Unsolved

This post is more than 5 years old

53796

March 5th, 2016 07:00

Internet issue with VLAN

Hi Everyone,

We're experiencing a very strange problem with our PowerConnect 6248. We have a VLAN (8) that we use as an internet VLAN. Our internet connection is connected to VLAN 8. It consists of a bunch of ports. I have a Cisco ASA connected here too that works perfectly.

We also had a Netgear router connected here that basically just provided a guest Wi-Fi network. One of our public IP's were configured on the WAN port of the Netgear. This worked perfectly for many years. It's suddenly stopped working a month ago, I just bought a new router and configured it and connected. It doesn't work, it can't get to the internet at all.

I can however connect my laptop to the same VLAN using the same public IP on my Ethernet card and can then browse the internet without issues.

We have tried 4 Wi-Fi routers so far and all have the same issue. We're not sure where the problem is. Please see the config below.

Any help would be appreciated.

!Current Configuration:
!System Description "PowerConnect 6248, 3.3.14.2, VxWorks 6.5"
!System Software Version 3.3.14.2
!Cut-through mode is configured as disabled
!
configure
vlan database
vlan 6-10
vlan routing 1 1
vlan routing 10 2
exit
sntp unicast client enable
sntp client poll timer 256
sntp server 192.5.41.40 priority 3
sntp server 192.5.41.41 priority 3
stack
member 1 2
exit
ip address 10.107.1.1 255.255.255.0
ip default-gateway 10.107.1.10
ip address vlan 7
ip routing
ip route 0.0.0.0 0.0.0.0 10.121.105.2
ip route 10.122.58.0 255.255.255.0 10.121.105.2 2
ip route 10.186.1.0 255.255.255.0 10.121.105.2
ip route 10.122.99.0 255.255.255.0 10.121.105.3
ip route 10.123.74.0 255.255.255.0 10.121.105.2
ip route 10.122.189.0 255.255.255.0 10.121.105.2
ip route 10.123.100.0 255.255.255.0 10.121.105.2
ip helper-address 10.121.105.5 dhcp
interface vlan 1
routing
ip address 10.121.105.1 255.255.255.0
ip address 192.168.0.1 255.255.255.0 secondary
ip address 10.121.110.1 255.255.254.0 secondary
ip address 10.121.101.1 255.255.255.0 secondary
no ip proxy-arp
exit
interface vlan 6
name "iSCSI"
exit
interface vlan 7
name "Mgmt"
exit
interface vlan 8
name "Internet"
exit
interface vlan 9
name "DMZ"
exit
interface vlan 10
name "VoiceVLAN"
routing
ip address 10.121.104.1 255.255.255.0
no ip proxy-arp
exit

