cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1294
Views
0
Helpful
11
Replies

HSRP and L3 issues on Cisco 7609

medi.mazinani
Level 1
Level 1

Hi. Firstly thanks for your time. Secondly, I have 2 major issues in regard of HSRP at L3 level as following:

Suppose that we have an SVI VLAN 120 with 2 different subnets (prim. & sec ip). We run HSRP on mentioned int Vlan by 2 different groups. So, the problem is each of our router is just able to ping it's phys. ip addr. along with the vir. ip addr. of HSRP, but it can not ping the phys. ip addr. of it's corresponding redundant router. Moreover, when I tried to ping the loopback address of adjacent router, it's not possible. I've checked all issues in regard of L2/L3 but found nothing! (We have IOS 12.2 (33) SRB2 & RSP720 on our routers). So, have anyone had the same issues as for now?! Can we say that it has a relation to IOS or Hardware matters?! Please kindly advise. Thanks & Regards,

11 Replies 11

Amit Singh
Cisco Employee
Cisco Employee

Could you please paste the config from the primary and standby routers.

Hi Asingh, I will paste the MSTP/HSRP/SVI and Ping test results of mentioned issues. Is it sufficient? Thanks for the support.

Router1 (RTHG1):

MSTP:

{spanning-tree mode mst

spanning-tree extend system-id

!

spanning-tree mst configuration

name RTHG

revision 1

instance 1 vlan 10-29, 50-69, 100-119, 140-179, 220-239

instance 2 vlan 30-49, 70-99, 120-139, 180-219, 240-361

!

spanning-tree mst 1 priority 0

spanning-tree mst 2 priority 4096

}

...

interface Loopback0

ip address 10.12.200.1 255.255.255.255

...

interface Port-channel1

description GE47&GE48 RTHG1 to GE47&GE48 RTHG2

switchport

switchport trunk encapsulation dot1q

switchport mode trunk

!

...

interface GigabitEthernet1/47

description trunk (EtherChannel) to RTHG2 GE47

switchport

switchport mode trunk

speed 1000

duplex full

spanning-tree link-type point-to-point

channel-protocol lacp

channel-group 1 mode active

!

interface GigabitEthernet1/48

description trunk (EtherChannel) to RTHG2 GE48

switchport

switchport mode trunk

speed 1000

duplex full

no cdp enable

spanning-tree link-type point-to-point

channel-protocol lacp

channel-group 1 mode active

...

interface Vlan120

description MAGD_OMU

ip address 10.12.101.2 255.255.255.224 secondary

ip address 10.12.100.2 255.255.255.224

no ip redirects

standby 3 ip 10.12.101.1

standby 3 timers 1 3

standby 3 priority 80

standby 3 preempt delay minimum 180

standby 120 ip 10.12.100.1

standby 120 timers 1 3

standby 120 priority 80

standby 120 preempt delay minimum 180

-------------------------------

All mentioned interfaces ar UP.

MSTP is OK; HSRP: sh stand br,

{

RTHG1#sho span mst conf

Name [RTHG]

Revision 1 Instances configured 3

Instance Vlans mapped

-------- ---------------------------------------------------------------------

0 1-9,362-4094

1 10-29,50-69,100-119,140-179,220-239

2 30-49,70-99,120-139,180-219,240-361

-------------------------------------------------------------------------------

RTHG1#sho stand br

P indicates configured to preempt.

|

Interface Grp Pri P State Active Standby Virtual IP

Vl120 3 80 P Standby 10.12.100.3 local 10.12.101.1

Vl120 120 80 P Standby 10.12.100.3 local 10.12.100.1

}

Will send Router2's configs in another message. Tnx,

Router2 (RTHG2):

MSTP:

{

spanning-tree mode mst

spanning-tree extend system-id

!

spanning-tree mst configuration

name RTHG

revision 1

instance 1 vlan 10-29, 50-69, 100-119, 140-179, 220-239

instance 2 vlan 30-49, 70-99, 120-139, 180-219, 240-361

!

spanning-tree mst 1 priority 4096

spanning-tree mst 2 priority 0

}

...

interface Loopback0

ip address 10.12.200.2 255.255.255.255

...

interface Port-channel1

description GE47&GE48 RTHG2 to GE47&GE48 RTHG1

switchport

switchport trunk encapsulation dot1q

switchport mode trunk

...

