Hello everyone.
I hope some gurus would be able to help me out with a problem that is really kicking my ass.
Here's the setup.
I have an ESX server with a vSwitch and 3 port groups. Each port group is a VLAN.
Group 1 - 10.0.10.0/24
Group 2 - 10.0.5.0/24
Group 3 - 10.0.50.0/24
In addition, untagged group of 192.168.1.0/24 (on another NIC from ESX) which is also part of my home network.
My main router is a pfSense, My VLAN router is a Cisco 3550, used to route traffic between those group VLANs above.
Now, here's the problem.
Each group can easily ping each other.
I can ping each group's hosts from my main PC, at 192.168.1.0/24 network.
But when it comes to pinging 192.168.1.1 from any group, it goes nowhere.
Here's my configuration from 3550 (useless junk removed)
ip subnet-zero
ip routing
!
vtp mode transparent
vlan internal allocation policy ascending
vlan dot1q tag native
!
vlan 2005
!
vlan 2010
!
vlan 2050
!
vlan 2060
!
interface FastEthernet0/47
switchport trunk encapsulation dot1q
switchport mode trunk
interface Vlan1
ip address 192.168.1.236 255.255.255.0
!
interface Vlan2005
ip address 10.0.5.1 255.255.255.0
!
interface Vlan2010
ip address 10.0.10.1 255.255.255.0
!
interface Vlan2050
ip address 10.0.50.1 255.255.255.0
!
ip classless
ip route 0.0.0.0 0.0.0.0 192.168.1.1
On pfSense, I defined static routes.
And weird thing is, when I ping from Cisco's 10.0.5.1 or any other SVIs, it goes nowhere too.
Here's me trying to ping.
Switch#ping 192.168.1.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Switch#ping 10.0.5.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.0.5.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms
Switch#ping 10.0.5.5
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.0.5.5, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms
Switch#ping
Protocol [ip]:
Target IP address: 192.168.1.1
Repeat count [5]:
Datagram size [100]:
Timeout in seconds [2]:
Extended commands [n]: y
Source address or interface: 10.0.5.1
Type of service [0]:
Set DF bit in IP header? [no]:
Validate reply data? [no]:
Data pattern [0xABCD]:
Loose, Strict, Record, Timestamp, Verbose[none]:
Sweep range of sizes [n]:
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:
Packet sent with a source address of 10.0.5.1
.....
Success rate is 0 percent (0/5)
Switch#
Any clues? I am banging my head against the wall. Went as far as recreating this same exact scenario in Packet Tracer and it works 100%
I hope some gurus would be able to help me out with a problem that is really kicking my ass.
Here's the setup.
I have an ESX server with a vSwitch and 3 port groups. Each port group is a VLAN.
Group 1 - 10.0.10.0/24
Group 2 - 10.0.5.0/24
Group 3 - 10.0.50.0/24
In addition, untagged group of 192.168.1.0/24 (on another NIC from ESX) which is also part of my home network.
My main router is a pfSense, My VLAN router is a Cisco 3550, used to route traffic between those group VLANs above.
Now, here's the problem.
Each group can easily ping each other.
I can ping each group's hosts from my main PC, at 192.168.1.0/24 network.
But when it comes to pinging 192.168.1.1 from any group, it goes nowhere.
Here's my configuration from 3550 (useless junk removed)
ip subnet-zero
ip routing
!
vtp mode transparent
vlan internal allocation policy ascending
vlan dot1q tag native
!
vlan 2005
!
vlan 2010
!
vlan 2050
!
vlan 2060
!
interface FastEthernet0/47
switchport trunk encapsulation dot1q
switchport mode trunk
interface Vlan1
ip address 192.168.1.236 255.255.255.0
!
interface Vlan2005
ip address 10.0.5.1 255.255.255.0
!
interface Vlan2010
ip address 10.0.10.1 255.255.255.0
!
interface Vlan2050
ip address 10.0.50.1 255.255.255.0
!
ip classless
ip route 0.0.0.0 0.0.0.0 192.168.1.1
On pfSense, I defined static routes.
And weird thing is, when I ping from Cisco's 10.0.5.1 or any other SVIs, it goes nowhere too.
Here's me trying to ping.
Switch#ping 192.168.1.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
Switch#ping 10.0.5.1
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.0.5.1, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms
Switch#ping 10.0.5.5
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 10.0.5.5, timeout is 2 seconds:
!!!!!
Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms
Switch#ping
Protocol [ip]:
Target IP address: 192.168.1.1
Repeat count [5]:
Datagram size [100]:
Timeout in seconds [2]:
Extended commands [n]: y
Source address or interface: 10.0.5.1
Type of service [0]:
Set DF bit in IP header? [no]:
Validate reply data? [no]:
Data pattern [0xABCD]:
Loose, Strict, Record, Timestamp, Verbose[none]:
Sweep range of sizes [n]:
Type escape sequence to abort.
Sending 5, 100-byte ICMP Echos to 192.168.1.1, timeout is 2 seconds:
Packet sent with a source address of 10.0.5.1
.....
Success rate is 0 percent (0/5)
Switch#
Any clues? I am banging my head against the wall. Went as far as recreating this same exact scenario in Packet Tracer and it works 100%