- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- Re: HP 5304 blocks Traffic
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-29-2007 05:28 PM
тАО12-29-2007 05:28 PM
HP 5304 blocks Traffic
before I will explain my problem here are some informations about the network Infrastructure:
Management VLAN --> Firewall --> Server VLAN
Management VLAN and Server VLAN are also on the Core Switches (HP5304). We route the Management VLAN through the Firewall. So the Default Gateway from the Server in the Mgmt-VLAN will be the Firewall. The Defualt Gateway in the Server VLAN will be the Core Switch.
Now the problem:
If I wan like to access a Server in the Server VLAn from a management host in the Management VLAN with RPC (eg. WMI) then I won't get any connection.
If I will change the Default Gateway on the server in the Server VLAN to the Firewall (which has also a leg in ther Server VLAN) then it will work fine.
So I think that the core Switch will block the RPC traffic. ICMP will work fine :(
The Frewall log told me that no connection will established and onto the Core Switch I don't have any entries in the log.
So what can it be? How can I find the problem and how can I resolve it?
Thanx for helping.
Alen
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-30-2007 06:57 PM
тАО12-30-2007 06:57 PM
Re: HP 5304 blocks Traffic
If you did so then the management VLAN becomes isolated and non-routable.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-31-2007 03:51 AM
тАО12-31-2007 03:51 AM
Re: HP 5304 blocks Traffic
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-31-2007 06:28 AM
тАО12-31-2007 06:28 AM
Re: HP 5304 blocks Traffic
Attaching the config of the 5300 will be helpful to understand whats going on.
But basically, what i understand from your situation that you have 2 Routers connected together, the Firewall and the 5300.
And to do a proper work here, both routers should be aware of other's Routing Table either statically or Dynamically.
So you can add a static routes on both router to be aware of each other.
Note:
In such a situation, Trace Route is a very helpful tool that will help you understand where the packet stopped.
Good Luck !!!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО12-31-2007 06:45 AM
тАО12-31-2007 06:45 AM
Re: HP 5304 blocks Traffic
The Routing will work ICMP Packets (eg. PING) will work only RPC Connections like opening a FileShare or so won't work.
That's what I see is strange :(
I attached the config to my post (without any IP-Addresses).
Thanx for helping.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-04-2008 08:43 AM
тАО01-04-2008 08:43 AM
Re: HP 5304 blocks Traffic
Looks interesting to me.
I hope that i won't be asking too much if asked you to attach a small drawing with IP addresses if possible to your devices interconnected together :)
Also, what is the Gateway you are setting for PCs in :
- Vlan 1003
- Vlan 1004
hint, have you tried to disable XRRP temporarily to check the situation ?
Good Luck !!!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-04-2008 10:56 AM
тАО01-04-2008 10:56 AM
Re: HP 5304 blocks Traffic
I attached a Overview and the Config from all 4 Core Switches to this Post.
I hope this will give you a better view of the backbone.
The Devices has this IP-Adresses for the
VLAN 1003 - 192.168.3.1
VLAN 1004 - 192.160.0.3
I don't have XRRP for testing.
Thanx for help.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-04-2008 10:57 AM
тАО01-04-2008 10:57 AM
Re: HP 5304 blocks Traffic
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-04-2008 01:00 PM
тАО01-04-2008 01:00 PM
Re: HP 5304 blocks Traffic
The firewall is configured to allow all ICMP so pings do work.
This would explain why it worked when you changed the server to use the firewall as its default gateway.
Using a traceroute tool from both ends should help isolate the issue.
If my guess is correct, a solution would be add a static route on the server for the management VLAN pointing to the IP address of the firewall that is on the server network.
casevh
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО01-07-2008 05:52 AM
тАО01-07-2008 05:52 AM
Re: HP 5304 blocks Traffic
you're right. The main problem will be the asynchronic routing. It gives three possibilities to resolve it:
1) A static route onto all server in the Server VLAN
2) A ststic route onto the NMS Host and ACL on the switches to prevent access to the Management VLAN
3) A NAT Rule onto the Firewall to hide the NMS behind an address from the Server VLAN
We would take the possibiliy No.2 to resolve our problem, because we also want to implement ACL's onto the switches and only set one static Route instead of many on all servers.
Thanx for helping.