interface GigabitEthernet1/47

description trunk (EtherChannel) to RTHG1 GE47

switchport

switchport mode trunk

speed 1000

duplex full

spanning-tree link-type point-to-point

channel-protocol lacp

channel-group 1 mode passive

!

interface GigabitEthernet1/48

description trunk (EtherChannel) to RTHG1 GE48

switchport

switchport mode trunk

speed 1000

duplex full

spanning-tree link-type point-to-point

channel-protocol lacp

channel-group 1 mode passive

...

interface Vlan120

description MAGD_OMU

ip address 10.12.101.3 255.255.255.224 secondary

ip address 10.12.100.3 255.255.255.224

no ip redirects

standby 3 ip 10.12.101.1

standby 3 timers 1 3

standby 3 priority 110

standby 3 preempt delay minimum 180

standby 120 ip 10.12.100.1

standby 120 timers 1 3

standby 120 priority 110

standby 120 preempt delay minimum 180

...

-------------------------------

All mentioned interfaces ar UP.

MSTP is OK; HSRP: sh stand br,

{

RTHG2#sho stand br

P indicates configured to preempt.

|

Interface Grp Pri P State Active Standby Virtual IP

Vl120 3 110 P Active local 10.12.100.2 10.12.101.1

Vl120 120 110 P Active local 10.12.100.2 10.12.100.1

}

Also pls. take into ur consideration that the Active Virt. router for both subnet is the same (???). Moreover, I don' know y I have no information for my port channel member links (1/47,48) in MSTP results? (Continued ...)

MSTP: sho span mst

{

RTHG2#sho span mst

##### MST0 vlans mapped: 1-9,362-4094

Bridge address --.6240 priority 32768 (32768 sysid 0)

Root address --.5780 priority 32768 (32768 sysid 0)

port Po1 path cost 0

Regional Root address --.5780 priority 32768 (32768 sysid 0)

internal cost 10000 rem hops 19

Operational hello time 2 , forward delay 15, max age 20, txholdcount 6

Configured hello time 2 , forward delay 15, max age 20, max hops 20

Interface Role Sts Cost Prio.Nbr Type

---------------- ---- --- --------- -------- --------------------------------

Gi1/1 Desg FWD 200000 128.1 P2p

Gi1/2 Desg FWD 200000 128.2 P2p

...

Gi1/27 Desg FWD 20000 128.27 Edge P2p

Gi1/43 Desg FWD 200000 128.43 Edge P2p

Po1 Root FWD 10000 128.3329 P2p

##### MST1 vlans mapped: 10-29,50-69,100-119,140-179,220-239

Bridge address --.6240 priority 4097 (4096 sysid 1)

Root address --.5780 priority 1 (0 sysid 1)

port Po1 cost 10000 rem hops 19

Interface Role Sts Cost Prio.Nbr Type

---------------- ---- --- --------- -------- --------------------------------

Gi1/1 Desg FWD 200000 128.1 P2p

Gi1/2 Desg FWD 200000 128.2 P2p

Gi1/3 Desg FWD 200000 128.3 P2p

Gi1/4 Desg FWD 200000 128.4 P2p

Gi1/5 Desg FWD 200000 128.5 P2p

Gi1/6 Desg FWD 200000 128.6 P2p

Gi1/7 Desg FWD 200000 128.7 P2p

Gi1/8 Desg FWD 200000 128.8 P2p

Gi1/9 Desg FWD 200000 128.9 P2p

Gi1/10 Desg FWD 200000 128.10 P2p

Gi1/19 Desg FWD 200000 128.19 P2p

Gi1/20 Desg FWD 200000 128.20 P2p

Gi1/21 Desg FWD 200000 128.21 P2p

Gi1/22 Desg FWD 200000 128.22 P2p

Gi1/23 Desg FWD 200000 128.23 P2p

Gi1/24 Desg FWD 200000 128.24 P2p

Po1 Root FWD 10000 128.3329 P2p

##### MST2 vlans mapped: 30-49,70-99,120-139,180-219,240-361

Bridge address --.6240 priority 2 (0 sysid 2)

