Got it

[All About Switches] A Gateway Fails to Ping a PC Connected to the VRRP Backup Device

Latest reply: Mar 9, 2018 05:51:55 1462 1 0 0 0

Involved Products and Versions

All products and versions


As shown in Figure 1-1, a VRRP group is configured on SwitchA and SwitchB. SwitchA is the VRRP master device and SwitchB is the VRRP backup device. The network segment where the PC resides is, and the network segment where the gateway SwitchC resides is

To enable communication between the network segments and, a user configures ACL-based packet filtering on SwitchB to allow only the traffic from to to pass. In addition, this rule is applied to the outbound direction of VLAN 322.

Figure 1-1 Networking diagram for the failure of a gateway to ping a PC connected to the VRRP backup device



Fault Symptom

SwitchC fails to ping the PC.

Cause Analysis

1.       Check the configuration on SwitchC.

The ACL named Vlan322Out and numbered 3022 allows all traffic from network segment to network segment to pass. Therefore, the PC can ping SwitchC. When SwitchC pings the PC, the traffic from network segment to network segment is not allowed to pass.

acl name Vlan322Out 3022 
 rule 10 permit ip source destination  
 rule 30 permit ip source destination 
 rule 40 permit ip source destination 
 rule 50 permit ip source destination 
 rule 60 permit ip source destination 
 rule 1000 deny ip 
acl number 3144 
 rule 10 deny tcp destination-port eq 5554 
 rule 15 deny tcp destination-port eq 9995 
 rule 20 deny tcp destination-port eq 9996 
 rule 25 deny udp destination-port eq 445  
 rule 30 deny udp destination-port eq 1434 
 rule 35 deny ip source destination 
 rule 40 permit ip source destination 
 rule 45 permit ip source destination 
 rule 1000 deny ip 
interface GigabitEthernet1/0/7 
 port link-type access 
 port default vlan 322 
traffic-filter vlan 322 inbound acl 3144
traffic-filter vlan 322 outbound acl name Vlan322Out

2.       SwitchB connected to the PC is the VRRP backup device, and therefore Layer 2 forwarding is performed. In this case, the ping is successful only when traffic is allowed to pass in both directions. If the PC is connected to the VRRP master device, you only need to configure unidirectional traffic.

Troubleshooting Procedure

                          Step 1     Add the following rule to the ACL named Vlan322Out and numbered 3022: rule 20 permit ip source destination Then SwitchC can ping the PC, and the fault is rectified.


  • x
  • convention:

Created Mar 9, 2018 05:51:55

View more
  • x
  • convention:


You need to log in to comment to the post Login | Register

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits


Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Please bind your phone number to obtain invitation bonus.