Jump to content

Recommended Posts

Posted

Hi all,

 

Got a bit of a weird one here...

 

Just had two switches fail on me. Cisco 3560s. (Switches 2 and 3)

 

Switch layout as follows...

 

Core <<< >>> Switch_1 <<< >>> Switch_2 <<< >>> Switch_3

 

 

Only been doing the job for a week with no handover documentation from the previous.

No passwords for switches and have tried to do password recovery without any luck.

 

Anyway... managed to find two new 3560s. Plugged them in with fibre links, configured both switches a very basic config using the startup wizard.

 

Hostname.

Set the enable and VT passwords.

Vlan1 as management

 

No further VLANS added.

No configuration changes made to ports.

 

 

Now, here is where the problem starts on both switches 2 and 3.

 

I initially set up Vlan1 to pick up an IP from the DHCP Server (Windows 2012) - Just to ensure connectivity!

No good.

 

Set Vlan1 with a static IP, subnet, etc. Can't ping my way through the network or any of the other switches.

CDP Neighbors shows the correct devices at either end of the fibre links.

 

No IP addresses leased to client devices.

 

 

However...

 

If I remove the switch from the cab and plug it into a directly into a known working switch via Ethernet, it'll pick up an IP address and issue addresses to clients.

 

What am I missing here? I can't get into the other switches to see their configs but I know 'Old Switch 2' had its fibre connections set as trunk ports and there were two additional VLANS (10 and 20) but these were not assigned to any other ports.

 

I have configured the fibre interfaces as trunks and checked that these are associated with Vlan1, still no luck.

 

Why would DHCP pass through the Ethernet ports but not the fibre connections?

 

Any help would be greatly appreciated.

 

Gav

Posted (edited)

Can you post configs of Switch 2 and 3 please. It would be good to understand what you have done already.

 

Why would DHCP pass through the Ethernet ports but not the fibre connections?

 

They are probably not configured properly. Could be a native VLAN or encapsulation miss match.

 

When you plugged the switch into the copper port and got IP addresses do you know if it forms an access port or trunk port?

 

Thanks

Edited by FN-GM
Posted

Yes, no problem...

 

Switch_2 As follows...

 

SW_02#sh run

Building configuration...

 

Current configuration : 1366 bytes

!

version 12.2

no service pad

service timestamps debug uptime

service timestamps log uptime

no service password-encryption

!

hostname SW_02

!

enable secret 5 $1$dNw1$7RyMWhj9MXT2MVI6NiYfO1

enable password ******

!

no aaa new-model

ip subnet-zero

!

!

!

!

!

!

no file verify auto

spanning-tree mode pvst

spanning-tree extend system-id

!

vlan internal allocation policy ascending

!

interface FastEthernet0/1

!

interface FastEthernet0/2

!

interface FastEthernet0/3

!

interface FastEthernet0/4

!

interface FastEthernet0/5

!

interface FastEthernet0/6

!

interface FastEthernet0/7

!

interface FastEthernet0/8

!

interface FastEthernet0/9

!

interface FastEthernet0/10

!

interface FastEthernet0/11

!

interface FastEthernet0/12

!

interface FastEthernet0/13

!

interface FastEthernet0/14

!

interface FastEthernet0/15

!

interface FastEthernet0/16

!

interface FastEthernet0/17

!

interface FastEthernet0/18

!

interface FastEthernet0/19

!

interface FastEthernet0/20

!

interface FastEthernet0/21

!

interface FastEthernet0/22

!

interface FastEthernet0/23

!

interface FastEthernet0/24

!

interface GigabitEthernet0/1

!

interface GigabitEthernet0/2

!

interface Vlan1

ip address dhcp

!

ip classless

ip http server

ip http secure-server

!

!

control-plane

!

!

line con 0

line vty 0 4

password ******

no login

line vty 5 15

password ******

no login

!

end

 

SW_02#

 

 

 

Switch_3 as follows...

 

SW_03#sh run

Building configuration...

 

Current configuration : 1366 bytes

!

version 12.2

no service pad

service timestamps debug uptime

service timestamps log uptime

no service password-encryption

!

hostname SW_03

!

enable secret 5 $1$dNw1$7RyMWhj9MXT2MVI6NiYfO1

enable password *****

!

no aaa new-model

ip subnet-zero

!

!

!

!

!

