<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: icx 7150 routing in ICX Switches</title>
    <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28826#M1416</link>
    <description>Duplicate IP somewhere?&lt;BR /&gt;you don't have anything else configured as 192.168.1.1 do you?&lt;BR /&gt;it could be responding to the pings when you think you are pinging the VE.</description>
    <pubDate>Thu, 13 Feb 2020 21:44:39 GMT</pubDate>
    <dc:creator>adam_foss</dc:creator>
    <dc:date>2020-02-13T21:44:39Z</dc:date>
    <item>
      <title>icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28816#M1406</link>
      <description>&lt;span class="lia-inline-image-display-wrapper" image-alt="Image_ images_messages_5f91c3fe135b77e24790f07f_7e42e015151b89749014b8b8e974665e_RackMultipart2020021311540817o-aa93c19c-9f5b-42e6-ae6d-e9775d4b2618-901360473.png1581624813"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/1814i1E42B10E8A4140BF/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image_ images_messages_5f91c3fe135b77e24790f07f_7e42e015151b89749014b8b8e974665e_RackMultipart2020021311540817o-aa93c19c-9f5b-42e6-ae6d-e9775d4b2618-901360473.png1581624813" alt="Image_ images_messages_5f91c3fe135b77e24790f07f_7e42e015151b89749014b8b8e974665e_RackMultipart2020021311540817o-aa93c19c-9f5b-42e6-ae6d-e9775d4b2618-901360473.png1581624813" /&gt;&lt;/span&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Needing a little help here please.&amp;nbsp; We have an environment with no router, but we do have a layer 3 switch.&amp;nbsp; Please refer to the diagram; we have a server with IP address 192.168.1.3 connected to Ethernet port 1 of the Brocade Ruckus ICX 7150 switch.&amp;nbsp; We have a fiber link on port 9 that goes out to a layer 2 switch.&amp;nbsp; On port 9 we have virtual interfaces for vlan 51 at 10.174.241.99 and vlan 351 at 11.174.246.99.&amp;nbsp; From the Brocade Ruckus we can ping the Camera at 11.174.246.30, so we are routing traffic as intended from the Brocade through the layer 2 switch (that has tagging) to the camera at 11.174.246.30.&amp;nbsp; What we need to do is have the server connect from its IP address of 192.168.1.3 to the camera at 11.174.246.30.&amp;nbsp; What configuration method would work best to achieve this goal?&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Thu, 13 Feb 2020 20:14:45 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28816#M1406</guid>
      <dc:creator>tony_butler_9y6</dc:creator>
      <dc:date>2020-02-13T20:14:45Z</dc:date>
    </item>
    <item>
      <title>Re: icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28817#M1407</link>
      <description>Good Afternoon:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;It is hard to visualize your setup because the masks weren't mentioned, but the 7150 can serve teh same function as a router.&amp;nbsp; Presumably, you create the router-interface ve interfaces??? and on int ve 51 set an IP within the subnet, and on int ve 351 set an IP within the subnet.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Then presumably, you carried port 9 to the Layer-2 switch, but I presume you used a media converter??? because there are no 7150 units with SFP or SFP+ slots to connect a fiber traceiver from port 1/1/9.&amp;nbsp; On the 7150, it is common place to place a fiber tranceiver into 1/3/x the way they are numbered.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;None the less, the port you are sending to the Layer-2 switch needs to carry both VLANS using 802.1q, so under each VLAN you would set that as TAGGED..&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vlan 52 name something by port&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;tagged e 1/1/9&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;router-interface ve 52&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vlan 351 name something-different by port&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;tagged e 1/1/9&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;router interface ve 251&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;int ve 52&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;port-name default gateway for 10.x network&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip add 10.x.x.x/yy&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;int ve 351&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;port-name default gateway for 11.x network&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip add 11.x.x.x/yy&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;On your layer-2 switch, I am confused that you said, "NATIVE" because that usually refers to an untagged interface that is also tagged in another VLAN.&amp;nbsp; In ICX terminology, this used to be referred to as a dual-mode port, which regardless of terminology&amp;nbsp; carries untagged ethernet frames into a particular vlan.&amp;nbsp; That said any particular interface can be untagged into only one vlan given the constraint the switch needs to know what VLAN to sort untagged frames it receives into (as well as transmit).&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;***&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;The reason your ping is likley working is that most likely your ICX 7150 is sourcing the ping from 11.x.x.x, which is on a directly-connected network, but this is just speculation being I cannot see your environment.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Regardless, to make this work, you will need some routing to occur between your 192.168.1.0/24 (presumably I am guessing at the mask) network.