Hello,
I'm trying to resolve an issue in a two-device stack of PowerConnect 6248s (firmware 3.3.3.3) that has me baffled.
Here are what I feel are the relevant configuration items:
- "ip routing" enabled in global config
- VLAN 10 configured without IP address & does not having "routing" in interface config
- Port 1/g10 is access mode for VLAN 10
- Lots of other ports are configured for VLAN 10 as general mode tagged traffic. These ports go to virtual switches (hypervisor) with lots of ports in each NIC team (Windows Server 2012 R2). The virtual switches are not configured to use tagged VLANs but one VM in environment uses VLAN 10 in tagged configuration. This is configured per-VM, not per-hypervisor
- Spanning tree is in default mode:
Spanning tree: Enabled
BPDU flooding: Disabled
Portfast BPDU filtering: Enabled
Mode: RSTP
Scenario:
When we connect the upstream device (Netvanta 4430) to a single port (1/g10), all VMs which reside in VLAN 20 lose connectivity. The VMs that lose connectivity are on the hypervisors mentioned above and only relationship is they are on ports configured with tagged VLAN 10 (and a couple others). When I shut down 1/g10, everything returns to normal...
The upstream device is a single device, single connection into our environment that is not connected anywhere else in our environment.
We had similar issues recently when connecting two devices in a redundant fashion to each physical switch in the stack and put this down to an undiagnosed STP issue but now realise that something else is going on.
My question is, what is the relationship between global config "ip routing" and routing on a VLAN interface. Is there some layer 2 issue going on that is 'below' VLANs and allowing the untagged VLAN 10 device to communicate with devices connected on tagged VLAN 10 ports?
Any thoughts or feedback would be appreciated, thanks in advance...!
Full config follows:
!Current Configuration:
!System Description "PowerConnect 6248, 3.3.3.3, VxWorks 6.5"
!System Software Version 3.3.3.3
!Cut-through mode is configured as disabled
!
configure
vlan database
vlan 10,20,30,38-39,44,255
vlan routing 20 1
vlan routing 30 2
vlan routing 38 3
vlan routing 44 4
exit
hostname "dcsw01"
clock timezone 10 minutes 0
stack
member 1 2
member 2 2
exit
ip address none
ip routing
ip route 0.0.0.0 0.0.0.0 192.168.38.1
ip route 192.168.39.0 255.255.255.0 192.168.38.1
ip route 192.168.47.0 255.255.255.0 192.168.38.1
ip route 192.168.0.0 255.255.0.0 192.168.44.1 5
ip route 10.0.0.0 255.0.0.0 192.168.44.1 5
ip route 192.168.49.0 255.255.255.0 192.168.38.1
interface vlan 10
name "SIP"
exit
interface vlan 20
name "DataCentre"
routing
ip address 192.168.20.1 255.255.255.0
exit
interface vlan 30
name "SAN"
routing
ip address 192.168.30.1 255.255.255.0
exit
interface vlan 38
name "ASA"
routing
ip address 192.168.38.10 255.255.255.0
exit
interface vlan 39
name "Perimeter"
exit
interface vlan 44
name "PIPN"
routing
ip address 192.168.44.10 255.255.255.0
exit
interface vlan 255
name "Internet"
exit
username ******** password ******** level 15 encrypted
bridge multicast filtering
ip igmp snooping
ip igmp snooping querier
!
interface ethernet 1/g1
description 'ASA Primary'
switchport access vlan 38
exit
!
interface ethernet 1/g2
description 'PIPN Primary'
switchport access vlan 44
exit
!
interface ethernet 1/g3
description 'Internet Service'
switchport access vlan 255
exit
!
interface ethernet 1/g4
description 'DCSAN01 NIC1'
switchport access vlan 30
exit
!
interface ethernet 1/g5
description 'SAN PS6120 NIC1'
switchport access vlan 20
exit
!
interface ethernet 1/g6
description 'DCNAS02 NIC1'
switchport access vlan 20
exit
!
