cancel
Showing results for 
Search instead for 
Did you mean: 

segmented management on 5520 running VOSS

segmented management on 5520 running VOSS

Chi
New Contributor II

Hi, has anybody gotten a 5520 running VOSS and acting as a router with two routed interfaces (VLANs with IPs) to have the segmented management VLAN be accessible from both sides of the router?  I created VLANs A and B on the 5520, assigned (public, routable) IPs to them, and then created a segmented management VLAN, and gave it an IP on the same subnet as VLAN A, with VLAN A’s IP address as it’s default route.

I can SSH to the segmented management VLAN address, but ONLY when I’m physically connected to anything on VLAN A side of the router, including devices going through another router that connects the VLAN A.  Anything on VLAN B or connected to the VLAN B side, cannot SSH to the segmented management VLAN address.

1 ACCEPTED SOLUTION

LionelH
New Contributor II

Hello,

 

I found my mistake, Router ISIS SPBM Ip wasn’t activate with IP shortcut as source.

 

Now Clip are working fine around the network.

 

Regards,

View solution in original post

10 REPLIES 10

Chi
New Contributor II

Both sides of the router have publicly routable IP addresses, so I would need to get another IP from the ISP and have them route to it.  But the end customer doesn’t really want to do that.

LionelH
New Contributor II

Hello,

 

I found my mistake, Router ISIS SPBM Ip wasn’t activate with IP shortcut as source.

 

Now Clip are working fine around the network.

 

Regards,

LionelH
New Contributor II

Hello,

I’m in the exact same situation.

We have 2 VOSS VSP4900 acting as network core and L3 for all our VLAN.

We cannot access the VSP in the Vlan as before.

I understand we must now use CLIP mgmt, but is somebody know how to configure CLIP MGMT Interface ?

It as to be /32, and how the CLIP Mgmt IP can be reach from other Vlan ?

Thanks for explanation,

Regards,

Ludovico_Steven
Extreme Employee

The point raised is that a mgmt VLAN IP cannot be reached if the same VSP is required to IP route the packet to the mgmt VLAN. This is documented as a limitation. The point is that if the VSP is acting as an IP router, then you should not be using a mgmt vlan IP but a mgmt clip instead.

See the attached slides, slide 19.

GTM-P2G8KFN