Root this switch for MST2

Interface Role Sts Cost Prio.Nbr Type

---------------- ---- --- --------- -------- --------------------------------

Gi1/1 Desg FWD 200000 128.1 P2p

Gi1/2 Desg FWD 200000 128.2 P2p

Gi1/3 Desg FWD 200000 128.3 P2p

Gi1/4 Desg FWD 200000 128.4 P2p

Gi1/5 Desg FWD 200000 128.5 P2p

Gi1/6 Desg FWD 200000 128.6 P2p

Gi1/7 Desg FWD 200000 128.7 P2p

Gi1/8 Desg FWD 200000 128.8 P2p

Gi1/9 Desg FWD 200000 128.9 P2p

Gi1/10 Desg FWD 200000 128.10 P2p

Gi1/19 Desg FWD 200000 128.19 P2p

Gi1/20 Desg FWD 200000 128.20 P2p

Gi1/21 Desg FWD 200000 128.21 P2p

Gi1/22 Desg FWD 200000 128.22 P2p

Gi1/23 Desg FWD 200000 128.23 P2p

Gi1/24 Desg FWD 200000 128.24 P2p

Gi1/27 Desg FWD 20000 128.27 Edge P2p

Gi1/43 Desg FWD 200000 128.43 Edge P2p

Po1 Desg FWD 10000 128.3329 P2p

}

HSRP ambiguities are here:

{

RTHG1#ping 10.12.100.1

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.100.1, timeout is 2 seconds:

..

Success rate is 0 percent (0/2)

RTHG1#ping 10.12.100.2

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.100.2, timeout is 2 seconds:

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms

RTHG1#ping 10.12.100.3

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.100.3, timeout is 2 seconds:

..

Success rate is 0 percent (0/2)

RTHG1#ping 10.12.101.1

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.101.1, timeout is 2 seconds:

..

Success rate is 0 percent (0/2)

RTHG1#ping 10.12.101.2

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.101.2, timeout is 2 seconds:

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms

RTHG1#ping 10.12.101.3

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.101.3, timeout is 2 seconds:

..

Success rate is 0 percent (0/2)

}

RTHG1#sho stand vlan 120

{

Vlan120 - Group 3

State is Standby

4 state changes, last state change 00:01:46

Virtual IP address is 10.12.101.1

Active virtual MAC address is --.ac03

Local virtual MAC address is --.ac03 (v1 default)

Hello time 1 sec, hold time 3 sec

Next hello sent in 0.480 secs

Preemption enabled, delay min 180 secs

Active router is 10.12.100.3, priority 110 (expires in 2.448 sec)

Standby router is local

Priority 80 (configured 80)

Group name is "hsrp-Vl120-3" (default)

Vlan120 - Group 120

State is Standby

4 state changes, last state change 00:01:46

Virtual IP address is 10.12.100.1

Active virtual MAC address is --.ac78

Local virtual MAC address is --.ac78 (v1 default)

Hello time 1 sec, hold time 3 sec

Next hello sent in 0.480 secs

Preemption enabled, delay min 180 secs

Active router is 10.12.100.3, priority 110 (expires in 2.448 sec)

Standby router is local

Priority 80 (configured 80)

Group name is "hsrp-Vl120-120" (default)

RTHG1#ping 10.12.100.1

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.100.1, timeout is 2 seconds:

.....

Success rate is 0 percent (0/5)

RTHG1#ping 10.12.101.1

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.101.1, timeout is 2 seconds:

.....

Success rate is 0 percent (0/5)

}

RTHG2#sho stand vlan 120

Vlan120 - Group 3

State is Active

2 state changes, last state change 00:04:36

Virtual IP address is 10.12.101.1

Active virtual MAC address is --.ac03

Local virtual MAC address is --.ac03 (v1 default)

Hello time 1 sec, hold time 3 sec

Next hello sent in 0.384 secs

Preemption enabled, delay min 180 secs

Active router is local

Standby router is 10.12.100.2, priority 80 (expires in 2.464 sec)

Priority 110 (configured 110)

Group name is "hsrp-Vl120-3" (default)

Vlan120 - Group 120

State is Active

2 state changes, last state change 00:04:36

Virtual IP address is 10.12.100.1

Active virtual MAC address is --.ac78

Local virtual MAC address is --.ac78 (v1 default)

Hello time 1 sec, hold time 3 sec

Next hello sent in 0.384 secs

Preemption enabled, delay min 180 secs

Active router is local

Standby router is 10.12.100.2, priority 80 (expires in 2.464 sec)

Priority 110 (configured 110)

Group name is "hsrp-Vl120-120" (default)

RTHG2#ping 10.12.100.1

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.100.1, timeout is 2 seconds:

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms

RTHG2#ping 10.12.101.1

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.101.1, timeout is 2 seconds:

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/4 ms

RTHG2#ping 10.12.100.2

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.100.2, timeout is 2 seconds:

.....