!

no file verify auto

spanning-tree mode pvst

spanning-tree extend system-id

!

vlan internal allocation policy ascending

!

interface FastEthernet0/1

!

interface FastEthernet0/2

!

interface FastEthernet0/3

!

interface FastEthernet0/4

!

interface FastEthernet0/5

!

interface FastEthernet0/6

!

interface FastEthernet0/7

!

interface FastEthernet0/8

!

interface FastEthernet0/9

!

interface FastEthernet0/10

!

interface FastEthernet0/11

!

interface FastEthernet0/12

!

interface FastEthernet0/13

!

interface FastEthernet0/14

!

interface FastEthernet0/15

!

interface FastEthernet0/16

!

interface FastEthernet0/17

!

interface FastEthernet0/18

!

interface FastEthernet0/19

!

interface FastEthernet0/20

!

interface FastEthernet0/21

!

interface FastEthernet0/22

!

interface FastEthernet0/23

!

interface FastEthernet0/24

!

interface GigabitEthernet0/1

!

interface GigabitEthernet0/2

!

interface Vlan1

ip address dhcp

!

ip classless

ip http server

ip http secure-server

!

!

control-plane

!

!

line con 0

line vty 0 4

password *****

no login

line vty 5 15

password *****

no login

!

end

 

SW_03#

Posted (edited)

EDIT: Hang on before you do this. Can you do "Show VLAN" and "Show VTP status" please?

 

 

When you connect via a console cable do you see any messages on screen?

 

What port connects to your fibre? I am guessing it is one of the gigabit ports?

 

Try adding this on switch 2 to the port that connects between 1 and 2.

 

switchport trunk encapsulation dot1q

switchport mode trunk

 

If not run this to put it back

 

default interface gi0/1 (or gi0/2)

 

And then try this config

 

switchport trunk encapsulation isl

switchport mode trunk

 

 

Your access ports are not configured for port fast so keep in mind it will take 30 seconds for a client to establish a connection and get an IP.

Edited by FN-GM
Posted

No probs

 

Switch_2

 

Switch_2#sh vlan

 

VLAN Name Status Ports

---- -------------------------------- --------- -------------------------------

1 default active Fa0/1, Fa0/2, Fa0/3, Fa0/4

Fa0/5, Fa0/6, Fa0/7, Fa0/8

Fa0/9, Fa0/10, Fa0/11, Fa0/12

Fa0/13, Fa0/14, Fa0/15, Fa0/16

Fa0/17, Fa0/18, Fa0/19, Fa0/20

Fa0/21, Fa0/22, Fa0/23, Fa0/24

Gig0/1

1002 fddi-default active

1003 token-ring-default active

1004 fddinet-default active

1005 trnet-default active

 

VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2

---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------

1 enet 100001 1500 - - - - - 0 0

1002 fddi 101002 1500 - - - - - 0 0

1003 tr 101003 1500 - - - - - 0 0

1004 fdnet 101004 1500 - - - ieee - 0 0

1005 trnet 101005 1500 - - - ibm - 0 0

 

VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2

---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------

 

Remote SPAN VLANs

------------------------------------------------------------------------------

 

Primary Secondary Type Ports

------- --------- ----------------- ------------------------------------------

Switch_2#

 

 

 

 

 

Switch_2#sh vtp status

VTP Version capable : 1 to 3

VTP version running : 2

VTP Domain Name :

VTP Pruning Mode : Disabled

VTP Traps Generation : Disabled

Device ID : 00D0.BAB6.A400

Configuration last modified by 0.0.0.0 at 0-0-00 00:00:00

Local updater ID is 0.0.0.0 (no valid interface found)

 

Feature VLAN :

--------------

VTP Operating Mode : Server

Maximum VLANs supported locally : 1005

Number of existing VLANs : 5

Configuration Revision : 0

MD5 digest : 0x7D 0x5A 0xA6 0x0E 0x9A 0x72 0xA0 0x3A

0xF0 0x58 0x10 0x6C 0x9C 0x0F 0xA0 0xF7

Switch_2#

 

 

 

 

Switch_3#sh vlan

 

VLAN Name Status Ports

---- -------------------------------- --------- -------------------------------

1 default active Fa0/1, Fa0/2, Fa0/3, Fa0/4

Fa0/5, Fa0/6, Fa0/7, Fa0/8

Fa0/9, Fa0/10, Fa0/11, Fa0/12

Fa0/13, Fa0/14, Fa0/15, Fa0/16

Fa0/17, Fa0/18, Fa0/19, Fa0/20

Fa0/21, Fa0/22, Fa0/23, Fa0/24

Gig0/2

1002 fddi-default active

1003 token-ring-default active

1004 fddinet-default active

1005 trnet-default active

 

VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2

---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------

1 enet 100001 1500 - - - - - 0 0

1002 fddi 101002 1500 - - - - - 0 0

1003 tr 101003 1500 - - - - - 0 0

1004 fdnet 101004 1500 - - - ieee - 0 0

1005 trnet 101005 1500 - - - ibm - 0 0

 

VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2

---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------

 

Remote SPAN VLANs

------------------------------------------------------------------------------

 

Primary Secondary Type Ports

------- --------- ----------------- ------------------------------------------

Switch_3#

 

 

Switch_3#sh vtp status

VTP Version capable : 1 to 3

VTP version running : 2

VTP Domain Name :

VTP Pruning Mode : Disabled

VTP Traps Generation : Disabled

Device ID : 0050.0F48.C900

Configuration last modified by 0.0.0.0 at 0-0-00 00:00:00

Local updater ID is 0.0.0.0 (no valid interface found)

 

Feature VLAN :

--------------

VTP Operating Mode : Server

Maximum VLANs supported locally : 1005

Number of existing VLANs : 5

Configuration Revision : 0

MD5 digest : 0x7D 0x5A 0xA6 0x0E 0x9A 0x72 0xA0 0x3A

0xF0 0x58 0x10 0x6C 0x9C 0x0F 0xA0 0xF7

Switch_3#

 

 

 

I don't get any messages that cause alarm when connecting using console.

 

Yes, that's right... Switch_1 Gi0/4 >>> Switch_2 Gi0/1 then Switch_2 Gi0/2 >>> Switch_3 Gi0/1

 

Thanks very much for your help, I will have to try the interface changes in the morning when I am back at work.

Will definitely configure port fast on the access ports.

Posted (edited)

Those outputs are fine. You have to be careful with VTP. It might indicate that the switches have never been trunked into the network.

 

Is there any way of getting into another switch on your system? It might give us some clues as to what is configured on your system.

 

Try those configs when you get chance. Also remember it can take upto 50 seconds for the uplinks to come online.

Edited by FN-GM
Posted

Forgive my naivety but I'm not sure you mean about being careful with VTP and indication that the switches have not been trunked into the network? What would I look for to suggest this?

 

There are a couple of switches that have been swapped out fairly recently that work as they should but I can only console on to these at the moment.

 

I'll try the configs first thing and let you know.

 

Thanks again!

Posted (edited)

You have to be careful with VTP. If someone has been playing with the switch off your network and the "Configuration Revision" is higher than the number on your live network it will overwrite your VLAN database on all your other switches and possibly delete some of them. The VTP revision increases with every VLAN change so if someone was using the switches in a lab it is likely to be high. You can dump and reset VTP (and your VLANS) by running "delete vlan.data" and reloading the switch. It will then inherit the VTP and VLAN data base from the other switches - the way you want it to.

 

If your other switches are running VTP and they established a trunk to another switch the VTP domain name would be populated and you would see VLANS 10 & 20 on the show vlan output. That is assuming your other switches are running VTP.

 

An output of "Show Int Status" and "show interface gi0/1" would also be useful.

 

Cheers

Edited by FN-GM
Posted

Oh yes! I see what you mean now! Yes, I deleted config.text and VLAN.dat from both Switch_2 and Switch_3 before configuring this morning.

 

I have seen a VTP domain on one switch. Can't remember where I saw it now but will pull off that config in the morning.

 

Hopefully, once I configure the gig interfaces as trunk tomorrow, the VTP and VLANS will populate.

Posted

For anyone interested I removed in today and we got it sorted the issue was 2 things

 

1. We had to set the VLAN on the ports but didn't know what VLAN to use. VTP was setup but was password protected so we couldn't inherit the VLANS. We did some educated guessing of VLAN numbers and struck gold.

2. The trunk between 2 switches wasn't forming properly via DTP. We needed to manually configure it.

 

All working now! :)

Posted

Thanks very much for your help today! Really appreciate what you did and all your advice. Started to document everything that needs be done going forward.

 

I owe you one!

Posted
No problem. It's not easy only having half the information. It was good practise for my exam. Hard to make this kind in a lab as you know what's going on!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...