Monday, October 8, 2018

Cisco SVI and management

I posted in Home networking but did't really get anywhere. So i'm trying here.

I was playing around with VLANs on a 2960. I have a ROAS configuration with several VLANs. All devices within these VLANs have been communicating with no problem for a while. I was moving some things to a management VLAN and this switch was the last thing I needed to move. The switch was at 192.168.1.0/24 untagged subnet on native VLAN 1. I wanted to move it to VLAN 10 on the 192.168.10.0/24 subnet.

I remoted in via SSH to the 192.168.1.0/24 address. After I added the IP to VLAN 10, I was able to SSH to it at this new address. I got the login prompt but it wouldn't accept my credentials (Access Denied), although they worked when remoted in to the other address.

I was trying to do some Googling about the issue but most was related to L3 switches. But I did see that SVI can only be active on one VLAN at a time. So I ran no shut on VLAN 10, and shut on VLAN 1. As I sort of expected, I lost connection form the 192.168.1.0/24 address but am still unable to authenticate on the new address.

I know VLAN 10 is up/up and there are active devices I can remote into that are in that VLAN so I know it not a routing problem. The only user account on that switch is privilege level 15. Is there a step I missed when moving the SVI from an untagged VLAN to another tagged VLAN?

Thanks



No comments:

Post a Comment