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Perhaps:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vlan 192 name servers by port&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;untagged ethe 1/1/1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;router-interface ve 192&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;int ve 192&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;port-name Default gateway for 192.168.1 network used by servers.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip add 192.168.1.1/24&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;***&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;This assumes the server is directly connected to interface 1 on the 7150 and that you have the default-gateway defined on the server as 192.168.1.1, that the mask is 255.255.255.0, that the server sends traffic without an 802.1q tag on the frame... that your network is not more complex than diagramed.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;***&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Lastly, may I suggest for private use to stick with the RFC1918 IPs.&amp;nbsp; 11's are Internet routable.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;You want to variably subset your private network subnets from these larger subnets:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;192.168.0.0/16&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;172.16.0.0/12&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;10.0.0.0/8&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Hope this helps.</description>
      <pubDate>Thu, 13 Feb 2020 20:37:43 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28817#M1407</guid>
      <dc:creator>netwizz</dc:creator>
      <dc:date>2020-02-13T20:37:43Z</dc:date>
    </item>
    <item>
      <title>Re: icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28818#M1408</link>
      <description>Does the server already have an existing gateway configured?&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;It may need a static route put in to point at the network the camera is on.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;if the server doesn't have a gateway configured, Create another VE on the L3 switch for that vlan.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Thu, 13 Feb 2020 20:41:39 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28818#M1408</guid>
      <dc:creator>adam_foss</dc:creator>
      <dc:date>2020-02-13T20:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28819#M1409</link>
      <description>Nope, this is a misnomer.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;U alt="" name="" rel="" target="" title="" type="" value=""&gt;No static route should be needed giving the diagram&lt;/U&gt; above because there is only one (1) layer-3 device doing any routing, and this device would automatically add to its routing table the directly-connected routes for any IPs assigned to its interfaces - typically VRIs (Virtual Router Interfaces), which are your "interface ve xxx".&amp;nbsp; Other vendors call these SVIs (Software Virtual Interfaces), and those are typically "interface vlan xxx."&amp;nbsp; It is the same concept though.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Regardless, as a general rule of thumb once you place an IP address with its Mask on an interface, that entire subnet will show up in the routing-table as a directly-connected route meaning that layer-3 device owns that subnet.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;A static-route would be to tell another layer-3 device that doesn't have that subnet or know how to get to that subnet to get to that subnet via a next-hop IP or via one of its interfaces.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;In this case with this diagram, the routing table will look something like this if Op assigns 192.168.1.1/24 to ve 192, and places at least one actual interface that is UP into that VLAN, so the VE changes its state to up/up (required to get the route inserted):&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;PRE alt="" name="" rel="" target="" title="" type="" value=""&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;SSH@OPsICX7150#sh ip route&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Total number of IP routes: 1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Type Codes - B:BGP D:Connected O:OSPF R:RIP S:Static; Cost - Dist/Metric&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;BGP&amp;nbsp; Codes - i:iBGP e:eBGP&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;OSPF Codes - i:Inter Area 1:External Type 1 2:External Type 2&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Destination&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Port&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Cost&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Type Uptime&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;192.168.1.0/24&amp;nbsp; DIRECT&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ve 192&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0/0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;D&amp;nbsp; &amp;nbsp; 1d6h&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;SSH@OpsICX7150#&lt;/PRE&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;There would be other&amp;nbsp; routing table entries for subnets directly-connected on ve 52, and ve 351, too.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;****&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;If you are referring to the server needing a static route, while that's true, it will already have a default route, which is used by the OS to get to any network which is not in the 192.168.1.x network the server is assigned.