Comware

 View Only
last person joined: 4 hours ago 

Expand all | Collapse all

2530, HPE5500 and HPE5700

This thread has been viewed 17 times
  • 1.  2530, HPE5500 and HPE5700

    Posted May 09, 2023 10:37 PM

    Hi All,

    I am at my wits end. I cannot figure out an issue why IP's within an expanded subnet are not accessible. I have a subnet we have been running on for years, 192.168.50.0/24 I expanded it by changing my subnet mask to /23 so now we have a range from 192.168.50.1-192.168.51.254. I changed the Subnet Mask on the gateway device (Cisco ASA) and all switches to /23 (one 2530, three 5500 and four 5700). I can ping only one single address in the entire expanded range of 192.168.51.1-192.168.51.254 and nothing can get to the internet. 

    Any ideas would be greatly appreciated.  



  • 2.  RE: 2530, HPE5500 and HPE5700

    EMPLOYEE
    Posted May 10, 2023 05:40 AM

    Hi,

    You may have two separate issues:

    1. If there is a NAT on Cisco ASA, then you need to modify the NAT ACL to reflect the new, expanded subnet. That could explain the 'nothing can get to the Internet' issue.
    2. The host from which you are pinging new IPs is still on /24 prefix and ARP resolution is broken because of that.

    Please, paste here the output of 'display ip routing-table' command ran on your Comware devices (5500 and 5700) to double-check the settings are indeed applied.



    ------------------------------
    Ivan Bondar
    ------------------------------



  • 3.  RE: 2530, HPE5500 and HPE5700

    Posted May 11, 2023 01:29 PM

    Correct on both points. My assumption was user had already changed mask and ASA had a pat statement that was used for internet that used a different object then the Lan Object. Thanks Ivan!!!