!
interface ethernet 1/g1
storm-control broadcast
classofservice trust ip-dscp
exit
!
interface ethernet 1/g2
storm-control broadcast
exit
!
interface ethernet 1/g3
storm-control broadcast
exit
!
interface ethernet 1/g4
storm-control broadcast
switchport mode trunk
switchport trunk allowed vlan add 1,9-10
exit
!
interface ethernet 1/g5
storm-control broadcast
exit
!
interface ethernet 1/g6
storm-control broadcast
exit
!
interface ethernet 1/g7
storm-control broadcast
exit
!
interface ethernet 1/g8
storm-control broadcast
switchport mode trunk
switchport trunk allowed vlan add 1,8
exit
!
interface ethernet 1/g9
storm-control broadcast
switchport mode trunk
switchport trunk allowed vlan add 1,10
exit
!
interface ethernet 1/g10
storm-control broadcast
exit
!
interface ethernet 1/g11
storm-control broadcast
exit
!
interface ethernet 1/g12
storm-control broadcast
exit
!
interface ethernet 1/g13
storm-control broadcast
exit
!
interface ethernet 1/g14
storm-control broadcast
exit
!
interface ethernet 1/g15
no negotiation
storm-control broadcast
exit
!
interface ethernet 1/g16
storm-control broadcast
switchport access vlan 9
exit
!
interface ethernet 1/g17
storm-control broadcast
exit
!
interface ethernet 1/g18
storm-control broadcast
exit
!
interface ethernet 1/g19
no negotiation
storm-control broadcast
switchport access vlan 8
exit
!
interface ethernet 1/g20
storm-control broadcast
switchport access vlan 8
exit
!
interface ethernet 1/g21
no negotiation
storm-control broadcast
switchport access vlan 8
exit
!
interface ethernet 1/g22
no negotiation
storm-control broadcast
switchport access vlan 8
exit
!
interface ethernet 1/g23
storm-control broadcast
switchport access vlan 8
exit
!
interface ethernet 1/g24
storm-control broadcast
switchport access vlan 8
exit
!
interface ethernet 1/g25
switchport access vlan 6
exit
!
interface ethernet 1/g26
switchport access vlan 6
exit
!
interface ethernet 1/g27
switchport access vlan 6
exit
!
interface ethernet 1/g28
switchport access vlan 6
exit
!
interface ethernet 1/g29
switchport access vlan 6
exit
!
interface ethernet 1/g30
switchport access vlan 6
exit
!
interface ethernet 1/g31
switchport access vlan 6
exit
!
interface ethernet 1/g32
switchport access vlan 6
exit
!
interface ethernet 1/g33
switchport access vlan 6
exit
!
interface ethernet 1/g34
switchport access vlan 6
exit
!
interface ethernet 1/g35
switchport access vlan 6
exit
!
interface ethernet 1/g36
switchport access vlan 6
exit
!
interface ethernet 1/g37
storm-control broadcast
exit
!
interface ethernet 1/g38
storm-control broadcast
switchport mode trunk
switchport trunk allowed vlan add 1,9-10
exit
!
interface ethernet 1/g39
storm-control broadcast
exit
!
interface ethernet 1/g40
storm-control broadcast
exit
!
interface ethernet 1/g41
storm-control broadcast
exit
!
interface ethernet 1/g42
storm-control broadcast
exit
!
interface ethernet 1/g43
storm-control broadcast
switchport mode general
switchport general allowed vlan add 10 tagged
exit
!
interface ethernet 1/g44
storm-control broadcast
exit
!
interface ethernet 1/g45
storm-control broadcast
exit
!
interface ethernet 1/g46
storm-control broadcast
switchport mode general
switchport general allowed vlan add 10 tagged
exit
!
interface ethernet 1/g47
storm-control broadcast
exit
!
interface ethernet 1/g48
storm-control broadcast
exit
exit

March 7th, 2016 07:00

Hi Daniel,

Port 19-24 is our Internet VLAN, the ISP is connected to port 19. Port 20 has our Cisco ASA 5500 connected protecting our corporate network. 10.121.105.2 is the internal address of the ASA. The outside interface of the Cisco is 74.213.163.101 and the ISP Gateway is 74.213.163.97.

We had a Netgear N900 connected to port 22 in the internet VLAN, it used 74.213.163.109. It worked perfectly and just stopped working one day. I tested it on another network and it worked, but I replaced it anyway. I have a new D-Link AC1200 to test with at the moment. I have configured 74.213.163.109 on the WAN interface. It can't get to the internet.

I have connected the D-Link directly to my ISP's media convertor (which comes into port 19) and it works perfectly. All my clients on the D-Link can browse the internet. We don't have any physical clients connected to the D-Link as the purpose is for it to provide a guest network with unrestricted internet access outside our corporate network.

Regards,

Francois

March 7th, 2016 09:00

Outside interface on the firewall (74.213.163.101) is connected to port 20, therefore providing internet to my internal network via 74.213.163.97.

10.121.105.2 is connected to port 15 (VLAN1) - internal network.

Theoretically any device connected to port 19-24 (VLAN8) using a static IP in my public range should have a direct internet connection as it's outside.

The D-Link doesn't provide internet when connected to VLAN 8, but when I connect it directly to my ISP device 74.213.163.97 is works without any issues. When I connect a computer to VLAN 8 using any of my public IP's I can connect to the internet without issues. Something is not allowing another router to connect in VLAN 8 for some reason.

Regards,

Francois

March 7th, 2016 11:00

The firewall's public interface is connected to port 20 in VLAN 8, that is confirmed. I think the idea behind VLAN 8 was to allow more devices to connect directly to our ISP, currently we only have the firewall and the Wi-Fi Router.

Clients connecting to the D-Link get dynamic addresses assigned by the D-Link in 192.168.158.0. The Netgear was configured as a router, I don't have the configuration of it anymore as we reset it many times. I don't think we had any static routes configured on it as it shouldn't need any.

I have just noticed another problem, the moment I connect the D-Link to the 6248 port 22 or 24 in VLAN 8 our internet starts to go wonky. You can see in the screenshot below, it started doing this the moment after connecting the D-Link.

March 7th, 2016 12:00

Storm-control was disabled on port 24 where the D-Link is connected, it didn't make any difference.

Please also see the screenshot of the interface counters for port 24 below. I'm not sure which route to add on the D-Link...

No Events found!

Top