit is exceeded). The network is predominantly PC based and implements active directory servers. The Xserve simply operates as a standalone server currently just handling some web serving tasks and a netboot server.
    The issue, regardless of the public and private subnet interfaces on the server, is that I am unable to get anything to boot from another subnet than the one the xserve is running on. If I run it on the public interface, local machines boot perfectly, but I a log like the one above if I try and boot from another campus (ie another VLAN or subnet). To test it locally I've been running it on the private subnet interface (on the same physical network segment) to boot machines on the local public subnet (which fails with the above log).
    According to Apple and other sources, all that should need to be configured is our CISCO routers need to be set to pass BOOTP information across VLANs/Subnets, which we have configured (using the IP helper-address and DHCP relay agent), but as stated, the connection is still not succeeding.
    I'm checking with our network engineer on a few specifics on how the routers are configured to make sure they are set properly for the forwarding, but he's not available at the moment.
    I applogize if this doesnt address the information you're needing, but please let me know if it does not, and I will try my best to get you the needed information.

  • Netbooting issue with Netgear switches

    Hi,
    We’ve started having issues with Netbooting since we recently replaced our network hardware, going from very old (10 yrs +) 3Com switches running at 100MB to desktop / 1GB backbone to brand new Netgear switches at 1GB desktop / 10GB backbone.
    On the old network hardware Netbooting would work fine, showing a list of Netboot images that we are able to boot from with no issue (mainly used for DeployStudio). We have two Mac servers on our network, and now, rather than being able to get a list of Netboot images, it seemingly selects one of the two “Default” images (one for each server) at random. Whichever image is selected works correctly, but we now have no way of choosing at time of bootup.
    Other than replacing the switches, nothing else has changed (that I am aware of) that could have caused this to stop working. However, some relevant info:
    The new Netgear switches are generally M5300-52G-POE+ with a small number of XSM7224S.
    Spanning Tree is enabled on the switches (set to Rapid Spanning Tree – 802.1w). Have also tried with STP turned off totally as I understand this may make a difference – however it did not.
    The infrastructure is a mixed network, with both Windows PC’s/Servers sitting on the same network as the Macs. DHCP is supplied by one of the Windows servers.
    No VLAN’s are set up – all running on same network.
    Both Mac servers are sitting in different physical locations on the network. One is running 10.9.4 and the other on 10.6.8
    If I boot holding down Option then I only see the local hard disk.
    If I boot holding down either N or Option N then the Mac boots using one of the two Default Netboot images, seemingly at random, from one of the two Mac servers. This is as expected for Option N, but N alone used to bring up a list of images (including those not selected as the default on either server).
    All the netboot images show up correctly within the Startup Disk option within System Preferences. I can then boot successfully from any of them in this manner, and am therefore able to get round my problem in the short term, but of course this isn’t ideal.
    I have tried setting the netinstall images to be available both over HTTP and NFS, but this has no effect. Also there are no access restrictions in place for any of the images.
    I’m not 100% convinced that the issue is related to swapping to Netgear switches. Particularly as no specific configuration was ever done on the old 3Com switches to get netboot working (it just worked from the start). Also, the new switches are so much quicker than the old ones. That said it seems far too coincidental that this started happening when the switches were swapped over, and that as I said before, nothing else has changed.
    If there’s anything anyone can suggest that I can check, both with the switch configuration or otherwise, I’d be really grateful.
    Finally, just to say I’m more a Windows person than a Mac man, so treat me gently J
    Cheers,
    LSDWho

    NetBoot uses DHCP to look for available NetBoot servers so when you hold down just N at boot time it sends a DHCP query asking NetBoot servers to advertise themselves. This might therefore suggest the issue is DHCP related. (Strictly speaking NetBoot uses BSDP - Boot Service Discovery Protocol.)
    Note: This use of DHCP by NetBoot does not normally conflict with a real full-blown DHCP server which would ignore this type of query. So it should not cause an issue with your Windows DHCP server.
    Since it might be DHCP related I would look at the following -
    http://kb.netgear.com/app/answers/detail/a_id/21984/~/what-is-a-dhcp-l2-relay-an d-how-does-it-work-with-my-manged-switch%3F
    http://kb.netgear.com/app/answers/detail/a_id/21990/~/how-do-i-configure-a-dhcp- l3-relay-using-the-web-interface-on-my-managed-switch%3F
    I would then see if you can disable DHCP relay functionality and also any other related features like DHCP filtering. If you have not already done so it might be worth checking for any firmware updates and installing those as often 'new' switches out of the box will have shipped with older firmware.

