why I can ping without correct gateway between LANs on multilayer switch?

Unanswered Question
Feb 14th, 2007

Hi :)

i ll appreciate your help pls,

Please see attached figure that shows network design. main purpose of the design is; seperate broadcst messages between VLAN A and VLAN B while PCs within the VLAN A and VLAN B communicates each other.

active devices' IPs are assigned as shown in figure

question is,I've noticed PC on VLAN A can ping PC on VLAN B without correct gateway address???

VLAN A PC:

50.50.50.73/24, gateway:50.50.50.224 (gateway is supposed to be SVI A's IP address 50.50.50.110)

-----------------------------

VLAN B PC:

50.50.50.35/24, gateway:50.50.50.224 (supposed to be SVI B's IP address 50.50.50.40)

on multilayer switch:

IP routıng enabled

OSPF enabled for both SVIs and L3 port to router.

tx in advance for helping

Attachment: 
I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (1 ratings)
Loading.
Jon Marshall Wed, 02/14/2007 - 02:54

Hi

Your diagram is inconsistent with your description so it's a bit difficult to tell.

You say in your description that PC A 50.50.50.73/24 can ping PC B 50.50.50.35/24.

Could you recheck the netmasks because the above two addresses are in the same network (the /24 bit ) so they don't need to route to each other and hence won't use their default gateways.

HTH

Jon

alfonzofernando Wed, 02/14/2007 - 04:11

hi jon

tx for replying: )

I know it looks inconsistent.

IP addresses and gateways of PC A and B were not assigned for this design. (I havent changed old IPs yet). I just put them on different VLANs and see if VLAN really works.

but all active devices in figure are configured as they are shown in the figure.

Pal they are in the same IP network but they are in the different VLANs on multilayer switch. (PC A: VLAN A port of switch, PC B: VLAN B port of the switch) therefore they shouldnt ping each other should they?

I dont get it HELP! :)

tx for helping

alfonzofernando Wed, 02/14/2007 - 04:41

hi john,

tx for replying.

I have completely disabled HSRP.

No HSRP is working on any switch, no standby ip. everything is just like shown in the figure. and still PC A (in VLAN A) pings PC B (in VLAN B).

under this conditions;

while PCs are in different VLANs they shouldnt ping each other even if they are in the same subnet. or am I wrong?

tx for helping

Jon Marshall Wed, 02/14/2007 - 04:48

Hi Alfonzo

You have rated the post - does that mean that you have solved the problem ???

Jon

Jon Marshall Wed, 02/14/2007 - 04:41

Hi

What type of L3 switch are you using ?

Does the old default gateway address still exist on the switch.

What should happen in your setup is this

1) PC A wants to talk to PC B.

2) PC A compares PC B's ip address with its own netmask.

3) In this instance PC A determines that PC is on the SAME network and so arps out for PC B's address. It does not try and route to PC B.

You say your pc's are dual honed. Can you check that both connections are in the correct vlans.

The other thing that occurs is proxy arp but i need to do a bit more reading as i haven't looked at that for a long time and it might not be relevant.

HTH

Jon

John Patrick Lopez Wed, 02/14/2007 - 04:46

Sorry for that reply awhile ago. I was on the phone talking to someone else and didn't read the whole situation. Hehehe!

That's kinda weird, have you checked the subnet mask of the L3 switch? Check it. Cause ip proxy-arp might be enabled.

The L3 switch can respond to that kind of situation of ip proxy-arp is enabled.

You can check it this way, check the mac address of the pc in vlan a and the pc in vlan b. Use the arp -a (windows command) to see if the ip address of vlan b pc really corresponds to vlan b's mac address (check it by ipconfig /all)

Coz if the mac-address of the vlan b pc is the mac-address of the router then proxy arp worked.

alfonzofernando Wed, 02/14/2007 - 04:50

perhaps you mean netmask of the native vlan(vlan 1)

I ll check it

you guys r right proxy-arp is the only logical explanation I guess.

I ll give it a try

Tony.henry Wed, 02/14/2007 - 11:42

Alfonzo,

Any chance of seeing the config of each device? what springs to mind immediately is that the devices have all ended up in the same broadcast domain, throuogh some inadvertant misconfiguration.

Thanks

Tony

alfonzofernando Thu, 02/15/2007 - 05:05

hi tony

I have changed the subnet mask of native vlan on multilayer switches and problem has disappeared, I am ont sure how. perhaps proxy arp

tx for your interest

Actions

This Discussion