phreak Posted June 12, 2012 Posted June 12, 2012 (edited) Hi there, Got a bit of an odd one. I have a network with several Vlans setup within it. Now the problem is that 2 of my switchs (HP procurve 2524) keep dropping pings and will not allow me to connect to the web interface of said switchs. These particular switchs in question are not doing any of the Vlans. I have a HP 2510 doing that in the main cabinet. All these switchs are doing is providing connection between patch panels and the main switch. So as such they themselves have a IP address on my seperate management Vlan. Now, if I plug myself in the switch directly I can connect to it fine, I can ping and whatnot, Even if I put myself on the Management Vlan then again, can connect with no issues. But if I switch to the main pc Vlan then it times out. Now from said Vlan I can get to another switch in the same ip range and Vlan as one of those switchs in question. I have tried copying the config into a fresh like for like replacement but still the same problem. The drops seem to be random as well. You might get a whole page of ping replies but then it just starts dropping off, could be one or 2, could be a whole page of drops. I have checked the firewall routing to make sure there is nothing blocking it there, but having looked at the logs after the fact I can see it passing the traffic through successfully even when I get time outs, so to my mind it is not the firewall. I have checked the running configuration of said 2 switchs against the other switchs that are working properly and they seem almost identical apart from the IP obviously. Any suggestions? Oh and another oddity is that I can ping the servers that connect through the switch without any ping drops. Edited June 12, 2012 by phreak
themightymrp Posted June 12, 2012 Posted June 12, 2012 I had something similar a while back and I'm trying to remember what I did. Can you check whether the default gateway and route settings are set up correctly for the switch. I think mine had something to do with that
sonofsanta Posted June 12, 2012 Posted June 12, 2012 Try clearing the ARP cache on the remote switch, it's occasionally cropped up here where certain computers can't ping certain switches, even though they seem to be working. I'd tlel you the command if I used ProCurve switches myself, but we're Comware here... should be easy enough to find out, anyway!
phreak Posted June 12, 2012 Author Posted June 12, 2012 (edited) Thanks guys. I have checked the default gateway is correct and the route tables look exactly like the other working switchs. On the ARP note, I have cleared the ARP table but still the same problem. Edited June 12, 2012 by phreak
themightymrp Posted June 13, 2012 Posted June 13, 2012 Any chance you could post a dump of one of those 2 switches configs?
phreak Posted June 13, 2012 Author Posted June 13, 2012 Here is the config dump Startup configuration: ; J4813A Configuration Editor; Created on release #F.05.72 hostname "HP 2524 [172.16.4.88]" snmp-server contact "[email protected]" snmp-server location "[server room]" time daylight-time-rule Western-Europe cdp run mirror-port 24 ip default-gateway 172.16.4.3 sntp server 172.16.8.1 timesync sntp sntp unicast snmp-server community "public" Unrestricted vlan 1 name "DEFAULT_VLAN" untagged 1-6,8-26 no ip address no untagged 7 exit vlan 40 name "TAG-40" untagged 7 ip address 172.16.4.88 255.255.255.128 exit no aaa port-access authenticator active password manager password operator
phreak Posted June 13, 2012 Author Posted June 13, 2012 (edited) That TAG-40 is the link to the Management VLAN switch. .4.3 is the gateway that all the switch's use. And all the latest firmwares have been applied. Let me know if you need anything else or can suggest anything. Thanks Edited June 13, 2012 by phreak
themightymrp Posted June 13, 2012 Posted June 13, 2012 Am I correct in that when you are connected to any port other than 7 you cannot ping the switch?
themightymrp Posted June 13, 2012 Posted June 13, 2012 Looking at the config, you have the IP address for the switch set on the TAG-40 VLAN but under the DEFAULT_VLAN you have no ip address. Could you assign the switch another IP from the range and have it on that VLAN?
phreak Posted June 13, 2012 Author Posted June 13, 2012 Yes, I suppose I could do that. Except all the working switch's configured the same, ie: no set ip under default Vlan. But I will try it anyway and let you know.
themightymrp Posted June 13, 2012 Posted June 13, 2012 Yeah I know it's not ideal, you should only need the one IP address. I'm just looking through the config on some of our HP's to see how they are set.....