&amp;nbsp; Any other IP would cause the server to forward those packets to its default-gateway, which if the config tweaks I suggested are made would be 192.168.1.1, and the server would find that being its subnet 192.168.1.3/24 is within the same subnet as the default-gateway.&amp;nbsp; That is to say the server is on the same layer-2 subnet as the default-gateway.&amp;nbsp; In reality, it is just plugged into interface 1/1/1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;In Windows, you can do a c:\&amp;gt;print route if you really want from a cmd prompt.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;You would be looking for something like this&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;print route&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Unable to initialize device PRN&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;PRE alt="" name="" rel="" target="" title="" type="" value=""&gt;C:\Users\Netwizz&amp;gt;route print&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;===========================================================================&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Interface List&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;REDACTED&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;===========================================================================&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;IPv4 Route Table&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;===========================================================================&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Active Routes:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Network Destination&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Netmask&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Gateway&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Interface&amp;nbsp; Metric&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.0.0.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0.0.0.0&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;192.168.1.1&amp;nbsp; &amp;nbsp; &amp;nbsp; 192.168.1.3&amp;nbsp; &amp;nbsp;281&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;/REDACTED&gt;&lt;/PRE&gt;&lt;REDACTED&gt;&lt;/REDACTED&gt;</description>
      <pubDate>Thu, 13 Feb 2020 20:52:31 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28819#M1409</guid>
      <dc:creator>netwizz</dc:creator>
      <dc:date>2020-02-13T20:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28820#M1410</link>
      <description>Very Helpful NetWizz!&amp;nbsp; You are so correct, we are actually in port 1/3/1 for the fiber link.&amp;nbsp; I was trying to simplify things and I made it more confusing.&amp;nbsp; Thank you!&amp;nbsp; We are running subnet mask of 255.255.255.0 on all subnets.&amp;nbsp; &amp;nbsp;You are also correct on our ve settings:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vlan 51&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;tagged ethernet 1/3/1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;router-interface ve 51&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;int ve 51&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip address 10.174.241.99/24&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vlan 351&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;tagged ethernet 1/3/1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;router-interface ve 351&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;int ve 351&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip address 11.174.246.99/24&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;The vlan of the layer 2 switch is 51 for its subnet address of 10.174.241.20.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;The server only has ip of 192.168.1.3 and mask of 255.255.255.0, we left the gateway empty.&amp;nbsp;&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;We are adding this now:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vlan 192&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;untagged ethe 1/1/1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;router-interface ve 192&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;int ve 192&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip add 192.168.1.1/24&lt;BR /&gt;&lt;BR /&gt;We will set the server gateway to 192.168.1.1 and do some testing and get back to you.&amp;nbsp; Thank you so much!!!&amp;nbsp; You are awesome</description>
      <pubDate>Thu, 13 Feb 2020 20:56:38 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28820#M1410</guid>
      <dc:creator>tony_butler_9y6</dc:creator>
      <dc:date>2020-02-13T20:56:38Z</dc:date>
    </item>
    <item>
      <title>Re: icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28821#M1411</link>
      <description>Hi Adam.&amp;nbsp; The server did not have a gateway, but with NetWizz's input we added a ve on port 1/1/1 with ip 192.168.1.1, and now have added the gateway of 192.168.1.1 to the server.&amp;nbsp; We can ping the ve port of 192.168.1.1 now, but if we try to ping the tagged ve's on 1/3/1 we fail in transit.&amp;nbsp;&amp;nbsp;</description>
      <pubDate>Thu, 13 Feb 2020 21:05:08 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28821#M1411</guid>
      <dc:creator>tony_butler_9y6</dc:creator>
      <dc:date>2020-02-13T21:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28822#M1412</link>
      <description>This is what our sh ip route looks like;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;01&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;10.174.241.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp; DIRECT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ve 51&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D&amp;nbsp;&amp;nbsp;&amp;nbsp;
