GeekyGav Posted April 26, 2018 Posted April 26, 2018 Hi all, Got a bit of a weird one here... Just had two switches fail on me. Cisco 3560s. (Switches 2 and 3) Switch layout as follows... Core <<< >>> Switch_1 <<< >>> Switch_2 <<< >>> Switch_3 Only been doing the job for a week with no handover documentation from the previous. No passwords for switches and have tried to do password recovery without any luck. Anyway... managed to find two new 3560s. Plugged them in with fibre links, configured both switches a very basic config using the startup wizard. Hostname. Set the enable and VT passwords. Vlan1 as management No further VLANS added. No configuration changes made to ports. Now, here is where the problem starts on both switches 2 and 3. I initially set up Vlan1 to pick up an IP from the DHCP Server (Windows 2012) - Just to ensure connectivity! No good. Set Vlan1 with a static IP, subnet, etc. Can't ping my way through the network or any of the other switches. CDP Neighbors shows the correct devices at either end of the fibre links. No IP addresses leased to client devices. However... If I remove the switch from the cab and plug it into a directly into a known working switch via Ethernet, it'll pick up an IP address and issue addresses to clients. What am I missing here? I can't get into the other switches to see their configs but I know 'Old Switch 2' had its fibre connections set as trunk ports and there were two additional VLANS (10 and 20) but these were not assigned to any other ports. I have configured the fibre interfaces as trunks and checked that these are associated with Vlan1, still no luck. Why would DHCP pass through the Ethernet ports but not the fibre connections? Any help would be greatly appreciated. Gav
FN-GM Posted April 26, 2018 Posted April 26, 2018 (edited) Can you post configs of Switch 2 and 3 please. It would be good to understand what you have done already. Why would DHCP pass through the Ethernet ports but not the fibre connections? They are probably not configured properly. Could be a native VLAN or encapsulation miss match. When you plugged the switch into the copper port and got IP addresses do you know if it forms an access port or trunk port? Thanks Edited April 26, 2018 by FN-GM
GeekyGav Posted April 26, 2018 Author Posted April 26, 2018 Yes, no problem... Switch_2 As follows... SW_02#sh run Building configuration... Current configuration : 1366 bytes ! version 12.2 no service pad service timestamps debug uptime service timestamps log uptime no service password-encryption ! hostname SW_02 ! enable secret 5 $1$dNw1$7RyMWhj9MXT2MVI6NiYfO1 enable password ****** ! no aaa new-model ip subnet-zero ! ! ! ! ! ! no file verify auto spanning-tree mode pvst spanning-tree extend system-id ! vlan internal allocation policy ascending ! interface FastEthernet0/1 ! interface FastEthernet0/2 ! interface FastEthernet0/3 ! interface FastEthernet0/4 ! interface FastEthernet0/5 ! interface FastEthernet0/6 ! interface FastEthernet0/7 ! interface FastEthernet0/8 ! interface FastEthernet0/9 ! interface FastEthernet0/10 ! interface FastEthernet0/11 ! interface FastEthernet0/12 ! interface FastEthernet0/13 ! interface FastEthernet0/14 ! interface FastEthernet0/15 ! interface FastEthernet0/16 ! interface FastEthernet0/17 ! interface FastEthernet0/18 ! interface FastEthernet0/19 ! interface FastEthernet0/20 ! interface FastEthernet0/21 ! interface FastEthernet0/22 ! interface FastEthernet0/23 ! interface FastEthernet0/24 ! interface GigabitEthernet0/1 ! interface GigabitEthernet0/2 ! interface Vlan1 ip address dhcp ! ip classless ip http server ip http secure-server ! ! control-plane ! ! line con 0 line vty 0 4 password ****** no login line vty 5 15 password ****** no login ! end SW_02# Switch_3 as follows... SW_03#sh run Building configuration... Current configuration : 1366 bytes ! version 12.2 no service pad service timestamps debug uptime service timestamps log uptime no service password-encryption ! hostname SW_03 ! enable secret 5 $1$dNw1$7RyMWhj9MXT2MVI6NiYfO1 enable password ***** ! no aaa new-model ip subnet-zero ! ! ! ! ! ! no file verify auto spanning-tree mode pvst spanning-tree extend system-id ! vlan internal allocation policy ascending ! interface FastEthernet0/1 ! interface FastEthernet0/2 ! interface