  • NetBoot issue

    Hi everybody,
    I have some trouble using NetBoot, to boot a computer with a minimal deploystudio netboot image.
    When doing a network boot, the client display the netbootserver address. When choosing the netbootserver, the system freeze for a while and then start booting on the local HD.
    I've read http://www.bombich.com/mactips/netboot.html and http://www.macgeekery.com/hacks/hardware/makeany_mac_a_netbootserver,
    the tftp server is running and the ./private/tftpboot/NetBoot/NetBootSP0/PPMac-090729-174122.nbi/i386/booter is easily downloadable with a tftp client.
    the nfs mount point are also accessible:
    showmount -e 172.17.33.22
    Exports list on 172.17.33.22:
    /Library/NetBoot/NetBootSP0 Everyone
    /Library/NetBoot/NetBootClients0 Everyone
    /Volumes/XserveOD-Data/referentielimagedeploystudio Everyone
    The rights seems also be ok:
    xserveod:i386 equipro$ ls -l
    total 38936
    -rw-rw-r-- 1 root admin 297256 May 31 2008 booter
    -rw-rw-r-- 1 root admin 5075232 Jul 29 17:45 mach.macosx
    -rw-rw-r-- 1 root admin 14554067 Jul 24 10:42 mach.macosx.mkext
    How can I solve my problem????
    Here are the server logs of a netboot process:
    Jul 29 19:04:10 xserveod bootpd[2800]: BSDP DISCOVER [en0] 1,0:23:df:83:a:66 NetBoot003 arch=i386 sysid=MacBookPro5,1
    Jul 29 19:04:10 xserveod bootpd[2800]: replyfile /private/tftpboot/NetBoot/NetBootSP0/PPMac-090729-174122.nbi/i386/booter
    Jul 29 19:04:10 xserveod bootpd[2800]: replying to 0.0.0.0
    Jul 29 19:04:10 xserveod bootpd[2800]: BSDP OFFER sent [1,0:23:df:83:a:66] pktsize 383
    Jul 29 19:04:10 xserveod bootpd[2800]: DHCP DISCOVER [en0]: 1,0:23:df:83:a:66
    Jul 29 19:04:10 xserveod bootpd[2800]: replying to 172.17.33.202
    Jul 29 19:04:10 xserveod bootpd[2800]: OFFER sent mbpsb01 172.17.33.202 pktsize 300
    Jul 29 19:04:10 xserveod bootpd[2800]: service time 0.002309 seconds
    Jul 29 19:04:12 xserveod bootpd[2800]: DHCP REQUEST [en0]: 1,0:23:df:83:a:66
    Jul 29 19:04:12 xserveod bootpd[2800]: replying to 172.17.33.202
    Jul 29 19:04:12 xserveod bootpd[2800]: ACK sent mbpsb01 172.17.33.202 pktsize 300
    Jul 29 19:04:12 xserveod bootpd[2800]: service time 0.001034 seconds
    Jul 29 19:04:13 xserveod tftpd[2803]: adding RRQ to cache: 172.17.33.202,/private/tftpboot/NetBoot/NetBootSP0/PPMac-090729-174122.nbi/i386 /booter
    Jul 29 19:04:13 xserveod com.apple.launchd[1] (com.apple.tftpd[2803]): Stray process with PGID equal to this dead job: PID 2804 PPID 1 tftpd+
    Jul 29 19:04:32 xserveod tftpd[2805]: adding RRQ to cache: 172.17.33.202,/private/tftpboot/NetBoot/NetBootSP0/PPMac-090729-174122.nbi/i386 /booter
    Jul 29 19:04:32 xserveod com.apple.launchd[1] (com.apple.tftpd[2805]): Stray process with PGID equal to this dead job: PID 2806 PPID 1 tftpd+
    Jul 29 19:04:32 xserveod tftpd[2807]: adding RRQ to cache: 172.17.33.202,/private/tftpboot/NetBoot/NetBootSP0/PPMac-090729-174122.nbi/i386 /booter
    Jul 29 19:04:32 xserveod com.apple.launchd[1] (com.apple.tftpd[2807]): Stray process with PGID equal to this dead job: PID 2808 PPID 1 tftpd+
    Jul 29 19:05:15 xserveod bootpd[2800]: DHCP REQUEST [en0]: 1,0:23:df:83:a:66 <mbpsb01>
    Jul 29 19:05:15 xserveod bootpd[2800]: domain search added
    Jul 29 19:05:15 xserveod bootpd[2800]: replying to 172.17.33.202
    Jul 29 19:05:15 xserveod bootpd[2800]: ACK sent mbpsb01 172.17.33.202 pktsize 361
    Jul 29 19:05:15 xserveod bootpd[2800]: service time 0.002421 seconds
    This makes me crazy as I've installed a deploystudio on a previous server 10 days ago ;-O
    JC

    Did you ever find a solution to this problem? I have near the same issue.
    I can netboot find from all subnets except one, and this one subnet will just not allow ppc machines to boot, yet allow intel machines to boot.
    I even setup a brand new server running 10.5.0 (to go back versions) on the same subnet and got rid of the helper IP and still cannot boot from ppc... this is very odd.

  • Netboot Issues

    I am having trouble with netboot.  Clients show the image as the boot disk, but when i restart it flashes the globe, then a circle with a slash through it, then shut off.  The following is the system log:
    Jan 17 10:59:31 macserver bootpd[27142]: server name macserver.local
    Jan 17 10:59:31 macserver bootpd[27142]: interface en0: ip 10.10.11.25 mask 255.255.254.0
    Jan 17 10:59:31 macserver bootpd[27142]: subnets: net_range in '10.10.10/23 Ethernet 2' overlaps with subnet '10.10.10/23 Ethernet 1'
    Jan 17 10:59:31 macserver bootpd[27142]: dhcp: re-reading lease list
    Jan 17 10:59:31 macserver bootpd[27142]: bsdpd: re-reading configuration
    Jan 17 10:59:31 macserver bootpd[27142]: bsdpd: shadow file size will be set to 48 megabytes
    Jan 17 10:59:31 macserver bootpd[27142]: bsdpd: age time 00:15:00
    Jan 17 10:59:31 macserver bootpd[27142]: BSDP DISCOVER [en0] 1,0:16:cb:86:c4:89 NetBoot001 arch=i386 sysid=iMac4,1
    Jan 17 10:59:31 macserver bootpd[27142]: BSDP OFFER sent [1,0:16:cb:86:c4:89] pktsize 403
    Any help would be greatly appreciated.  Thanks!

    I spoke with Apple Tech Support.  They had me plug the test computer directly into the server's second ethernet port, enable dhcp for that port and try to boot.  It still didn't work, however, the process seems to have gotten a little farther.
    Jan 18 12:26:43 macserver bootpd[41217]: server name macserver.miamips.net
    Jan 18 12:26:43 macserver bootpd[41217]: interface en0: ip 10.10.11.25 mask 255.255.254.0
    Jan 18 12:26:43 macserver bootpd[41217]: dhcp: re-reading lease list
    Jan 18 12:26:43 macserver bootpd[41217]: bsdpd: re-reading configuration
    Jan 18 12:26:43 macserver bootpd[41217]: bsdpd: shadow file size will be set to 48 megabytes
    Jan 18 12:26:43 macserver bootpd[41217]: bsdpd: age time 00:15:00
    Jan 18 12:26:46 macserver bootpd[41217]: server name macserver.miamips.net
    Jan 18 12:26:46 macserver bootpd[41217]: interface en0: ip 10.10.11.25 mask 255.255.254.0
    Jan 18 12:26:46 macserver bootpd[41217]: interface en1: ip 192.168.2.2 mask 255.255.255.0
    Jan 18 12:26:46 macserver bootpd[41217]: dhcp: re-reading lease list
    Jan 18 12:26:46 macserver bootpd[41217]: bsdpd: re-reading configuration
    Jan 18 12:26:46 macserver bootpd[41217]: bsdpd: shadow file size will be set to 48 megabytes
    Jan 18 12:26:46 macserver bootpd[41217]: bsdpd: age time 00:15:00
    Jan 18 12:26:46 macserver bootpd[41217]: BSDP DISCOVER [en1] 1,0:16:cb:86:c4:89 NetBoot001 arch=i386 sysid=iMac4,1
    Jan 18 12:26:46 macserver bootpd[41217]: replyfile /private/tftpboot/NetBoot/NetBootSP0/NetBoot of Mac OS X Server Install Disc.nbi/i386/booter
    Jan 18 12:26:46 macserver bootpd[41217]: replying to 0.0.0.0
    Jan 18 12:26:46 macserver bootpd[41217]: BSDP OFFER sent [1,0:16:cb:86:c4:89] pktsize 456
    Jan 18 12:26:46 macserver bootpd[41217]: DHCP DISCOVER [en1]: 1,0:16:cb:86:c4:89
    Jan 18 12:26:46 macserver bootpd[41217]: replying to 192.168.2.3
    Jan 18 12:26:46 macserver bootpd[41217]: OFFER sent <no hostname> 192.168.2.3 pktsize 300
    Jan 18 12:26:46 macserver bootpd[41217]: service time 0.090113 seconds
    Jan 18 12:26:50 macserver bootpd[41217]: DHCP REQUEST [en1]: 1,0:16:cb:86:c4:89
    Jan 18 12:26:50 macserver bootpd[41217]: replying to 192.168.2.3
    Jan 18 12:26:50 macserver bootpd[41217]: ACK sent <no hostname> 192.168.2.3 pktsize 300
    Jan 18 12:26:50 macserver bootpd[41217]: service time 0.009636 seconds
    Jan 18 12:27:21 macserver bootpd[41217]: server name macserver.miamips.net
    Jan 18 12:27:21 macserver bootpd[41217]: interface en0: ip 10.10.11.25 mask 255.255.254.0
    Jan 18 12:27:21 macserver bootpd[41217]: dhcp: re-reading lease list
    Jan 18 12:27:21 macserver bootpd[41217]: bsdpd: re-reading configuration
    Jan 18 12:27:21 macserver bootpd[41217]: bsdpd: shadow file size will be set to 48 megabytes
    Jan 18 12:27:21 macserver bootpd[41217]: bsdpd: age time 00:15:00
    Jan 18 12:27:23 macserver bootpd[41217]: server name macserver.miamips.net
    Jan 18 12:27:23 macserver bootpd[41217]: interface en0: ip 10.10.11.25 mask 255.255.254.0
    Jan 18 12:27:23 macserver bootpd[41217]: interface en1: ip 192.168.2.2 mask 255.255.255.0
    Jan 18 12:27:23 macserver bootpd[41217]: dhcp: re-reading lease list
    Jan 18 12:27:23 macserver bootpd[41217]: bsdpd: re-reading configuration
    Jan 18 12:27:23 macserver bootpd[41217]: bsdpd: shadow file size will be set to 48 megabytes
    Jan 18 12:27:23 macserver bootpd[41217]: bsdpd: age time 00:15:00
    Jan 18 12:27:24 macserver bootpd[41217]: DHCP REQUEST [en1]: 1,0:16:cb:86:c4:89
    Jan 18 12:27:24 macserver bootpd[41217]: replying to 192.168.2.3
    Jan 18 12:27:24 macserver bootpd[41217]: ACK sent <no hostname> 192.168.2.3 pktsize 310
    Jan 18 12:27:24 macserver bootpd[41217]: service time 0.002865 seconds