1h46m &lt;/P&gt;

&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;02 &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;11.174.246.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp; DIRECT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ve 351&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D&amp;nbsp;&amp;nbsp;&amp;nbsp;
1h46m &lt;/P&gt;

&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;03&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;
192.168.1.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DIRECT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ve 192&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D&amp;nbsp;&amp;nbsp;&amp;nbsp;
12m52s&lt;/P&gt;

&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;&lt;/P&gt;04&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.45.0/24&amp;nbsp;&amp;nbsp;&amp;nbsp; DIRECT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; e mgmt1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0/0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; D&amp;nbsp;&amp;nbsp;&amp;nbsp;
2h2m&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Thu, 13 Feb 2020 21:14:23 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28822#M1412</guid>
      <dc:creator>tony_butler_9y6</dc:creator>
      <dc:date>2020-02-13T21:14:23Z</dc:date>
    </item>
    <item>
      <title>Re: icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28823#M1413</link>
      <description>just to clarify, I mentioned the static route in the case that the server was already using a different router.&lt;BR /&gt;&lt;BR /&gt;I know he said he didn't have one, but sometimes things are omitted.</description>
      <pubDate>Thu, 13 Feb 2020 21:18:13 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28823#M1413</guid>
      <dc:creator>adam_foss</dc:creator>
      <dc:date>2020-02-13T21:18:13Z</dc:date>
    </item>
    <item>
      <title>Re: icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28824#M1414</link>
      <description>All good, no router here.&amp;nbsp; I know it's confusing.&amp;nbsp; I'm trying.&amp;nbsp; If we had a router, we'd be done last week.&amp;nbsp; lol</description>
      <pubDate>Thu, 13 Feb 2020 21:24:18 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28824#M1414</guid>
      <dc:creator>tony_butler_9y6</dc:creator>
      <dc:date>2020-02-13T21:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28825#M1415</link>
      <description>With all that is added, from the server we can ping 192.168.1.1 on the ve.&amp;nbsp; From the Layer 3 switch Brocade switch however, we cannot ping the server at 192.168.1.3.&amp;nbsp; Any ideas?&amp;nbsp;&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Switch#ping 192.168.1.3&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Sending 1, 16-byte ICMP Echo to 192.168.1.3, timeout 5000 msec, TTL 64&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Type Control-c to abort&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Request timed out.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;No reply from remote host.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;It's most strange as the server shows up in arp:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Switch#sh arp&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Total number of ARP entries: 2&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Entries in default routing instance:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;No.&amp;nbsp; &amp;nbsp;IP Address&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;MAC Address&amp;nbsp; &amp;nbsp; Type&amp;nbsp; &amp;nbsp; &amp;nbsp;Age Port&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Status&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;1&amp;nbsp; &amp;nbsp; &amp;nbsp;10.174.241.20&amp;nbsp; &amp;nbsp; 000b.abec.9d67 Dynamic&amp;nbsp; 0&amp;nbsp; &amp;nbsp; 1/3/1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Valid&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;2&amp;nbsp; &amp;nbsp; &amp;nbsp;192.168.1.3&amp;nbsp; &amp;nbsp; &amp;nbsp; 54b2.0382.fd5e Dynamic&amp;nbsp; 2&amp;nbsp; &amp;nbsp; 1/1/1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Valid &lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Thu, 13 Feb 2020 21:33:39 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28825#M1415</guid>
      <dc:creator>tony_butler_9y6</dc:creator>
      <dc:date>2020-02-13T21:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28826#M1416</link>
      <description>Duplicate IP somewhere?&lt;BR /&gt;you don't have anything else configured as 192.168.1.1 do you?&lt;BR /&gt;it could be responding to the pings when you think you are pinging the VE.</description>
      <pubDate>Thu, 13 Feb 2020 21:44:39 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28826#M1416</guid>
      <dc:creator>adam_foss</dc:creator>
      <dc:date>2020-02-13T21:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28827#M1417</link>
