VMware Cloud Community
Sysxp
Enthusiast
Enthusiast
Jump to solution

Can't ping VLAN 1 from VLAN 10, please help

Hello!

I have an ESXi host with dvSwitch and two dvPortGroups:

1. Prod (VLAN type set to "none"). 192.168.255.0/24

2. VLAN10 (VLAN type set to VLAN 10). 192.168.100.0/24

vmk0 Management of the ESXi is connected to VLAN10. (IP 192.168.100.3)

vCenter is connected to Prod (no VLAN). (IP 192.168.255.199)

Everything is connected to L3 Cisco stacked switch with VLAN1 (int 192.168.255.250) and VLAN10 (int 192.168.100.254).

I can perfecly ping the ESXi from vcenter (no VLAN 192.168.255.199 ->> VLAN10 192.168.100.3) or any PC - it works just fine. But when I'm trying to ping the vCenter from an ESXi (VLAN10 192.168.100.3 ->> no vlan 192.168.255.199) - it is not working. In fact I can't ping anything, but my VLAN10 cisco GW, so I can ping 192.168.100.254 and nothing else. Can you please advice why this is happening and how to fix it? I really need to be able to ping everyting from VLAN10->> no vlan.

BIG thanks in advance!

0 Kudos
2 Solutions

Accepted Solutions
Kinnison
Commander
Commander
Jump to solution

Comment removed...

View solution in original post

Sysxp
Enthusiast
Enthusiast
Jump to solution

I found why it was not working as it should on a Cisco forum - someone had the exact same problem. And the issue is: the default GW for the PCs or VMs in Vlan1 must be the ip of the cisco router that does all Vlan routing (in my case 192.168.255.250). After setting the correct GW everything begin to work as intended.

Thank you Kinnison! Your initial assumption about incorrect network settings was somewhat right. 🙂

View solution in original post

0 Kudos
8 Replies
Kinnison
Commander
Commander
Jump to solution

Comment removed...

Sysxp
Enthusiast
Enthusiast
Jump to solution

Even impolite guessing is totally OK, I'm stuck and really need to fix this. 🙂

Network settings are probably fine, because they are as simple as possible. No ACL involved, also no firewall.

I can ping GW and VMs in VLAN 20 no problem (gw for VLAN20 192.168.120.254) and vice versa.

I can also ping 2 mikrotik routers in VLAN1 but nothing else, PCs and VMs are not responding.

Maybe there is a way to remove the vlan tag from the packets if the destination is in Vlan 1? Not sure how to do it.

 

0 Kudos
Kinnison
Commander
Commander
Jump to solution

Comment removed...

0 Kudos
Sysxp
Enthusiast
Enthusiast
Jump to solution

VLAN 20 is for vMotion traffic, does not leave the blade cage. 

Here are all the vlans in cisco:

VLANall.PNG

Both the vCenter VM and ESXi ping traffic does not leave the blade cage, everything is up to cisco this ESXi is plugged into. My guess is that it is somehow connected with "Native VLAN". Ping between Vlan10 <<->> Vlan20 work fine. But ping between Vlan1 and Vlan10 only works from Vlan1=>>vLan10. No complicated settings involved, and it 'should' work, but it does not.

0 Kudos
Sysxp
Enthusiast
Enthusiast
Jump to solution

I found why it was not working as it should on a Cisco forum - someone had the exact same problem. And the issue is: the default GW for the PCs or VMs in Vlan1 must be the ip of the cisco router that does all Vlan routing (in my case 192.168.255.250). After setting the correct GW everything begin to work as intended.

Thank you Kinnison! Your initial assumption about incorrect network settings was somewhat right. 🙂

0 Kudos
Kinnison
Commander
Commander
Jump to solution

Comment removed...

Sysxp
Enthusiast
Enthusiast
Jump to solution

"Should work" I meant if we have 3 Vlans with ip interfaces on them and L3 cisco with ip routing 'on' they should 'see' each other no problem. I had Vlan20 trunked outside of the cage solely for testing purposes - to find WHY the blasted Vlan1 is not working properly.

I have multi-nic vMotion with 4 vmk in VLan20, once I remove this vlan from trunk ports this traffic will not leave the bladecage.

Thank you for your help!

0 Kudos
Kinnison
Commander
Commander
Jump to solution

Hi,


Of course routing in the context of your CISCO stack works fine since you have it enabled, but you didn't tell me that your devices on VLAN 1 used a different router as their gateway, set up I don't know how. However what matters is that you have solved the problem, everything else matters little. 😀


Good things,
Ferdinando

0 Kudos