  • Netboot issues in snow leopard

    I have been fighting this all day, I have osx server 10.6.7 and many snow machines. i have images can see them from the client machines in startup disk but i can not seem to get them to boot from these images.
    the last 2 log say
    BSDP OFFER sent [1,10:9a:dd:44:66:60] pktsize 360
    service time 0.000007 seconds
    i can not see whats wrong
    I do not use server DHCP i have been testing with both my network DHCP and static
    also when i check the mounts for netboot folders they say everyone
    please help before I go insane

    i have been looking over that site here are the logs to the fullest
    m-002 bootpd[5945]: BSDP INFORM [en0] 1,10:9a:dd:44:66:60 NetBoot002 arch=i386 sysid=iMac11,3
    m-002 bootpd[5945]: NetBoot: [1,10:9a:dd:44:66:60] BSDP ACK[LIST] sent 10.10.0.45 pktsize 369
    m-002 bootpd[5945]: service time 0.000384 seconds
    m-002 bootpd[5945]: BSDP INFORM [en0] 1,10:9a:dd:44:66:60 NetBoot002 arch=i386 sysid=iMac11,3
    m-002 bootpd[5945]: NetBoot: [1,10:9a:dd:44:66:60] BSDP ACK[SELECT] sent 10.10.0.45 pktsize 363
    m-002 bootpd[5945]: service time 0.001220 seconds
    m-002 bootpd[5945]: BSDP DISCOVER [en0] 1,10:9a:dd:44:66:60 NetBoot002 arch=i386 sysid=iMac11,3
    m-002 bootpd[5945]: replyfile /private/tftpboot/NetBoot/NetBootSP0/IMAC INSTALL 5-16.nbi/i386/booter
    m-002 bootpd[5945]: replying to 0.0.0.0
    m-002 bootpd[5945]: BSDP OFFER sent [1,10:9a:dd:44:66:60] pktsize 360
    m-002 bootpd[5945]: service time 0.000013 seconds
    m-002 bootpd[5945]: service time 0.000015 seconds
    as far as subnets same sub i have also tried the direct connect method to eliminate all nerwork gear no luck
    Thanks in advance