FastEthernet0/3 ! interface FastEthernet0/4 ! interface FastEthernet0/5 ! interface FastEthernet0/6 ! interface FastEthernet0/7 ! interface FastEthernet0/8 ! interface FastEthernet0/9 ! interface FastEthernet0/10 ! interface FastEthernet0/11 ! interface FastEthernet0/12 ! interface FastEthernet0/13 ! interface FastEthernet0/14 ! interface FastEthernet0/15 ! interface FastEthernet0/16 ! interface FastEthernet0/17 ! interface FastEthernet0/18 ! interface FastEthernet0/19 ! interface FastEthernet0/20 ! interface FastEthernet0/21 ! interface FastEthernet0/22 ! interface FastEthernet0/23 ! interface FastEthernet0/24 ! interface GigabitEthernet0/1 ! interface GigabitEthernet0/2 ! interface Vlan1 ip address dhcp ! ip classless ip http server ip http secure-server ! ! control-plane ! ! line con 0 line vty 0 4 password ***** no login line vty 5 15 password ***** no login ! end SW_03#
FN-GM Posted April 26, 2018 Posted April 26, 2018 (edited) EDIT: Hang on before you do this. Can you do "Show VLAN" and "Show VTP status" please? When you connect via a console cable do you see any messages on screen? What port connects to your fibre? I am guessing it is one of the gigabit ports? Try adding this on switch 2 to the port that connects between 1 and 2. switchport trunk encapsulation dot1q switchport mode trunk If not run this to put it back default interface gi0/1 (or gi0/2) And then try this config switchport trunk encapsulation isl switchport mode trunk Your access ports are not configured for port fast so keep in mind it will take 30 seconds for a client to establish a connection and get an IP. Edited April 26, 2018 by FN-GM
GeekyGav Posted April 26, 2018 Author Posted April 26, 2018 No probs Switch_2 Switch_2#sh vlan VLAN Name Status Ports ---- -------------------------------- --------- ------------------------------- 1 default active Fa0/1, Fa0/2, Fa0/3, Fa0/4 Fa0/5, Fa0/6, Fa0/7, Fa0/8 Fa0/9, Fa0/10, Fa0/11, Fa0/12 Fa0/13, Fa0/14, Fa0/15, Fa0/16 Fa0/17, Fa0/18, Fa0/19, Fa0/20 Fa0/21, Fa0/22, Fa0/23, Fa0/24 Gig0/1 1002 fddi-default active 1003 token-ring-default active 1004 fddinet-default active 1005 trnet-default active VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2 ---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------ 1 enet 100001 1500 - - - - - 0 0 1002 fddi 101002 1500 - - - - - 0 0 1003 tr 101003 1500 - - - - - 0 0 1004 fdnet 101004 1500 - - - ieee - 0 0 1005 trnet 101005 1500 - - - ibm - 0 0 VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2 ---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------ Remote SPAN VLANs ------------------------------------------------------------------------------ Primary Secondary Type Ports ------- --------- ----------------- ------------------------------------------ Switch_2# Switch_2#sh vtp status VTP Version capable : 1 to 3 VTP version running : 2 VTP Domain Name : VTP Pruning Mode : Disabled VTP Traps Generation : Disabled Device ID : 00D0.BAB6.A400 Configuration last modified by 0.0.0.0 at 0-0-00 00:00:00 Local updater ID is 0.0.0.0 (no valid interface found) Feature VLAN : -------------- VTP Operating Mode : Server Maximum VLANs supported locally : 1005 Number of existing VLANs : 5 Configuration Revision : 0 MD5 digest : 0x7D 0x5A 0xA6 0x0E 0x9A 0x72 0xA0 0x3A 0xF0 0x58 0x10 0x6C 0x9C 0x0F 0xA0 0xF7 Switch_2# Switch_3#sh vlan VLAN Name Status Ports ---- -------------------------------- --------- ------------------------------- 1 default active Fa0/1, Fa0/2, Fa0/3, Fa0/4 Fa0/5, Fa0/6, Fa0/7, Fa0/8 Fa0/9, Fa0/10, Fa0/11, Fa0/12 Fa0/13, Fa0/14, Fa0/15, Fa0/16 Fa0/17, Fa0/18, Fa0/19, Fa0/20 Fa0/21, Fa0/22, Fa0/23, Fa0/24 Gig0/2 1002 fddi-default active 1003 token-ring-default active 1004 fddinet-default active 1005 trnet-default active VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2 ---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------ 1 enet 100001 1500 - - - - - 0 0 1002 fddi 101002 1500 - - - - - 0 0 1003 tr 101003 1500 - - - - - 0 0 1004 fdnet 101004 1500 - - - ieee - 0 0 1005 trnet 101005 1500 - - - ibm - 0 0 VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1 Trans2 ---- ----- ---------- ----- ------ ------ -------- ---- -------- ------ ------ Remote SPAN VLANs ------------------------------------------------------------------------------ Primary Secondary Type Ports ------- --------- ----------------- ------------------------------------------ Switch_3# Switch_3#sh vtp status VTP Version capable : 1 to 3 VTP version running : 2 VTP Domain Name : VTP Pruning Mode : Disabled VTP Traps Generation : Disabled Device ID : 0050.0F48.C900 Configuration last modified by 0.0.0.0 at 0-0-00 00:00:00 Local updater ID is 0.0.0.0 (no valid interface found) Feature VLAN : -------------- VTP Operating Mode : Server Maximum VLANs supported locally : 1005 Number of existing VLANs : 5 Configuration Revision : 0 MD5 digest : 0x7D 0x5A 0xA6 0x0E 0x9A 0x72 0xA0 0x3A 0xF0 0x58 0x10 0x6C 0x9C 0x0F 0xA0 0xF7 Switch_3# I don't get any messages that cause alarm when connecting using console. Yes, that's right... Switch_1 Gi0/4 >>> Switch_2 Gi0/1 then Switch_2 Gi0/2 >>> Switch_3 Gi0/1 Thanks very much for your help, I will have to try the interface changes in the morning when I am back at work. Will definitely configure port fast on the access ports.
FN-GM Posted April 26, 2018 Posted April 26, 2018 (edited) Those outputs are fine. You have to be careful with VTP. It might indicate that the switches have never been trunked into the network. Is there any way of getting into another switch on your system? It might give us some clues as to what is configured on your system. Try those configs when you get chance. Also remember it can take upto 50 seconds for the uplinks to come online. Edited April 26, 2018 by FN-GM
GeekyGav Posted April 26, 2018 Author Posted April 26, 2018 Forgive my naivety but I'm not sure you mean about being careful with VTP and indication that the switches have not been trunked into the network? What would I look for to suggest this? There are a couple of switches that have been swapped out fairly recently that work as they should but I can only console on to these at the moment. I'll try the configs first thing and let you know. Thanks again!
FN-GM Posted April 26, 2018 Posted April 26, 2018 (edited) You have to be careful with VTP. If someone has been playing with the switch off your network and the "Configuration Revision" is higher than the number on your live network it will overwrite your VLAN database on all your other switches and possibly delete some of them. The VTP revision increases with every VLAN change so if someone was using the switches in a lab it is likely to be high. You can dump and reset VTP (and your VLANS) by running "delete vlan.data" and reloading the switch. It will then inherit the VTP and VLAN data base from the other switches - the way you want it to. If your other switches are running VTP and they established a trunk to another switch the VTP domain name would be populated and you would see VLANS 10 & 20 on the show vlan output. That is assuming your other switches are running VTP. An output of "Show Int Status" and "show interface gi0/1" would also be useful. Cheers Edited April 26, 2018 by FN-GM
GeekyGav Posted April 26, 2018 Author Posted April 26, 2018 Oh yes! I see what you mean now! Yes, I deleted config.text and VLAN.dat from both Switch_2 and Switch_3 before configuring this morning. I have seen a VTP domain on one switch. Can't remember where I saw it now but will pull off that config in the morning. Hopefully, once I configure the gig interfaces as trunk tomorrow, the VTP and VLANS will populate.
FN-GM Posted April 27, 2018 Posted April 27, 2018 For anyone interested I removed in today and we got it sorted the issue was 2 things 1. We had to set the VLAN on the ports but didn't know what VLAN to use. VTP was setup but was password protected so we couldn't inherit the VLANS. We did some educated guessing of VLAN numbers and struck gold. 2. The trunk between 2 switches wasn't forming properly via DTP. We needed to manually configure it. All working now!
GeekyGav Posted April 27, 2018 Author Posted April 27, 2018 Thanks very much for your help today! Really appreciate what you did and all your advice. Started to document everything that needs be done going forward. I owe you one!
FN-GM Posted April 27, 2018 Posted April 27, 2018 No problem. It's not easy only having half the information. It was good practise for my exam. Hard to make this kind in a lab as you know what's going on!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now