interface ethernet 1/g7
description 'DCHyperVSupport RAC'
switchport access vlan 20
exit
!
interface ethernet 1/g8
description 'DCHyperVSupport NIC1'
switchport access vlan 20
exit
!
interface ethernet 1/g9
description 'DCHyperVSupport NIC2'
switchport access vlan 20
exit
!
interface ethernet 1/g10
shutdown
description 'Netvanta SIP Service'
switchport access vlan 10
exit
!
interface ethernet 1/g11
switchport access vlan 255
exit
!
interface ethernet 1/g12
switchport access vlan 255
exit
!
interface ethernet 1/g14
switchport access vlan 20
exit
!
interface ethernet 1/g15
description 'DCHyperV03 RAC'
switchport access vlan 20
exit
!
interface ethernet 1/g16
description 'DCHyperV03'
switchport access vlan 20
exit
!
interface ethernet 1/g17
description 'DCHyperV03'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 1/g18
description 'Cisco ASA device 1'
switchport access vlan 255
exit
!
interface ethernet 1/g19
description 'DCHyperV04 RAC'
switchport access vlan 20
exit
!
interface ethernet 1/g20
description 'DCHyperV04'
switchport access vlan 20
exit
!
interface ethernet 1/g21
description 'DCHyperV04'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 1/g22
description 'DCHyperV04'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 1/g23
description 'DCHyperV01 RAC'
switchport access vlan 20
exit
!
interface ethernet 1/g24
description 'DCHyperV01'
switchport access vlan 20
exit
!
interface ethernet 1/g25
description 'DCHyperV01'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 1/g26
description 'DCHyperV01'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 1/g27
description 'DCHyperV01'
switchport access vlan 39
exit
!
interface ethernet 1/g28
switchport access vlan 20
exit
!
interface ethernet 1/g29
description 'DCHyperV02 RAC'
switchport access vlan 20
exit
!
interface ethernet 1/g30
description 'DCHyperV02'
switchport access vlan 20
exit
!
interface ethernet 1/g31
description 'DCHyperV02'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 1/g32
description 'DCHyperV02'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 1/g33
description 'DCHyperV02'
switchport access vlan 39
exit
!
interface ethernet 1/g34
description 'DCSW03 management'
switchport access vlan 20
exit
!
interface ethernet 1/g35
switchport access vlan 20
exit
!
interface ethernet 1/g36
description 'DCNAS01 NIC1'
switchport access vlan 20
exit
!
interface ethernet 1/g37
switchport access vlan 20
exit
!
interface ethernet 1/g38
switchport access vlan 20
exit
!
interface ethernet 1/g39
description 'DCHyperV03'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 1/g40
description 'DCHyperV04'
switchport access vlan 39
exit
!
interface ethernet 1/g41
description 'DCHyperVTest-RAC'
switchport access vlan 20
exit
!
interface ethernet 1/g42
description 'DCHyperVTest'
switchport access vlan 20
exit
!
interface ethernet 1/g43
description 'DCHyperVTest'
switchport access vlan 20
exit
!
interface ethernet 1/g44
shutdown
switchport access vlan 39
exit
!
interface ethernet 1/g45
description 'DCHyperV04'
switchport access vlan 39
exit
!
interface ethernet 1/g46
description 'DCHyperV03'
switchport access vlan 39
exit
!
interface ethernet 1/g47
switchport access vlan 39
exit
!
interface ethernet 1/g48
switchport access vlan 39
exit
!
interface ethernet 1/xg1
switchport access vlan 20
exit
!
interface ethernet 1/xg2
switchport access vlan 20
exit
!
interface ethernet 1/xg3
switchport access vlan 20
exit
!
interface ethernet 1/xg4
switchport access vlan 20
exit
!
interface ethernet 2/g1
description 'ASA Secondary'
switchport access vlan 38
exit
!
interface ethernet 2/g2
description 'PIPN Secondary'
switchport access vlan 44
exit
!
interface ethernet 2/g3
description 'Internet Service 2'
switchport access vlan 255
exit
!