  • Intervlan Routing Issues - Cannot Ping

    I'm at a loss here folks and really need some help.
    Looking for some obvious things I may be overseeing?  Here is the situation quite simply.  Turning up a new site in Mexico to connect to our network.  They have their own carrier, modem, and we use one switch and a Sonicwall TZ215 with vpn tunnel.  I configured it all in the US here and shipped it down there with a console cable.  Now I'm finishing up some additional config. I'll post the config below.
    Physical Layout:
    Sonicwall XO  --> Port 24 on Cisco 2960-X
    Avaya IP Appliance --> Port 22 on Cisco 2960-X
    Test Laptop --> Port 2 on Cisco 2960-X
    I had them down there plug in the Avaya (10.30.21.253) to port 22 because I need to access it and check its config.  The problem is, I can ping that IP from the switch itself, but from my laptop I can't ping it.  Nor can I ping it over the WAN here in the US.  The screwed up part is I can ping that gateway fine from any node on the network  (10.30.21.254).  I can also ping any of the vlan gateways ending in .245 on the switch. The tunnel networks work fine.
    Now..if I put my laptop on vlan 121, I can ping the avaya appliance just fine.  On the vlan111 network, I cannot.  IP routing is enabled.  I've also got the correct return route configured on the sonicwall (if that matters in this test scenario)
    version 15.0
    no service pad
    service timestamps debug datetime msec
    service timestamps log datetime msec
    no service password-encryption
    hostname SWMEXICO
    boot-start-marker
    boot-end-marker
    enable secret 5
    no aaa new-model
    clock timezone UTC -6 0
    clock summer-time UTC recurring
    switch 1 provision ws-c2960x-24ps-l
    ip routing
    ip dhcp excluded-address 10.30.11.1 10.30.11.10
    ip dhcp excluded-address 10.30.21.250 10.30.21.253
    ip dhcp pool PC's
     network 10.30.11.0 255.255.255.0
     default-router 10.30.11.254
     dns-server 200.33.148.202 200.33.148.196
     lease 6
    ip dhcp pool Phones
     network 10.30.21.0 255.255.255.0
     default-router 10.30.21.254
     option 176 ascii "mcipadd=10.30.21.253,mcport=1719,tftpsrvr=10.30.21.253"
     lease 6
    vtp mode transparent
    crypto pki trustpoint TP-self-signed-768520448
     enrollment selfsigned
     subject-name cn=IOS-Self-Signed-Certificate-768520448
     revocation-check none
     rsakeypair TP-self-signed-768520448
    crypto pki certificate chain TP-self-signed-768520448
     certificate self-signed 01
      30820229 30820192 A0030201 02020101 300D0609 2A864886 F70D0101 05050030
      30312E30 2C060355 04031325 494F532D 53656C66 2D536967 6E65642D 43657274
      69666963 6174652D 37363835 32303434 38301E17 0D313530 32303330 39303833
      315A170D 32303031 30313030 30303030 5A303031 2E302C06 03550403 1325494F
      532D5365 6C662D53 69676E65 642D4365 72746966 69636174 652D3736 38353230
      34343830 819F300D 06092A86 4886F70D 01010105 0003818D 00308189 02818100
      BBC0766E B4096302 C78534E0 B696E915 E16F419D 87089157 FD46E78D A024F11A
      4B1F887B AB5907A7 36E924C2 D82B0992 0FE5E50D F924CBE3 00CC022C 5FB171BF
      44333CD4 294CB9B6 CB817BAF 96319C2D F39A0862 587B2D93 D0FE1164 803AEBA5
      E6272B11 205E7B9B 4966617F D3C85B85 1AE6A4B8 5F4AB109 EE588E95 D1F9838B
      02030100 01A35330 51300F06 03551D13 0101FF04 05300301 01FF301F 0603551D
      23041830 1680141A 266167F1 91A7542E 44F9E2C8 EE876903 9EAB1330 1D060355
      1D0E0416 04141A26 6167F191 A7542E44 F9E2C8EE 8769039E AB13300D 06092A86
      4886F70D 01010505 00038181 00B1B665 621AD0DA D837ED5F 95B58666 3FBF57F9
      FFE660DE 3CD3332B 666B3445 1657898A E733D56F 18A93549 73F4CFD4 B6EA6A0C
      E89EF404 4BDA652D 103DFA54 527A31A8 0DC44B59 1E3F61EA 55912C4C ECB24619
      BD56A7EA 97A82939 7CFA329A BD72CA6B 1865DE28 FD511C8D 57574351 F53772B7
      8B3A39DF 4A5690A1 DCAEA37B AF
            quit
    spanning-tree mode pvst
    spanning-tree extend system-id
    vlan internal allocation policy ascending
    vlan 30
     name Servers
    vlan 99
     name Sonicwall
    vlan 101
     name Management
    vlan 111
     name PC's
    vlan 121
     name Phones
    vlan 145
     name Printers
    interface FastEthernet0
     no ip address
     no ip route-cache
    interface GigabitEthernet1/0/1
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/2
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/3
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/4
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/5
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/6
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/7
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/8
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/9
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/10
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/11
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/12
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/13
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/14
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/15
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/16
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/17
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/18
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/19
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/20
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/21
     switchport access vlan 111
     switchport mode access
     switchport voice vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/22
     description Avaya IP04
     switchport access vlan 121
     spanning-tree portfast
    interface GigabitEthernet1/0/23
     description Server
     switchport access vlan 30
     switchport mode access
     spanning-tree portfast
    interface GigabitEthernet1/0/24
     description Link to Sonicwall
     switchport trunk native vlan 99
     switchport trunk allowed vlan 30,99,101,111,121,145
     switchport mode trunk
    interface GigabitEthernet1/0/25
    interface GigabitEthernet1/0/26
    interface GigabitEthernet1/0/27
    interface GigabitEthernet1/0/28
    interface Vlan1
     no ip address
     shutdown
    interface Vlan30
     description Servers
     ip address 10.30.0.254 255.255.255.0
    interface Vlan99
     description Sonicwall
     ip address 10.30.99.253 255.255.255.0
    interface Vlan101
     description Management
     ip address 10.30.1.254 255.255.255.0
    interface Vlan111
     description PC's
     ip address 10.30.11.254 255.255.255.0
    interface Vlan121
     description Phones
     ip address 10.30.21.254 255.255.255.0
    interface Vlan145
     description Printers
     ip address 10.30.45.254 255.255.255.0
    ip http server
    ip http secure-server
    ip route 0.0.0.0 0.0.0.0 10.30.99.254
    *********************************************************^C
    line con 0
    line vty 0 4
     password
     login
    line vty 5 15
     login
    end
    SWMEXICO#
    Also, on the side, when I ping from a host for example, how does the traffic go..does it goto the sonicwall first because of the ip route statement, then the sonicwall returns the traffic back to the switch and the ping traffic to the host?  Or does local traffic not even traverse the sonicwall

