Jump to content

VLAN Trouble between Watchguard and Brocade

PlenumRated
Go to solution Solved by brwainer,

Change 1/1/1 vlan 110 to tagged.

Can you try to update to a newer Ruckus ICX firmware? They got rid of dual mode and generally improved the setup of VLANs.

Hello, 

 

I can't seem to get online with any of my VLAN's. I can't get a DHCP lease as well. I have attached my config for both the Watchguard and Brocade. (VLAN 1/5 are not used.)

 

Thanks,

 

Matthew

VLAN SW.png

VLAN WG.png

"Just another day at the office" Captain Price -Call of Duty

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Matthew45985 said:

Hello, 

 

I can't seem to get online with any of my VLAN's. I can't get a DHCP lease as well. I have attached my config for both the Watchguard and Brocade. (VLAN 1/5 are not used.)

 

Thanks,

 

Matthew

Sending this to a friend who has experience with Watchguard equipment. I personally don't have a lot of experience with setting up VLANs on anything outside of Unifi equipment. 

Fine you want the PSU tier list? Have the PSU tier list: https://linustechtips.com/main/topic/1116640-psu-tier-list-40-rev-103/

 

Stille (Desktop)

Ryzen 9 3900XT@4.5Ghz - Cryorig H7 Ultimate - 16GB Vengeance LPX 3000Mhz- MSI RTX 3080 Ti Ventus 3x OC - SanDisk Plus 480GB - Crucial MX500 500GB - Intel 660P 1TB SSD - (2x) WD Red 2TB - EVGA G3 650w - Corsair 760T

Evoo Gaming 15"
i7-9750H - 16GB DDR4 - GTX 1660Ti - 480GB SSD M.2 - 1TB 2.5" BX500 SSD 

VM + NAS Server (ProxMox 6.3)

1x Xeon E5-2690 v2  - 92GB ECC DDR3 - Quadro 4000 - Dell H310 HBA (Flashed with IT firmware) -500GB Crucial MX500 (Proxmox Host) Kingston 128GB SSD (FreeNAS dev/ID passthrough) - 8x4TB Toshiba N300 HDD

Toys: Ender 3 Pro, Oculus Rift CV1, Oculus Quest 2, about half a dozen raspberry Pis (2b to 4), Arduino Uno, Arduino Mega, Arduino nano (x3), Arduino nano pro, Atomic Pi. 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, mynameisjuan said:

Gonna need some more info like what ports you are testing from

Ok. My port that goes to the Watchguard is 1/1/1. From ports 1/1/1-24 are VLAN 110. 1/1/1 is configured in Dual Mod.  Ports 1/1/25-1/1/44 is VLAN 120. Then 1/1/45-1/1/48 is VLAN 100. 

"Just another day at the office" Captain Price -Call of Duty

Link to comment
Share on other sites

Link to post
Share on other sites

Change 1/1/1 vlan 110 to tagged.

Can you try to update to a newer Ruckus ICX firmware? They got rid of dual mode and generally improved the setup of VLANs.

Looking to buy GTX690, other multi-GPU cards, or single-slot graphics cards: 

 

Link to comment
Share on other sites

Link to post
Share on other sites

9 minutes ago, Matthew45985 said:

Ok. My port that goes to the Watchguard is 1/1/1. From ports 1/1/1-24 are VLAN 110. 1/1/1 is configured in Dual Mod.  Ports 1/1/25-1/1/44 is VLAN 120. Then 1/1/45-1/1/48 is VLAN 100. 

So if you attach a device off say port 1/1/45 you are unable to get a lease? Are you able to reach the gateway if you statically set it int the 10.1.48.0/24 range?

 

Side note, not familiar with Dual mode. I would assume this is like a typical trunk/native

Link to comment
Share on other sites

Link to post
Share on other sites

On the watchguard interface VLAN settings, uncheck VLAN 1. You can’t use VLAN 1 (normally untagged traffic / default vlan on most hardware) on a VLAN interface in watchguard - or at least i’ve never seen it used that way.

 

EDIT: To be clear, you can use VLAN 1 on a VLAN interface, but it normally isn’t selected as tagged, which is what you have done. You have to apply VLAN 1 to the interface as untagged, which is done from the separate selection “Send and receive untagged traffic...” at the bottom of the window.

Looking to buy GTX690, other multi-GPU cards, or single-slot graphics cards: 

 

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, brwainer said:

Change 1/1/1 vlan 110 to tagged.

Can you try to update to a newer Ruckus ICX firmware? They got rid of dual mode and generally improved the setup of VLANs.

Perfect! Thank you. I thought Dual Mode was the "core" vlan and it would assign to the ports assigned with the dual mode. Then other ports would get the other tagged VLANs. 

"Just another day at the office" Captain Price -Call of Duty

Link to comment
Share on other sites

Link to post
Share on other sites

7 minutes ago, mynameisjuan said:

So if you attach a device off say port 1/1/45 you are unable to get a lease? Are you able to reach the gateway if you statically set it int the 10.1.48.0/24 range?

 

Side note, not familiar with Dual mode. I would assume this is like a typical trunk/native

Dual mode is something AFAIK unique to Brocade. Its like tagged and untagged at the same time. The port will accept traffic already tagged as 110, and also convert incoming untagged traffic to 110. 

Looking to buy GTX690, other multi-GPU cards, or single-slot graphics cards: 

 

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, mynameisjuan said:

So if you attach a device off say port 1/1/45 you are unable to get a lease? Are you able to reach the gateway if you statically set it int the 10.1.48.0/24 range?

 

Side note, not familiar with Dual mode. I would assume this is like a typical trunk/native

Thank you for the help! I got it to work!

"Just another day at the office" Captain Price -Call of Duty

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×