Wired Intelligent Edge

 View Only
last person joined: 2 days ago 

Bring performance and reliability to your network with the HPE Aruba Networking Core, Aggregation, and Access layer switches. Discuss the latest features and functionality of your switching devices, and find ways to improve security across your network to bring together a mobile-first solution
Expand all | Collapse all

Active-gateway ping or ssh don't work

This thread has been viewed 27 times
  • 1.  Active-gateway ping or ssh don't work

    Posted May 10, 2021 10:42 AM
    Hi,
    I have a strange behaviour on 8325 vsx as my active-gateway below doesn't respond to ssh/ping:
    interface vlan 34
    vsx-sync active-gateways
    ip address 192.168.34.2/23
    active-gateway ip mac 12:01:00:00:01:00
    active-gateway ip 192.168.34.150

    the configuration is the same on peer
    from a distribution switch ping/ssh is ok to ip address of both peer
    the arp resolution is ok for the ip active-gateway
    no vrf on the network ...

    What could be the problem, I'm loosing my mind .... the active-gatway funcitonnality would be used for routing for others vlan,
    I must to be sure that's all is ok before plan a migration.


    ------------------------------
    stephane henrot
    ------------------------------


  • 2.  RE: Active-gateway ping or ssh don't work

    MVP GURU
    Posted May 10, 2021 01:40 PM
    Does it respond to ping from devices on the same subnet/VLAN?

    ------------------------------
    Dustin Burns

    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 3.  RE: Active-gateway ping or ssh don't work

    Posted May 12, 2021 03:18 AM
    HI,
    I made en extended ping from a cisco device by specifying the source address in vlan 34 and it doesn't work.
    I created a second active-gteway for another vlan (with same active mac ) and after that both active-gw were reachable ...?!?
    I deleted the new active-gw and the ping to the acti-gw for vlan 34 doesn't work ....

    I don't understand why .... and this behavior for me seem to be like a bug.
    I think i have to open a tac case.
    Brgds

    ------------------------------
    stephane henrot
    ------------------------------



  • 4.  RE: Active-gateway ping or ssh don't work

    MVP GURU
    Posted May 12, 2021 07:25 AM
    I guess the next thing I would check is the L3 path to and from VLAN 34 (routing). I know it doesn't sound like it, but it sounds like something is definitely in play somewhere at L3 or L2 over a trunk. Enabling another L3 interface fixed it, and maybe its reachable through that?

    ------------------------------
    Dustin Burns

    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 5.  RE: Active-gateway ping or ssh don't work

    Posted May 12, 2021 07:35 AM
    I understand but how to explain that the ip address of the interface vlan reply to ping and not the active-gateway ip.
    the L2 is ok (arp resolution is ok for both address) and i ping "from" the vlan34 on another switch so no routing process involved.

    Let's see what the TAC reply after investigation....

    Brgds.

    ------------------------------
    stephane henrot
    ------------------------------



  • 6.  RE: Active-gateway ping or ssh don't work

    MVP GURU
    Posted May 12, 2021 08:31 AM
    Ahh OK I didn't know you were able to ping the L3 interface. Yea that's strange.

    ------------------------------
    Dustin Burns

    If my post was useful accept solution and/or give kudos
    ------------------------------



  • 7.  RE: Active-gateway ping or ssh don't work

    MVP GURU
    Posted May 19, 2021 03:50 AM
    for me, it is "normal" the SSH can't work on Active Gateway... (but ICMP should work)


    ------------------------------
    PowerArubaSW : Powershell Module to use Aruba Switch API for Vlan, VlanPorts, LACP, LLDP...

    PowerArubaCP: Powershell Module to use ClearPass API (create NAD, Guest...)

    PowerArubaCX: Powershell Module to use ArubaCX API (get interface/vlan/ports info)..

    ACEP / ACMX #107 / ACDX #1281
    ------------------------------