    Hey Jon,
    Here is the sh int vlan121 that you asked about.
    SWME01#sh ip interface vlan 121
    Vlan121 is up, line protocol is up
      Internet address is 10.30.21.254/24
      Broadcast address is 255.255.255.255
      Address determined by non-volatile memory
      MTU is 1500 bytes
      Helper address is not set
      Directed broadcast forwarding is disabled
      Outgoing access list is not set
      Inbound  access list is not set
      Proxy ARP is enabled
      Local Proxy ARP is disabled
      Security level is default
      Split horizon is enabled
      ICMP redirects are always sent
      ICMP unreachables are always sent
      ICMP mask replies are never sent
      IP fast switching is enabled
      IP Flow switching is disabled
      IP CEF switching is enabled
      IP CEF switching turbo vector
      IP Null turbo vector
      IP multicast fast switching is disabled
      IP multicast distributed fast switching is disabled
      IP route-cache flags are Fast, CEF
      Router Discovery is disabled
      IP output packet accounting is disabled
      IP access violation accounting is disabled
      TCP/IP header compression is disabled
      RTP/IP header compression is disabled
      Probe proxy name replies are disabled
      Policy routing is disabled
      Network address translation is disabled
      BGP Policy Mapping is disabled
      Input features: MCI Check
      Output features: Input interface drop, Check hwidb
    SWME01#

  • Netboot Error Code: Mac OS X Server 10.4

    Hello,
    I have been working on a two-fold Netboot issue when trying to pull an image off of a 10.2.8 iMac and distribute it via Netboot from a 10.4 server. First off, image creation worked just fine. I copied the System Image tool from the server to my 10.4 G4 Powerbook in target mode. The image created OK, and I was able to share it off the server, but after the spinning globe, I got screen corruption that looked like frozen static in the middle of the screen. At this point I pursued troubleshooting the image. I did some reading on various web pages, and got a lead that suggested the image creation machine needs to be the same OS version as the image. (Didn't make much sense, but it was 3PM and I was getting tired of working on it) The System Image utility doesn't work from 10.4 to 10.2.8 apparently as it wouldn't start. I removed the images from the server and unchecked all the images in Server Admin under Netboot. At this point Netboot crashed and gave me this error when trying a "serveradmin start netboot", which persisted even after a reboot: serveradmin[12660] Exception in doCommand: * -[NSCFArray addObject:]: attempt to insert nil
    netboot:error = "NILRESPONSEERR (* -[NSCFArray addObject:]: attempt to insert nil)"
    Wierd. Our main Mac guy that handles this stuff is overseas for Christmas, so I'm stuck with making this work. I picked up quite a bit and I'm a fast learner, but I'm just not very adept with the Mac imaging stuff yet. Maybe I'm missing something basic, but that's why I'm asking. Any ideas?
    TIA
    Charlie
    G4 Server Mac OS X (10.4.3)
    G4 Server   Mac OS X (10.4.3)  

    Hello,
    I have been working on a two-fold Netboot issue when trying to pull an image off of a 10.2.8 iMac and distribute it via Netboot from a 10.4 server. First off, image creation worked just fine. I copied the System Image tool from the server to my 10.4 G4 Powerbook in target mode. The image created OK, and I was able to share it off the server, but after the spinning globe, I got screen corruption that looked like frozen static in the middle of the screen. At this point I pursued troubleshooting the image. I did some reading on various web pages, and got a lead that suggested the image creation machine needs to be the same OS version as the image. (Didn't make much sense, but it was 3PM and I was getting tired of working on it) The System Image utility doesn't work from 10.4 to 10.2.8 apparently as it wouldn't start. I removed the images from the server and unchecked all the images in Server Admin under Netboot. At this point Netboot crashed and gave me this error when trying a "serveradmin start netboot", which persisted even after a reboot: serveradmin[12660] Exception in doCommand: * -[NSCFArray addObject:]: attempt to insert nil
    netboot:error = "NILRESPONSEERR (* -[NSCFArray addObject:]: attempt to insert nil)"
    Wierd. Our main Mac guy that handles this stuff is overseas for Christmas, so I'm stuck with making this work. I picked up quite a bit and I'm a fast learner, but I'm just not very adept with the Mac imaging stuff yet. Maybe I'm missing something basic, but that's why I'm asking. Any ideas?
    TIA
    Charlie
    G4 Server Mac OS X (10.4.3)
    G4 Server   Mac OS X (10.4.3)  

