10-29-2024 10:17 AM - edited 10-29-2024 10:25 AM
Hello,
when I install an ERS 4950 with spbm and connect it to a VSP, everything is OK : I can ping it, ssh access, EDM access...
but when I connect a PC on a port of this switch, it can only get ip address from DHCP server (which is configured as dhcp relay in VSP). so the pc can only ping other pc in the same vlan but it can not ping the gateway of its vlan and other IP addresses on other VLANs.
on the switch, I can ping everything, VSP, Gateways, other switches (VLANs are OK, i-sid are OK...)
!**********************conf file ******************************
ip default-gateway 192.168.254.254
ip address 192.168.254.23
! *** SSH ***
!
ssh
!
! *** SSL ***
!
ssl
no https-only
!
!
! *** LACP (Phase 1) ***
interface Ethernet ALL
lacp mode port ALL off
exit
!
!
vlan create 11,12,13 type port
vlan create 4010-4011 type spbm-bvlan
vlan ports 1/49-50 tagging tagAll filter-untagged-frame enable
vlan configcontrol automatic
vlan members remove 1 ALL
!
! *** SPBM (Phase 1) ***
router isis
spbm 1
spbm 1 b-vid 4010-4011 primary 4010
spbm 1 nick-name 9.50.23
manual-area 49.0001
interface Ethernet 1/49-50
isis
isis spbm 1
isis enable
exit
router isis
system-id 00bb.0149.0023
sys-name "SW-023"
exit
!
i-sid 14900011 vlan 11
i-sid 14900012 vlan 12
i-sid 14900113 vlan 13
!
router isis enable
!
!
!*********Spanning tree bpdu filterring****************
interface Ethernet ALL
spanning-tree mstp port 1/49-50 learning disable
spanning-tree mstp port 1/1-48 learning enable
spanning-tree mstp port 1/1-48 edge-port true
spanning-tree bpdu-filtering port 1/1-48 enable
spanning-tree bpdu-filtering timeout 0
exit
!
! *** SLPP-guard ***
!
interface Ethernet ALL
slpp-guard port 1/1-48 enable
exit
!
!
!*******storm control*************
!
interface ethernet all
storm-control all port 1/1-48 high-watermark 1500 action shutdown enable
exit
!
when I install the same switch without SPBM, everything is OK.
someone had the same problem or someone can help me ? thanks.
Regards,
10-30-2024 06:07 AM
Hello,
thanks for your answer, but the problem is more complicated than it appears.
my switch is connected to 2 VSP (1/49 --> VSP 1, 1/50 --> VSP2). I did some tests :
- double connection to 2 VSP : PC can negociate DHCP IP address but can not reach other VLAN (ICMP)
- connection only to VSP1 --> no problem
- connection only to VSP2 --> PC can negociate DHCP IP address but can not reach other VLAN (ICMP)
so I think the problem is in VSP2, I compare the 2 VSP configurations, I do not find any difference :
same VLAN, same i-sid, same spbm configuration, same isis configuration...
I can not find why, thx for your help.
Regards,
10-30-2024 06:42 AM
So where is your IP gateway? Is it VRRP on both VSPs or on VSP1 or configured on some other device? Could you share config? Or if you are using external device and you checked FDB state in C-VLAN in both scenarios (connection only to VSP1 and connection only to VSP2) and it was OK then I suggest checking connection to gateway device (especially if you are using SMLT)
10-30-2024 04:20 AM
Hi,
From ERS perspective: do you see mac address of IP gateway in C-VLAN and this PC MAC address when running command below?
show <C-VLAN> mac-address-entry