cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1324
Views
0
Helpful
2
Replies

Cisco sg500x/ASA5512 can’t ping gateway on voice vlan

Rhys Davies
Level 1
Level 1

Hi

We have a stack of sg500x switches and are using the auto voice vlan for voip. Phones pick up their ip from the correct scope and auto smartport recognises the phones when plugged into the switch and assigns them to the correct vlan. Have configured a port to be the trunk link to the ASA firewall by assigning the port as tagged for the voice VLAN and placed it in trunk mode. The connecting interface on the firewall is configured with an IP on the voice subnet and for testing I have allowed icmp from anywhere to anywhere. I can ping the next hope on the WAN but I can’t ping back into the voice LAN on the switches neither can I ping from the data VLAN to the ASA on the voice vlan. But I can ping any phones on the voice VLAN from the data VLAN - basically the ASA is unreachable on its voice gateway port connected to the voice VLAN. I’m thinking auto voice vlan is not allowing traffic to the ASA but I don’t know how or why.

Thanks for any help

2 Replies 2

Rhys Davies
Level 1
Level 1

Additionally I have plugged a pc into the voice vlan port given it voice subnet IP and I can't ping that either. I believe I'm not understanding something fundamental about how voice vlan works. How do I connect a router/firewall to the voice vlan to provide a gateway out?

Thanks

Needed a sub interface on the ASA assigned to voice vlan and details on physical interface left blank as in this thread -

https://supportforums.cisco.com/thread/2206103

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: