webForumDet fria alternativet

Cisco 2801, routa mellan HWICar

Nätverk

4 svar · 443 visningar · startad av Astrakan

Medlem sedan mars 20085 inlägg
Frågan#1

Hej,

Har en 2801 där jag satt i 2st 4-portars HWIC:ar (lager 2 switchmoduler med SVI mot routern).
Routern används i ett testnät för att simulera internet.
Till routern ansluts 8 st noder, 1 för varje port.
Varje nod sitter på ett eget nät så jag har confat separata VLAN på alla switchportarna och satt respektive nods gw-adress på respektive VLAN-interface.

Problemet är att det är bara på den ena HWICen som trafik routas mellan VLANen. HWICen som sitter i slot 1 funkar klockrent medan den i slot 3 inte fungerar alls. Och det fungerar heller inte att routa mellan vlan som sitter på separata HWIC:ar.
Jag har link på allla portar men 2801an routar inte trafiken mellan VLANen i modulen på slot 3, men på slot 1 kan jag pinga till/från alla portar utan problem.

Alla switchportar och VLAN är uppsatta på exakt samma sätt.
Vad kan skilja mellan slot 1 & 3 som orsakar detta???

ip routing är igång och alla ifc är uppe.

Tack på förhand!!

/U

Medlem sedan jan. 2004527 inlägg
#2

config du kan klistra in?
antar iofs att du har samma conf på alla portar(?)

Medlem sedan mars 20085 inlägg
#3

Här är den. Japp samma conf på alla portar.

Current configuration : 3015 bytes
!
version 12.4
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname XXXXcisco2801
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 3 log
security passwords min-length 6
logging buffered 51200 debugging
logging console critical
enable secret xxxxxxxxxxxxxxxxxxxxxxx
!
no aaa new-model
clock timezone PCTime 1
clock summer-time PCTime date Mar 30 2003 2:00 Oct 26 2003 3:00
ip cef
!
!
!
!
ip domain name yourdomain.com
!
username XXXXX privilege 15 secret xxxxxxxxxxxxxxxxxxxx
!
!
ip tcp synwait-time 10
!
!
interface FastEthernet0/0
description $ETH-SW-LAUNCH$$INTF-INFO-FE 0$$ES_LAN$$FW_INSIDE$$ETH-LAN$
ip address 192.168.1.1 255.255.255.0
ip nat inside
ip route-cache flow
duplex auto
speed auto
!
interface FastEthernet0/1
description $ES_WAN$$FW_OUTSIDE$
ip address 192.168.2.1 255.255.255.0
ip nat outside
ip route-cache flow
duplex auto
speed auto
!
interface FastEthernet0/1/0
switchport access vlan 12
!
interface FastEthernet0/1/1
switchport access vlan 13
!
interface FastEthernet0/1/2
switchport access vlan 11
!
interface FastEthernet0/1/3
switchport access vlan 16
!
interface FastEthernet0/3/0
switchport access vlan 10
!
interface FastEthernet0/3/1
switchport access vlan 11
!
interface FastEthernet0/3/2
switchport access vlan 12
!
interface FastEthernet0/3/3
switchport access vlan 13
!
interface Vlan1
ip address 192.168.20.1 255.255.255.0
ip route-cache flow
!
interface Vlan2
ip address 192.168.21.1 255.255.255.0
!
interface Vlan10
description XXXXXX
ip address <ipadress> <nätmask>
!
interface Vlan11
description XXXXXX
ip address <ipadress> <nätmask>
!
interface Vlan12
description XXXXXX
ip address <ipadress> <nätmask>
!
interface Vlan13
description XXXXXX
ip address <ipadress> <nätmask>
!
interface Vlan14
description XXXXXX
ip address <ipadress> <nätmask>
!
interface Vlan15
description XXXXXX
ip address <ipadress> <nätmask>
!
interface Vlan16
description XXXXXX
ip address <ipadress> <nätmask>
!
ip route 0.0.0.0 0.0.0.0 FastEthernet0/1
!
ip http server
ip http authentication local
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 1 interface FastEthernet0/1 overload
!
logging trap debugging
access-list 1 remark INSIDE_IF=FastEthernet0/0
access-list 1 remark SDM_ACL Category=2
access-list 1 permit 192.168.1.0 0.0.0.255
!
control-plane
!
banner login ^CAuthorized access only!
Disconnect IMMEDIATELY if you are not an authorized user!^C
!
line con 0
login local
transport output telnet
line aux 0
login local
transport output telnet
line vty 0 4
privilege level 15
login local
transport input telnet
line vty 5 15
privilege level 15
login local
transport input telnet
!
scheduler allocate 20000 1000
end

Medlem sedan mars 20085 inlägg
#4

Har kommit lite längre med detta. Genom att stacka switchmodulerna så har jag fått även modul 3 att fungera.
Det problem som kvarstår nu är att routern inte verkar skyffla trafik mellan switchmodulerna.
Har kopplat in 2 klienter i routern, en på switchmodul 0/1 och den andra på switchmodul 0/3:

- Routern kan pinga båda klienterna.
- Båda klienterna kan pinga routern/vlan-ifc:t (alltså sin egen gw)
- Men....
Klient 1 kan inte pinga klient 2 och vice versa. Får "Destination host
unreachable"

