Contact US

Log In

Come Join Us!

Are you a
Computer / IT professional?
Join Tek-Tips Forums!
  • Talk With Other Members
  • Be Notified Of Responses
    To Your Posts
  • Keyword Search
  • One-Click Access To Your
    Favorite Forums
  • Automated Signatures
    On Your Posts
  • Best Of All, It's Free!

*Tek-Tips's functionality depends on members receiving e-mail. By joining you are opting in to receive e-mail.

Posting Guidelines

Promoting, selling, recruiting, coursework and thesis posting is forbidden.

Students Click Here

HP ProCurve 5406zl routing problem

HP ProCurve 5406zl routing problem

HP ProCurve 5406zl routing problem

I'm having some problem with routing an incoming connection - and I am no network engineer.

We got a new ISP with ethernet handoff through a WatchGuard - I do not have access to the WatchGuard. It is configured to NAT some of our public IPs to their corresponding internal server IPs, and put that traffic onto our switch on port A1.

I am unable to ping or connect to our servers using the new IP addresses assigned to us. It appears that it is routed correctly to us and our switch - but once at the switch it never reaches our servers.

Here is our setup.

We have 10 VLANs, and I believe our core switch (the 5046zl) is doing the routing between the subnets/VLANs. This core switch is connected to two other switches: a 2650, and a 2626 - I believe using some sort of Trunk. Our servers are attached to these last two switches and are in the IP subnet: "show ip route" on the 5406zl shows that destination should be routed to our DMZ VLAN.

I setup a laptop with Wireshark, and configured the switch for port monitoring, then pinged one of our new public IPs. Sorting through the Wireshark data, I did find the ICMP packets coming into the switch properly NATted to the servers IP address. These were apparently being routed to a MAC address that after some digging and using walkmib on the core switch maps to the following ifPhysAddress: 291, 292, 410-417, 429, and 430. I'm not really certain how to interpret that.

I hoping someone can help me debug what is going wrong and how to fix this.


RE: HP ProCurve 5406zl routing problem

You have verified that the IP range your new ISP assigned to you is setup correctly in the WatchGuard?? If the only thing that has changed is the new IP range, I would begin at the firewall.

RE: HP ProCurve 5406zl routing problem

As I said I can't get into the WatchGuard to verify settings - however, I do believe I have figured out the issue.

Running the port monitoring on the server port, I was able to detect the ICMP reply and response from the server. While my ping was failing this indicated that the incoming routes were indeed setup correctly, and that the server was attempting to respond.

Analyzing the Wireshark data for the ICMP response, I found that the response was using our old ISP still. After trying to fix the outgoing routes within the switch (with no success), I found that the default gateway of the servers was pointing to the old router, bypassing the outgoing routes I setup in the switch.

Once I changed the default gateway of the server to point to the core switch, my outbound routes started working - and so did my ping.

RE: HP ProCurve 5406zl routing problem

Physical interface IDs like 291, 292, 410, etc.. are the internal way the switch identifies, say, interface G3/23, etc...

I've forgotten where you can check how these are mapped but there will be various show commands that elucidate it for you: try "show interfaces" for starters.

RE: HP ProCurve 5406zl routing problem

Yes, I understood that - the low numbered ids I could easily map to the physical ports, though with numbers that high (well above the number of actual ports in the switch) I have to assume that they are somehow for the VLANs.

Fortunately for my issue it no longer matters, as we up and running on the new ISP - and everything appears to be working correctly. Now we just have to wait for DNS to fully propagate.

Red Flag This Post

Please let us know here why this post is inappropriate. Reasons such as off-topic, duplicates, flames, illegal, vulgar, or students posting their homework.

Red Flag Submitted

Thank you for helping keep Tek-Tips Forums free from inappropriate posts.
The Tek-Tips staff will check this out and take appropriate action.

Reply To This Thread

Posting in the Tek-Tips forums is a member-only feature.

Click Here to join Tek-Tips and talk with other members! Already a Member? Login

Close Box

Join Tek-Tips® Today!

Join your peers on the Internet's largest technical computer professional community.
It's easy to join and it's free.

Here's Why Members Love Tek-Tips Forums:

Register now while it's still free!

Already a member? Close this window and log in.

Join Us             Close