vrf mgmtVrf help

itdaddyitdaddy Senior MemberMember Posts: 2,089 ■■■■□□□□□□
hey guys,
my first time configuring a vrf mgmtVrf interface for out of band management. I do not understand. Before I port-channeled the uplinks ssh to the vrf mgmtVrf worked but once I port-channeled the new switch, access is gone? why is that ?? This switch is not connected to anything. I have a new Core + distro setup I am building and I put all 6 new switches with cat 6 on back of their ether management ports hoping to connect to them out of band and work on them but when I configured the port-channel on the 1st switch iti cut me off of the vrf mgmtVrf access? what happened?

Comments

  • d4nz1gd4nz1g Member Posts: 464
    Could you explain your issue in a clearer way? Which boxes are you using? 6500?
  • MitechniqMitechniq Member Posts: 286 ■■■■□□□□□□
    I am interested in further details as well....

    Are you using the console port for OOB management? Normally I have a Terminal Access router to do OOB management, which needs no VRF configuration.
  • itdaddyitdaddy Senior Member Member Posts: 2,089 ■■■■□□□□□□
    I have 6 switches stacked in 2s. so you have 1 core switch (2 switches) 4500x port channels 4 portchannel/uplinks to each distro stack of 3850s
    imagine 4500x 2 switches stacked as core and on both sides you have 1 3850 stack of 2 distro switches and on the other 2 stack 3850 distro switches. each switch has a out of band management interface say fast1 that is a vrf MGMTVrf interface with and IP and each of their mgmt interface cat 6 cables is plugged into a access switch with proper access vlan. So i have have a distri + core + distri setup with 4 uplinks portchanneled to the core from the distri switches total 40 GB port channels. Once I port channel the switches any of them. I lose the vrf mgmtVrf access? I dont get it? This system is not even touching production. It is a new core distri setup. How can I lose the vrf mgmtVrf access when I configure port channels. .The funny thing is I can ping the interfaces from the access switch but cannot ssh anymore? confused?
  • itdaddyitdaddy Senior Member Member Posts: 2,089 ■■■■□□□□□□
    I wish i had a terminal access router to access console. I am trying the out of band manage vrf port. It did work but when i port channelled the switch it cut off access?
  • itdaddyitdaddy Senior Member Member Posts: 2,089 ■■■■□□□□□□
    yah think it is because i added a switchport trunk native vlan 987 command on the port channels?? which caused this ??/
  • itdaddyitdaddy Senior Member Member Posts: 2,089 ■■■■□□□□□□
    I have 6 switches stacked in 2s. so you have 1 core switch (2 switches) 4500x port channels 4 portchannel/uplinks to each distro stack of 3850s
    imagine 4500x 2 switches stacked as core and on both sides you have 1 3850 stack of 2 distro switches and on the other 2 stack 3850 distro switches. each switch has a out of band management interface say fast1 that is a vrf MGMTVrf interface with and IP and each of their mgmt interface cat 6 cables is plugged into a access switch with proper access vlan. So i have have a distri + core + distri setup with 4 uplinks portchanneled to the core from the distri switches total 40 GB port channels. Once I port channel the switches any of them. I lose the vrf mgmtVrf access? I dont get it? This system is not even touching production. It is a new core distri setup. How can I lose the vrf mgmtVrf access when I configure port channels. .The funny thing is I can ping the interfaces from the access switch but cannot ssh anymore? confused? icon_redface.gif
  • d4nz1gd4nz1g Member Posts: 464
    Where are the mgmt interfaces connected? To the switch itself (like back 2 back)?

    If so, there might be an issue with the mgmt vlan up to the distro/core.

    Could you test from the same mgmt vlan, to exclude possible l3 issues?
  • itdaddyitdaddy Senior Member Member Posts: 2,089 ■■■■□□□□□□
    d4nz1g
    user-offline.png
    dude what a dummy I am ...i forgot the vrf mgmtVrf interface is in a seperate virtual routing table and i had to do this statement and it worked fine.

    ip route vrf mgmtVrf 0.0.0.0 0.0.0.0 next-hope-gw

    works perfect now...
Sign In or Register to comment.