Running config-vy över intefacen nu:

!
interface FastEthernet0/1/0
switchport access vlan 10
!
interface FastEthernet0/1/1
switchport access vlan 11
!
interface FastEthernet0/1/2
switchport access vlan 12
!
interface FastEthernet0/1/3
switchport stacking-partner interface FastEthernet0/3/0
!
interface FastEthernet0/3/0
switchport stacking-partner interface FastEthernet0/1/3
!
interface FastEthernet0/3/1
switchport access vlan 13
!
interface FastEthernet0/3/2
switchport access vlan 14
!
interface FastEthernet0/3/3
switchport access vlan 15
!
interface Vlan1
ip address <ip adress> <nätmask>
ip route-cache flow
!
interface Vlan2
ip address <ip adress> <nätmask>
!
interface Vlan10
description XXXXXX
ip address <ip adress> <nätmask>
!
interface Vlan11
description XXXXXX
ip address <ip adress> <nätmask>
!
interface Vlan12
description XXXXXX
ip address <ip adress> <nätmask>
!
interface Vlan13
description XXXXXX
ip address <ip adress> <nätmask>
!
interface Vlan14
description XXXXXX
ip address <ip adress> <nätmask>
!
interface Vlan15
description XXXXXX
ip address <ip adress> <nätmask>
!
interface Vlan16
description XXXXXX
ip address <ip adress> <nätmask>
!
ip route 0.0.0.0 0.0.0.0 FastEthernet0/1

Medlem sedan mars 20085 inlägg
#5

Suttit och testat och ändrat och testat och ändrat här idag och nu fungerar det klockrent med nedan config.
Alla hostar kan pinga alla hostar och vlan-ifc. Oavsett vilken modul de sitter på.

Current configuration : 3147 bytes
!
version 12.4
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname XXXXX_cisco2801
!
boot-start-marker
boot-end-marker
!
security authentication failure rate 3 log
security passwords min-length 6
logging buffered 51200 debugging
logging console critical
enable secret 5 XXXXX
!
no aaa new-model
clock timezone PCTime 1
clock summer-time PCTime date Mar 30 2003 2:00 Oct 26 2003 3:00
ip cef
!
!
!
!
ip domain name yourdomain.com
!
username sina privilege 15 secret 5 XXXXX
!
!
ip tcp synwait-time 10
!
!
interface FastEthernet0/0
description $ETH-SW-LAUNCH$$INTF-INFO-FE 0$$ES_LAN$$FW_INSIDE$$ETH-LAN$
ip address 192.168.1.1 255.255.255.0
ip nat inside
ip route-cache flow
duplex auto
speed auto
!
interface FastEthernet0/1
description $ES_WAN$$FW_OUTSIDE$
ip address 192.168.2.1 255.255.255.0
ip nat outside
ip route-cache flow
duplex auto
speed auto
!
interface FastEthernet0/1/0
switchport access vlan 10
!
interface FastEthernet0/1/1
switchport access vlan 11
!
interface FastEthernet0/1/2
switchport access vlan 12
!
interface FastEthernet0/1/3
description Stackingpartner slot 1
switchport stacking-partner interface FastEthernet0/3/0
!
interface FastEthernet0/3/0
description Stackingpartner slot 3
switchport stacking-partner interface FastEthernet0/1/3
!
interface FastEthernet0/3/1
switchport access vlan 13
!
interface FastEthernet0/3/2
switchport access vlan 14
!
interface FastEthernet0/3/3
switchport access vlan 15
!
interface Vlan1
ip address 192.168.20.1 255.255.255.0
ip route-cache flow
!
interface Vlan2
ip address 192.168.21.1 255.255.255.0
!
interface Vlan10
description XXXXX
ip address <ip adress> <nätmask>
!
interface Vlan11
description XXXXX
ip address <ip adress> <nätmask>
!
interface Vlan12
description XXXXX
ip address <ip adress> <nätmask>
!
interface Vlan13
description XXXXX
ip address <ip adress> <nätmask>
!
interface Vlan14
description XXXXX
ip address <ip adress> <nätmask>
!
interface Vlan15
description XXXXX
ip address <ip adress> <nätmask>
!
interface Vlan16
description XXXXX
ip address <ip adress> <nätmask>
!
ip route 0.0.0.0 0.0.0.0 FastEthernet0/1
!
ip http server
ip http authentication local
ip http timeout-policy idle 60 life 86400 requests 10000
ip nat inside source list 1 interface FastEthernet0/1 overload
!
logging trap debugging
access-list 1 remark INSIDE_IF=FastEthernet0/0
access-list 1 remark SDM_ACL Category=2
access-list 1 permit 192.168.1.0 0.0.0.255
!
control-plane
!
banner login ^CAuthorized access only!
Disconnect IMMEDIATELY if you are not an authorized user!^C
!
line con 0
login local
transport output telnet
line aux 0
login local
transport output telnet
line vty 0 4
privilege level 15
login local
transport input telnet
line vty 5 15
privilege level 15
login local
transport input telnet
!
scheduler allocate 20000 1000
end

338 ms totalt · 4 externa anrop · v20260731065814-full.a51de22e
206 ms — deklarationer (db)
0 ms — hämta statistik (cache)
129 ms — hämta tråd, inlägg och bilagor (db)
206 ms — ändringar (db)