  • NetBoot Older Systems

    Have a Mac Pro set up as an AST & Reimaging server via Netboot/Install, and am having difficulties getting it to work with older Macs (all Intel based). I deal with the full range of x86 Macs, and even the odd PPC system. Running Mac OS X Server 10.6.6, using only the built-in tools for the moment. Nothing like DeployStudio. The one and only thing is I can't remember if I made this retail disc image before or after installing the 10.6.6 update (the disc was 10.6.3). I don't see why that would be an issue, but will mention it anyway.
    Replaced the HDD in a Mid-07 iMac the other day, and went to boot my copy of the 10.6 Retail disc from the netboot server to install an OS on it. The iMac flatly refuses to show any netboot images from the EFI boot selector. At one point it showed a generic netboot image icon, which was strobing and couldn't be selected. That lasted for maybe 30-60 seconds and then it disappeared.
    While testing to make sure it wasn't something with my server, I grabbed a mid-2010 MBP, which picked up on the images immediately. So I booted off an external HDD on the iMac, and found that the startup disk preference pane recognized the netboot image almost immediately as well, but if I tried to reboot using that image, it just sat there until it timed out.
    I don't have the exact logs from the server at the moment, but from the looks of it, the server was trying to send the EFI image to the iMac, but the iMac was refusing to accept it.
    I know the mid-2007 line of everything tended to be crap, but I had a similar problem with a Late 2008 MBP earlier in the day. It also refused to show any netboot images, even after I let it sit for probably 30 minutes while I did something else. Apple's documentation has been found severely wanting on these kinds of subjects. Is there some known issue with older Macs and netboot/install? Is it possibly that the drive has yet to be partitioned? That would be a huge oversight, but I can work around that. Looking for any suggestions and/or solutions that may help me to resolve this issue.

    AST related issues should technically be redirected to AASP chat...
    But I've had issues with using other NetBoot images on an AST server. As a result, I host that image by itself on a separate NetBoot server. As for one machine seeing the server in EFI and one not, there probably isn't an explanation for that. When my NetBoot server does that, I just start and stop the NetBoot service and cross my fingers. Auto discovery just plain out stops working sometimes and doesn't work at all for some machines unless the logic board is replaced. Also, the disk being formatted is irrelevant to the machine booting so I wouldn't be too worried about that.
    On the note of the Mid2007 iMac, check the optical drive cable. If faulty (in my experience) it can cause NetBoot issues.
    At the boot picker, only Mid2010 and newer machines (with the exception of the older Air) should show the available images on a server. Machines older than Mid2010 will show the IP of the NetBoot server and that would be it (though I realize you weren't getting anything on the iMac). Are you always option-booting or holding "N"?

  • Aggregate (trunked) link and NetBoot

    The previous thread on link aggregation was archived without a solution last year. OS X 10.4.2 was the last version tested in that thread.
    I have an xserve with an aggregate link. Everything works well except netboot. Half the time the computer will boot from it's local hard drive and half the time it will netboot. So it seems Apple 'sorta' fixed this problem.
    Is anybody out there doing the same thing? How is it working for you?

    v10.4.3 is the first version of Server to support the NetBoot service running on a link aggregate.
    I have it up and running on v10.4.7. I had to remember to reconfigure my DHCP service too, so that it was going out on bond0 instead of en0.
    Admittedly, I haven't pushed this yet to find to verify its reliability. We have netboot issues even with a single port. Ocassionally clients will fail to netboot some of the time. No apparent rhyme nor reason to it.
    Xserve G5 Dual 2.3GHz   Mac OS X (10.4.7)  

  • Help with simple interVlan routing on L3 switch

    Hi all - I just can't get my head around this really simple interVlan routing issue.  I have two VLANs (1 & 6) on a 3560 L3 switch.  I simply need to route between them.  Here is how I have it set up:
    Firewall is the VLAN1 client's default gateway:
    10.10.22.1 /255.255.255.0
    3560switch config:
    ip subnet-zero
    ip routing
    VLAN1:
    (hosts on 10.10.22.x/255.255.255.0; gateway 10.10.22.1)
    int vlan1
    ip address 10.10.22.254 255.255.255.0
    no shutdown
    VLAN6: (hosts on 192.168.25.x/255.255.255.0; gateway 192.168.25.1)
    ip address 192.168.25.1 255.255.255.0
    no shutdown
    ip classless
    int gi0/31 (an available unused port)
    no switchport
    ip address ?.?.?.?
    no shutdown
    Is the issue that all my 10.10.22.x clients are going to 10.10.22.1 trying to find 192.168.25.x, when they would need to go to 10.10.22.254; then the switch should have an ip route of 0.0.0.0 0.0.0.0 10.10.22.1? Then give the router on gi0/31 the 10.10.22.254 address?
    (as a side note, it would be easier for me to change the gateway's IP than to change each VLAN1 client's IP.)
    Thanks for any help!