Success rate is 0 percent (0/5)

RTHG2#ping 10.12.101.2

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.101.2, timeout is 2 seconds:

.....

Success rate is 0 percent (0/5)

}

LP not pinged!:

{RTHG1# ping 10.12.200.2

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.200.2, timeout is 2 seconds:

.....

Success rate is 0 percent (0/5)

RTHG1#

}

{RTHG2#ping 10.12.200.1

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.200.1, timeout is 2 seconds:

.....

Success rate is 0 percent (0/5)

}

LP investigation:

{

RTHG1#ping 10.12.200.2

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.200.2, timeout is 2 seconds:

..

Success rate is 0 percent (0/2)

RTHG1#ping 10.12.200.2 sour loo 0

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.200.2, timeout is 2 seconds:

Packet sent with a source address of 10.12.200.1

.....

Success rate is 0 percent (0/5)

RTHG1#sho ip rou | inc 10.12.200

C 10.12.200.1/32 is directly connected, Loopback0

O 10.12.200.2/32 [110/2] via 10.12.120.19, 00:09:17, Vlan241

}

{

RTHG2#ping 10.12.200.1 sour loo 0

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.200.1, timeout is 2 seconds:

Packet sent with a source address of 10.12.200.2

..

Success rate is 0 percent (0/2)

RTHG2#sho ip route | inc 10.12.200

O 10.12.200.1/32 [110/2] via 10.12.120.18, 00:10:36, Vlan241

C 10.12.200.2/32 is directly connected, Loopback0

RTHG2#tra 10.12.200.1

Type escape sequence to abort.

Tracing the route to 10.12.200.1

1 10.12.108.2 0 msec

10.12.108.34 0 msec

10.12.120.18 0 msec

RTHG2#ping 10.12.200.1 sour vlan 241

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.200.1, timeout is 2 seconds:

Packet sent with a source address of 10.12.120.19

.....

Success rate is 0 percent (0/5)

RTHG2#ping 10.12.200.1 sour vlan 360

Type escape sequence to abort.

Sending 5, 100-byte ICMP Echos to 10.12.200.1, timeout is 2 seconds:

Packet sent with a source address of 10.12.108.35

!!!!!

Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms

RTHG2#

}

That's all. Please keep me posted if you have any upd. in this regard. Really appreciate it. BR,

Hi buddy. Did u have any time for taking a look on enclosed logs? Did u find anything? I will proceed with changing IOS to 12.2 (18) SXF9, maybe it's working.

Regards,

Hey. No one has no idea in this regard? If someone can give a pro support, it would be highly appreciated. Believe me or not, no one can not help me as for now in this regard! BR,

Hello Medi,

first of all I would suggest you next time to attach the config and shows in an attachement file instead of using multiple posts.

It makes easier to understand the thread is still at the beginning...

I noticed one configuration issue:

when you want to configure an HSRP group that has to be associated to a secondary ip address you need to add the secondary keyword:

interface Vlan120

description MAGD_OMU

ip address 10.12.101.2 255.255.255.224 secondary

ip address 10.12.100.2 255.255.255.224

no ip redirects

standby 3 ip 10.12.101.1

last line needs to be:

standby 3 ip 10.12.101.1 secondary

B)

any command should be on the port-channel interface not on the member links

I would put

spanning-tree link-type point-to-point

under port-channel

but I think that this command is not needed.

c)

fix the missing secondary option and retry.

Hope to help

Giuseppe

Hi Giuseppe,

Firstly thanks for your advise in regard of attaching configs. Will proceed so afterwards.

Secondly, indeed I had tried ur suggested solution in regard of HSRP sec, but it did not work at all!

Regards,

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: