Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements
Step-by-Step Configuration and Troubleshooting Best Practices for the NGFW, NGIPS and AMP Technologies A Visual Guide to the Cisco Firepower Threat Defense (FTD)
New Member

ASA5505 vlan1 down, active workstations on vlan1

Hello,

I have an ASA5505 where vlan1 (inside) and all associated ports (e0/1 - e0/7) are down.  Workstations on vlan 1 are online and working.  Vlan2 (outside) is up and running normally.  I tried to shut/no shut on the vlan.  I also rebooted the firewall.  No change. 

Can someone tell me why vlan1 is down??  I've attached some config info and some troubleshooting.

Everyone's tags (2)
5 REPLIES
New Member

ASA5505 vlan1 down, active workstations on vlan1

Hello,

What does a 'show int e0/x' (where x is 1-7) show? Are the physical interfaces under VLAN 1 showing up/up?

Thanks

Joey

New Member

ASA5505 vlan1 down, active workstations on vlan1

Interfaces are down but workstations are actively communicating on them.  I connected to a workstation via remote desktop to confirm the workstation and port were active. 

ASA5505D# show int

Interface Vlan1 "inside", is down, line protocol is down

  Hardware is EtherSVI, BW 100 Mbps, DLY 100 usec

        MAC address 0024.c49d.38ea, MTU 1500

        IP address 172.29.x.x, subnet mask 255.255.255.248

  Traffic Statistics for "inside":

        0 packets input, 0 bytes

        0 packets output, 0 bytes

        0 packets dropped

      1 minute input rate 0 pkts/sec,  0 bytes/sec

      1 minute output rate 0 pkts/sec,  0 bytes/sec

      1 minute drop rate, 0 pkts/sec

      5 minute input rate 0 pkts/sec,  0 bytes/sec

      5 minute output rate 0 pkts/sec,  0 bytes/sec

      5 minute drop rate, 0 pkts/sec

Interface Vlan2 "outside", is up, line protocol is up

  Hardware is EtherSVI, BW 100 Mbps, DLY 100 usec

        IP address y.y.y.y, subnet mask 255.255.255.252

  Traffic Statistics for "outside":

        4703 packets input, 568862 bytes

        6535 packets output, 2928588 bytes

        130 packets dropped

      1 minute input rate 4 pkts/sec,  557 bytes/sec

      1 minute output rate 7 pkts/sec,  1626 bytes/sec

      1 minute drop rate, 0 pkts/sec

      5 minute input rate 1 pkts/sec,  173 bytes/sec

      5 minute output rate 2 pkts/sec,  775 bytes/sec

      5 minute drop rate, 0 pkts/sec

Interface Ethernet0/0 "", is up, line protocol is up

  Hardware is 88E6095, BW 100 Mbps, DLY 100 usec

        Auto-Duplex(Full-duplex), Auto-Speed(100 Mbps)