    Hi all - I just can't get my head
    around this really simple interVlan routing issue.  I have two VLANs (1
    & 6) on a 3560 L3 switch.  I simply need to route between them.
    Here is how I have it set up:Firewall is the VLAN1 client's default gateway:
    10.10.22.1 /255.255.255.03560switch config:
    ip subnet-zero
    ip routingVLAN1:
    (hosts on 10.10.22.x/255.255.255.0; gateway 10.10.22.1)
    int vlan1
    ip address 10.10.22.254 255.255.255.0
    no shutdownVLAN6: (hosts on 192.168.25.x/255.255.255.0; gateway 192.168.25.1)
    ip address 192.168.25.1 255.255.255.0
    no shutdownip classlessint gi0/31 (an available unused port)
    no switchport
    ip address ?.?.?.?
    no shutdown***Is
    the issue that all my 10.10.22.x clients are going to 10.10.22.1 trying
    to find 192.168.25.x, when they would need to go to 10.10.22.254; then
    the switch should have an ip route of 0.0.0.0 0.0.0.0 10.10.22.1? Then
    give the router on gi0/31 the 10.10.22.254 address?(as a side note, it would be easier for me to change the gateway's IP than to change each VLAN1 client's IP.)Thanks for any help!
    Hi,
    With the above configuuration vlan 1 users will be going to firewll and if they want to reach vlan 6 firewall should have rule to permit for vlan 6 subnet and route towards vlan 6 interface and which is not there is your network.
    Just clarify few things you want firewall to come into picture for every traffic which goes between vlan or not and in interface gi0/31 you will be connecting router also is this router is sending traffic to outside world if yes then you need to change some design configuration to route tha traffic from vlans to outside world.
    If you want only inter vlan routing between vlan 1 and vlan 6 via firewall then make another zone in firewall and place that in vlan 6 with ip address as given in vlan 1 so that vlan 6 users can point traffic towards vlan 6 interface of firewall and in firewall just permit the vlan 6 communication with vlan 1 and drop a route for vlan 6 towards switch vlan 6 interface.
    and if between vlans you dont want firewall to come into picture then the best is create three vlan one for vlan 1,vlan 6 and outside vlan between router and firewall and drop a default route towards firewall.In this case inter vlan routing will be taken care by switch and traffic towards outside world will scaaned as per rule given in firewall.
    Hope to help
    If helpful do rate the post
    Ganesh.H

  • Netboot doesn't work; DHCP issue?

    I'm setting up NetBoot for the first time on my Leopard Xserve, trying to do NetInstall on some G4 clients.
    Imaging seemed to work fine and the client boots as far as the grey apple screen - but then the client crashes with "You need to restart your computer now".
    The log looks like this:
    May 19 03:42:29 blue bootpd[64401]: can't open /etc/bootptab
    May 19 03:42:29 blue bootpd[64401]: server name blue.pvpa.com
    May 19 03:42:29 blue bootpd[64401]: interface en0: ip 192.168.1.15 mask 255.255.255.0
    May 19 03:42:29 blue bootpd[64401]: subnets: Failed to convert 'router': Invalid IP address
    May 19 03:42:29 blue bootpd[64401]: bsdpd: re-reading configuration
    May 19 03:42:29 blue bootpd[64401]: bsdpd: shadow file size will be set to 48 megabytes
    May 19 03:42:29 blue bootpd[64401]: bsdpd: age time 00:15:00
    I'm not running DHCP service on my Xserve - DHCP is coming from the router. The client does seem to be getting an IP address, according to Server Admin --> NetBoot --> Clients. Do I need to do something different with DHCP on the Xserve, and if so what?
    Also, I tried creating /etc/bootptab by hand but that didn't make a difference either.

    May 19 03:42:29 blue bootpd64401: subnets: Failed to convert 'router': Invalid IP address
    This might be an issue... I've never seen this log before. Is your server on a different subnet then the clients you are attempting to boot? NetBoot doesn't work across subnets without some extra work.

  • AP2600I - autonomous - intervlan issue

    Hi all,
    We are deploying an access point SAP2600I and we are facing a network communication issue.
    2602I - software version : 15.2(2)JB
    AP have a static IP address, mask and default gateway
    LAN is configured properly
    AP can ping and communication just in the same subnet
    Intervlan communication is not working with any protocol 
    We have around 20 Access Point with the same behavior.
    Workaround to AP2602:  Upgrade to software version 15.3(3)JAB
    Do you know if it is a bug ? Do you Know if have any other workaround without software upgrade ?
    thanks 

    Hi Scott,
    I tryed search any information about this issue but I not find. I just perform the upgrade and it resolved the problem.
    Before upgrade, the AP can ping just layer 2
    After upgrade, the AP can ping Layer3 interfaces
    I would like to be if exist any bug reported, because I have around 200 Access Point in the remotes sites to be deployed.
    thanks and regards,
    Murilo

Maybe you are looking for

  • Frontierville will not open in firefox 4 (on mac)

    Just installed firefox 4. Zynga Frontierville will not open. All I get is a blank page

  • Newbie - troubleshoot flash video

    HI All Flash is not my normal area so I apologise upfront if I don't use the correct terminology. Using Flash Professional 8 I want to convert movie files such as .avi into a flash video file to be viewed online. When I do this it outputs the audio b

  • Duplicating Doc for Two Across Printing

    I have finished a 4 x 8in information card - front page 1 and back page 2.  The printer requested that, if possible, I provide a PDF file with the cards two across for printing.  I have spent the past two days trying to determine how this could be do

  • Re installing Premiere Elements 9. I have Serial number but no access to software cd.

    Re installing Premiere Elements 9. I have Serial number but no access to software cd.\ fDoes anyone know how to go about this. Its so difficult to download old software with all of adobe's promotion of its newer stuff.

  • Launchpad show "server offline", but the server is running

    Greetings, I have a MS-Server 2012 Essential and it work very fine many years. But now the Launchpad on my client is showing "Server offline"! I have installed Teamviewer on my server and I can connect from the internet to my server. Also a ping to m