themightymrp Posted June 13, 2012 Posted June 13, 2012 I might be on to something - could I ask you to dump a config of a working switch so I can compare? My setup is slightly different in that I use the 'DEFAULT_VLAN' as the management VLAN and then the rest of the sockets are set as untagged on that areas VLAN i.e. VLAN5
phreak Posted June 13, 2012 Author Posted June 13, 2012 I have tried assigning it an IP on that range on the Default Vlan through the menu interface. However, every time I try that I get an Inconsistent Value. It will only allow me to assign it an IP on a different range by the looks of it. And when I set it on the range that the servers themselves use on said Vlan I can ping it when plugged directly into the switch, however, cannot ping that new IP from anywhere else.
phreak Posted June 13, 2012 Author Posted June 13, 2012 Sure. Here is a dump of a working one. Startup configuration: ; J4813A Configuration Editor; Created on release #F.05.17 hostname "HP 2524 [172.16.4.83]" snmp-server contact "[email protected]" snmp-server location "[server room]" time daylight-time-rule Western-Europe cdp run ip default-gateway 172.16.4.3 sntp server 172.16.8.1 timesync sntp sntp unicast snmp-server community "public" Unrestricted snmp-server host 10.10.1.1 "public" Not-INFO vlan 1 name "DEFAULT_VLAN" untagged 1-6,8-26 no ip address no untagged 7 exit vlan 40 name "TAG-40" untagged 7 ip address 172.16.4.83 255.255.255.128 exit no aaa port-access authenticator active password manager password operator
themightymrp Posted June 13, 2012 Posted June 13, 2012 OK scrap the idea of adding a second IP address, but if you can show the config from a working switch?
themightymrp Posted June 13, 2012 Posted June 13, 2012 The only noticable difference I can see is that on the one which doesn't work you have this line: mirror-port 24 Not entirely sure what that does as have never had to use it. Could you take that out and see if it works?
ricki Posted June 13, 2012 Posted June 13, 2012 Hi I know this will be a stab in the dark but are the switches overheating. If they are out of warrenty open them up and check the fans if they are in warranty use compressed air and blow them out. Does the cabinet have a door on it. It might be worth trying the door open. Other things you can do is. Take the settings down then reset the switch and install the latest firmware and then set it up again. We had some strange problems with the 2952 sfp plus and eventually gave up on it and replaced it with a cisco. Richard
phreak Posted June 13, 2012 Author Posted June 13, 2012 (edited) That mirror port is for monitoring from what I have read. I am not sure it is overheating. Reason being I have replaced like for like with another perfectly working switch. Copied over the config and went from there. I suppose I could try reset the switch again and configuring from scratch. But would like to avoid that if possible, plus would be nice to get to the bottom of the problem. Don't know it if helps but here is the config of the other switch which is giving me the same problem. And it is not set to mirror port. Startup configuration: ; J4812A Configuration Editor; Created on release #F.05.72 hostname "HP 2524 [172.16.4.89]" snmp-server contact "[email protected] / +44 208 344 0300" snmp-server location "[server room]" time daylight-time-rule Western-Europe cdp run ip default-gateway 172.16.4.3 sntp server 172.16.8.1 timesync sntp sntp unicast snmp-server community "eastmon" Manager Unrestricted vlan 1 name "DEFAULT_VLAN" untagged 1-6,8-14 no ip address no untagged 7 exit vlan 40 name "TAG-40" untagged 7 ip address 172.16.4.89 255.255.255.128 exit no aaa port-access authenticator active password manager password operator Edited June 13, 2012 by phreak
themightymrp Posted June 13, 2012 Posted June 13, 2012 Interesting to note: Working switch = J4813A Configuration Editor; Created on release #F.05.17 Not working switches = J4812A Configuration Editor; Created on release #F.05.72
phreak Posted June 13, 2012 Author Posted June 13, 2012 That is just because when I started the non working one was on F.05.17 and so did the firmware update hoping that would resolve it... obviously it did not. However when on the older version it still had the same problem.
themightymrp Posted June 13, 2012 Posted June 13, 2012 Tell me if this sounds daft (I'm really at a loss as to why this isn't working on those 2 switches) but how about setting the DEFAULT_VLAN as Tagged on port 7?
phreak Posted June 13, 2012 Author Posted June 13, 2012 Well, at this point I am open to any ideas. Tried it, no difference I'm afraid. But I see where you were coming from. And yes, I too am at a loss. Really quite a headscratcher this one.
robk Posted June 13, 2012 Posted June 13, 2012 Just as a question, which vlan is the switch management interface on? by default its on DEFAULT_VLAN and theres no ip address for that Vlan. The command is "primary-vlan " Worth a try?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now