        Input flow control is unsupported, output flow control is unsupported

        Available but not configured via nameif

        MAC address 0024.c49d.38e2, MTU not set

        IP address unassigned

        4722 packets input, 655788 bytes, 0 no buffer

        Received 0 broadcasts, 0 runts, 0 giants

        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort

        0 L2 decode drops

        0 switch ingress policy drops

        6561 packets output, 3055824 bytes, 0 underruns

        0 pause output, 0 resume output

        0 output errors, 0 collisions, 0 interface resets

        0 late collisions, 0 deferred

        0 input reset drops, 0 output reset drops

        0 rate limit drops

        0 switch egress policy drops

Interface Ethernet0/1 "", is down, line protocol is down

  Hardware is 88E6095, BW 100 Mbps, DLY 100 usec

        Auto-Duplex, Auto-Speed

        Input flow control is unsupported, output flow control is unsupported

        Available but not configured via nameif

        MAC address 0024.c49d.38e3, MTU not set

        IP address unassigned

        0 packets input, 0 bytes, 0 no buffer

        Received 0 broadcasts, 0 runts, 0 giants

        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort

        0 L2 decode drops

        0 switch ingress policy drops

        0 packets output, 0 bytes, 0 underruns

        0 pause output, 0 resume output

        0 output errors, 0 collisions, 0 interface resets

        0 late collisions, 0 deferred

        0 input reset drops, 0 output reset drops

        0 rate limit drops

        0 switch egress policy drops

Interface Ethernet0/2 "", is down, line protocol is down

  Hardware is 88E6095, BW 100 Mbps, DLY 100 usec

        Auto-Duplex, Auto-Speed

        Input flow control is unsupported, output flow control is unsupported

        Available but not configured via nameif

        MAC address 0024.c49d.38e4, MTU not set

        IP address unassigned

        0 packets input, 0 bytes, 0 no buffer

        Received 0 broadcasts, 0 runts, 0 giants

        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort

        0 L2 decode drops

        0 switch ingress policy drops

        0 packets output, 0 bytes, 0 underruns

        0 pause output, 0 resume output

        0 output errors, 0 collisions, 0 interface resets

        0 late collisions, 0 deferred

        0 input reset drops, 0 output reset drops

        0 rate limit drops

        0 switch egress policy drops

Interface Ethernet0/3 "", is down, line protocol is down

  Hardware is 88E6095, BW 100 Mbps, DLY 100 usec

        Auto-Duplex, Auto-Speed

        Input flow control is unsupported, output flow control is unsupported

        Available but not configured via nameif

        MAC address 0024.c49d.38e5, MTU not set

        IP address unassigned

        0 packets input, 0 bytes, 0 no buffer

        Received 0 broadcasts, 0 runts, 0 giants

        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort

        0 L2 decode drops

        0 switch ingress policy drops

        0 packets output, 0 bytes, 0 underruns

        0 pause output, 0 resume output

        0 output errors, 0 collisions, 0 interface resets

        0 late collisions, 0 deferred

        0 input reset drops, 0 output reset drops

        0 rate limit drops

        0 switch egress policy drops

Interface Ethernet0/4 "", is down, line protocol is down

  Hardware is 88E6095, BW 100 Mbps, DLY 100 usec

        Auto-Duplex, Auto-Speed

        Input flow control is unsupported, output flow control is unsupported

        Available but not configured via nameif

        MAC address 0024.c49d.38e6, MTU not set

        IP address unassigned

        0 packets input, 0 bytes, 0 no buffer

        Received 0 broadcasts, 0 runts, 0 giants

        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort

        0 L2 decode drops

        0 switch ingress policy drops

        0 packets output, 0 bytes, 0 underruns

        0 pause output, 0 resume output

        0 output errors, 0 collisions, 0 interface resets

        0 late collisions, 0 deferred

        0 input reset drops, 0 output reset drops

        0 rate limit drops

        0 switch egress policy drops

Interface Ethernet0/5 "", is down, line protocol is down

  Hardware is 88E6095, BW 100 Mbps, DLY 100 usec

        Auto-Duplex, Auto-Speed

        Input flow control is unsupported, output flow control is unsupported

        Available but not configured via nameif

        MAC address 0024.c49d.38e7, MTU not set

        IP address unassigned

        0 packets input, 0 bytes, 0 no buffer

        Received 0 broadcasts, 0 runts, 0 giants

        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort

        0 L2 decode drops

        0 switch ingress policy drops

        0 packets output, 0 bytes, 0 underruns

        0 pause output, 0 resume output

        0 output errors, 0 collisions, 0 interface resets

        0 late collisions, 0 deferred

        0 input reset drops, 0 output reset drops

        0 rate limit drops

        0 switch egress policy drops

Interface Ethernet0/6 "", is down, line protocol is down

  Hardware is 88E6095, BW 100 Mbps, DLY 100 usec

        Auto-Duplex, Auto-Speed

        Input flow control is unsupported, output flow control is unsupported

        Available but not configured via nameif

        MAC address 0024.c49d.38e8, MTU not set

        IP address unassigned

        0 packets input, 0 bytes, 0 no buffer

        Received 0 broadcasts, 0 runts, 0 giants

        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort

        0 L2 decode drops

        0 switch ingress policy drops

        0 packets output, 0 bytes, 0 underruns

        0 pause output, 0 resume output

        0 output errors, 0 collisions, 0 interface resets

        0 late collisions, 0 deferred

        0 input reset drops, 0 output reset drops

        0 rate limit drops

        0 switch egress policy drops

Interface Ethernet0/7 "", is down, line protocol is down

  Hardware is 88E6095, BW 100 Mbps, DLY 100 usec

        Auto-Duplex, Auto-Speed

        Input flow control is unsupported, output flow control is unsupported

        Available but not configured via nameif

        MAC address 0024.c49d.38e9, MTU not set

        IP address unassigned

        0 packets input, 0 bytes, 0 no buffer

        Received 0 broadcasts, 0 runts, 0 giants

        0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort

        0 L2 decode drops

        0 switch ingress policy drops

        0 packets output, 0 bytes, 0 underruns

        0 pause output, 0 resume output

        0 output errors, 0 collisions, 0 interface resets

        0 late collisions, 0 deferred

        0 input reset drops, 0 output reset drops

        0 rate limit drops

        0 switch egress policy drops

ASA5505D#

ASA5505D# show arp

        outside y.y.y.y 78cd.8e75.feaa 4404

ASA5505D#

New Member

ASA5505 vlan1 down, active workstations on vlan1

Hello,

How exactly are you connecting via remote desktop? Through the ASA from outside to inside? Or through the inside VLAN 1 switchports (e0/1 - 7) on the ASA? Or are you connecting through a different device?

Can you give a screenshot of one of these working PCs pinging VLAN 1 (172.29.x.x)?

I just find it very odd that these devices are communicated over interfaces which are showing down/down. I could not find any bugs which describe this issue.

Thanks!

ASA5505 vlan1 down, active workstations on vlan1

You have assigned the outside vlan2 to interface interface ethernet 0/0 with the command:

switchport access vlan 2

and you plugged a cable into that interface for your internet access.

Now you need to figure out which interface you want vlan1 configured for on the ASA and set the following command:

switchport access vlan1

and then cable that interface to your inside network on that same vlan.

Thanks and let me know if this works.

Kimberly

Thanks and Cheers! Kimberly Please remember to rate helpful posts.
New Member

ASA5505 vlan1 down, active workstations on vlan1

Found the problem.  I worked with TAC a couple weeks ago to fix 8.2.4 to 8.4 upgrade problems on the HQ ASA.  The 5505 discussed above is one of a few that VPN into the HQ ASA.  While working with TAC i noticed a NAT statement that didn't seem right but at the time (3AM after hours of troubleshooting) i didn't press the issue.  Here is the statement:

(Inside, Outside)

Original Packet Source = HQ LAN network

Destination = Remote office A network

Translate Destination = Remote office B network

(Outside, Inside)

Original Packet Source = Remote office B network

Destination = HQ LAN network

Translate Source = Remote office A network

When connecting the 5505 (described above) via ASDM from the HQ LAN, I was not connecting to the 5505 i expected... thus the confusion.  I removed the NAT statement and the devices act as they should. 

Thanks for the responses. 

1844
Views
0
Helpful
5
Replies
CreatePlease to create content