interface ethernet 2/g4
description 'DCSAN01 NIC2'
switchport access vlan 30
exit
!
interface ethernet 2/g5
description 'SAN PS6120 NIC2'
switchport access vlan 20
exit
!
interface ethernet 2/g6
description 'DCNAS02 NIC2'
switchport access vlan 20
exit
!
interface ethernet 2/g7
switchport access vlan 20
exit
!
interface ethernet 2/g8
description 'DCHyperVSupport NIC3'
switchport access vlan 20
exit
!
interface ethernet 2/g9
description 'DCHyperVSupport NIC4'
switchport access vlan 20
exit
!
interface ethernet 2/g10
switchport access vlan 39
exit
!
interface ethernet 2/g11
switchport access vlan 20
exit
!
interface ethernet 2/g12
switchport access vlan 20
exit
!
interface ethernet 2/g13
switchport access vlan 20
exit
!
interface ethernet 2/g14
switchport access vlan 39
exit
!
interface ethernet 2/g15
switchport access vlan 20
exit
!
interface ethernet 2/g16
description 'DCHyperV03'
switchport access vlan 20
exit
!
interface ethernet 2/g17
description 'DCHyperV03'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 2/g18
description 'Cisco ASA device 2'
switchport access vlan 255
exit
!
interface ethernet 2/g19
switchport access vlan 20
exit
!
interface ethernet 2/g20
description 'DCHyperV04'
switchport access vlan 20
exit
!
interface ethernet 2/g21
description 'DCHyperV04'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 2/g22
description 'DCHyperV04'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 2/g23
switchport access vlan 20
exit
!
interface ethernet 2/g24
description 'DCHyperV01'
switchport access vlan 20
exit
!
interface ethernet 2/g25
description 'DCHyperV01'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 2/g26
description 'DCHyperV01'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 2/g27
description 'DCHyperV01'
switchport access vlan 39
exit
!
interface ethernet 2/g28
switchport access vlan 20
exit
!
interface ethernet 2/g29
switchport access vlan 20
exit
!
interface ethernet 2/g30
description 'DCHyperV02'
switchport access vlan 20
exit
!
interface ethernet 2/g31
description 'DCHyperV02'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 2/g32
description 'DCHyperV02'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 2/g33
description 'DCHyperV02'
switchport access vlan 39
exit
!
interface ethernet 2/g34
description 'DCSW04 management'
switchport access vlan 20
exit
!
interface ethernet 2/g35
switchport access vlan 20
exit
!
interface ethernet 2/g36
description 'DCNAS01 NIC2'
switchport access vlan 20
exit
!
interface ethernet 2/g37
switchport access vlan 20
exit
!
interface ethernet 2/g38
switchport access vlan 20
exit
!
interface ethernet 2/g39
description 'DCHyperV03'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 2/g40
description 'DCHyperV04'
switchport access vlan 39
exit
!
interface ethernet 2/g41
switchport access vlan 20
exit
!
interface ethernet 2/g42
description 'DCHyperVTest'
switchport access vlan 20
exit
!
interface ethernet 2/g43
description 'DCHyperVTest'
switchport mode general
switchport general pvid 20
switchport general allowed vlan add 20
switchport general allowed vlan add 10,30,255 tagged
exit
!
interface ethernet 2/g44
switchport access vlan 39
exit
!
interface ethernet 2/g45
description 'DCHyperV04'
switchport access vlan 39
exit
!
interface ethernet 2/g46
description 'DCHyperV03'
switchport access vlan 39
exit
!
interface ethernet 2/g47
switchport access vlan 20
exit
!
interface ethernet 2/g48
switchport access vlan 39
exit
!
interface ethernet 2/xg1
switchport access vlan 20
exit
!
interface ethernet 2/xg2
switchport access vlan 20
exit
!
interface ethernet 2/xg3
switchport access vlan 20
exit
!
interface ethernet 2/xg4
switchport access vlan 20
exit
snmp-server community public ro
exit