Skip to main content

Weird CatOS to IOS Trunk Problem – Cannot Ping

I was setting this very basic configuration up the other evening and could not get basic L3 connectivity up and running.

 

I have a ASR 1002 on one side and an Catalyst 6509 running Hybrid CATOS and IOS. The configuration is basically to connect two devices for routing using 802.1q vlans. Here is the configs, but I cannot ping between the devices.

ASR1002



interface GigabitEthernet0/0/2
no ip address
negotiation auto
!
interface GigabitEthernet0/0/2.700
encapsulation dot1Q 700
ip address 172.24.253.17 255.255.255.252
ip ospf network point-to-point

6509 – Switch



set vlan 700   3/3
clear trunk 3/3  1-699,701-1005,1025-4094
set trunk 3/3  on dot1q 700
set spantree portfast    3/3 enable trunk
end

6509 - MSFC



interface Vlan700
ip address 172.24.253.18 255.255.255.252
ip ospf network point-to-point
end


I could not see any issue, so to confirm try and establish if it was some trunking issue, I remove the trunk and used the main interface on the ASR1000 and access port to vlan on the 6509 and I could ping between the devices no problem.

 

Happy the L2 was now establish I decided to rebuild the configuration again and still had the same issues. Not sure why I tried the next step but I modified the configuration on the 6509 to be this:

I issued set vlan 1   3/3

6509 - Switch



#module 3 : 16-port 1000BaseX Ethernet
clear trunk 3/3  1-699,701-1005,1025-4094
set trunk 3/3  on dot1q 700
set spantree portfast    3/3 enable trunk
end


Now everything is working ok ?

It also works with: set vlan 10   3/3 just not with the same VLAN as the trunk is using ???

 

It is Working


So in this situation it seems I cannot have the switchport configured with the same vlan id as I want to trunk. I found this really weird since I had stripped all vlans off the trunk anyway? Hope this helps some one else. Not that I really needed the Vlan assigned, so no big deal in most cases (what was I thinking!!!).

 

Code Level:


ASR1002


Cisco IOS Software, IOS-XE Software (PPC_LINUX_IOSD-ADVENTERPRISEK9-M), Version 15.1(1)S1, RELEASE SOFTWARE (fc1)
asr1000rp1-adventerprisek9.03.02.01.S.151-1.S1.bin

6509 – Switch


WS-C6509 Software, Version NmpSW: 7.6(9)
Copyright (c) 1995-2004 by Cisco Systems
NMP S/W compiled on Aug 27 2004, 20:05:14

System Bootstrap Version: 7.1(1)
System Boot Image File is 'bootflash:cat6000-sup2k8.7-6-9.bin'

6509 – MFSC


ROM: System Bootstrap, Version 12.1(11r)E1, RELEASE SOFTWARE (fc1)
BOOTFLASH: MSFC2 Software (C6MSFC2-BOOT-M), Version 12.1(8b)E11, EARLY DEPLOYMENT RELEASE SOFTWARE (fc1)

 

Comments

Popular posts from this blog

Break the Network Emulators out of the Cloud

Cisco IOU and JunoSphere Recently both Cisco and Juniper have announced the availability of online resources to provide hands on training over the internet. They have built software emulators in the cloud that can be accessed remotely for a cost. These solutions are based purely around the certification programs and therefore are pretty rigid in the topology that are provided, not to mention the re-occurring cost. http://www.juniper.net/us/en/company/press-center/press-releases/2011/pr_2011_05_16-03_01.html https://learningnetworkstore.cisco.com/market/prod/listSubCatLearnLab.se.work?TRGT=85&/nxt/rcrs/=2559 Rack Rentals There are training providers such as Internetwork Expert (http://www.ine.com/) and IPexpert (http://www.ipexpert.com/) who provide rack rentals based on their training materials. These guy cannot possibly compete going forward. To keep these sustainable they will need to reduce the overhead of building physical racks, providing power and space for the racks. Using e

VMWARE ESXi 5.0 Command line quickies

Hi, It has been a long time since my last posts, but recently I have been working on my home ESXi lab so I thought I would share. I switched over to using Apple Mac just over a year ago, so I don't have a windows machine running by default to run the vSphere client software and generally all I want to do is startup VMs and switch off the ESXi server when I am done. I did some searching and found that I could use vmware vim-cmd if I SSHed into the ESXi server. This need to be enabled at the console, then you can use putty or your tool of choice to connect. Anyway there are several commands the following to me are most useful. List all Virtual Machines vim-cmd vmsvc/getallvms Get a Virtual Machines state (on/off etc) vim-cmd  vmsvc/power.getstate Power on a virtual machine vim-cmd vmsvc/power.on Combining command to a one liner you can find out the power on state of all Virtual Machines vim-cmd vmsvc/getallvms && for x in `vim-cmd vmsvc/getallvms|

Where are all the AAA and PKI solutions gone for Dot1x

More Question than answers (This series will be based on an enterprise with >20,000 dot1x devices) I have been looking into dot1x authentication for Wired and Wireless devices based on device identity using x.509 Certificates. While I understand PKI, AAA, PEAP and sorts I had never really had the opertunity to bring these technologies together. I quickly found out that despite this stuff being around for years,  it was difficult to answer the following questions: Which PKI solution should I use? Which AAA solution should I use? How to setup the PKI solution? Does the PKI server need to be part of AD? What if the clients are not in AD e.g. Wireless Tablets? How do I issue certificates for devices? How to configure the devices (wired and wireless)? What AAA server do I use? How do configure the rules and policies and identify clients?   What are the answers? I am going to kick off a series here at networking-guru.net that tries to address the question above; I have l