      <description>Pretty much a closed lab network.&amp;nbsp; Just the server, ruckus, layer 2 switch, and camera.&amp;nbsp; Nothing duplicate.&amp;nbsp; Here's the running config:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;RuckusSWitch#sh running-config&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Current configuration:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ver 08.0.90eT213&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;stack unit 1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; module 1 icx7150-c12-poe-port-management-module&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; module 2 icx7150-2-copper-port-2g-module&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; module 3 icx7150-2-sfp-plus-port-20g-module&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; stack-port 1/3/1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; stack-port 1/3/2&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vlan 1 name DEFAULT-VLAN by port&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;router-interface ve 1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vlan 51 by port&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;tagged ethe 1/3/1&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;router-interface ve 51&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vlan 192 by port&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;untagged ethe 1/1/1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;router-interface ve 192&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vlan 351 by port&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;tagged ethe 1/3/1&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;router-interface ve 351&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication web-server default local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication enable default local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication login default local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication login privilege-mode&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;enable telnet password .....&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;enable super-user-password .....&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;enable aaa console&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;hostname RuckusSWitch&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip add-host-route-first&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip router-id 192.168.2.1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;username admin password .....&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;sz registrar&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;interface management 1&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;ip address 192.168.45.44 255.255.255.0&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;interface ethernet 1/3/1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;speed-duplex 1000-full&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;interface ve 1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;interface ve 51&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;ip address 10.174.241.99 255.255.255.0&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;interface ve 192&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;ip address 192.168.1.1 255.255.255.0&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;interface ve 351&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;ip address 11.174.246.99 255.255.255.0&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;end&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Thu, 13 Feb 2020 22:01:53 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28827#M1417</guid>
      <dc:creator>tony_butler_9y6</dc:creator>
      <dc:date>2020-02-13T22:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28828#M1418</link>
      <description>Firewall was turned on at the server blocking our pings.&amp;nbsp; We can now ping from the ICX 7150 switch to the server, however the server still cannot ping the ve addresses of 10.174.241.99 or 11.174.246.99, or the end devices at 10.174.241.20 and 11.174.246.30.&amp;nbsp; Any ideas?&amp;nbsp; Help please.</description>
      <pubDate>Thu, 13 Feb 2020 22:10:53 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28828#M1418</guid>
      <dc:creator>tony_butler_9y6</dc:creator>
      <dc:date>2020-02-13T22:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28829#M1419</link>
      <description>&lt;span class="lia-inline-image-display-wrapper" image-alt="Image_ images_messages_5f91c47b135b77e247ab2500_cbac8f9eab0bdd899184a2e44a70950e_RackMultipart2020021321350n219-7a54113f-20d3-4f37-9330-70fedc9fb8cd-2006487827.png1581634389"&gt;&lt;img src="https://community.ruckuswireless.com/t5/image/serverpage/image-id/1813i6B78A359082B51B2/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image_ images_messages_5f91c47b135b77e247ab2500_cbac8f9eab0bdd899184a2e44a70950e_RackMultipart2020021321350n219-7a54113f-20d3-4f37-9330-70fedc9fb8cd-2006487827.png1581634389" alt="Image_ images_messages_5f91c47b135b77e247ab2500_cbac8f9eab0bdd899184a2e44a70950e_RackMultipart2020021321350n219-7a54113f-20d3-4f37-9330-70fedc9fb8cd-2006487827.png1581634389" /&gt;&lt;/span&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;We've made a few updates since this was posted, but we still can't communicate across the subnets.&amp;nbsp; I realize I left off a lot of information while trying to stick to the basics.&amp;nbsp; We've figured a lot out, but we're not there yet.&amp;nbsp; We made a VE on port 1/1/1 of the ruckus and assigned it vlan 192 with ip 192.168.1.1.&amp;nbsp; We set the gateway of the server to 192.168.1.1.&amp;nbsp; We can now ping the gateway on the switch, and from the switch we can ping the server.&amp;nbsp; We still cannot ping across the subnets. &amp;nbsp;&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;The fiber port isn't on port 9, it's actually on port 1/3/1. &amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;We've added the static routes below on the server, but it didn't help, still can't ping the camera at 11.174.246.30.&lt;/P&gt;route add 10.174.241.0 mask 255.255.255.0 192.168.1.1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;route add 11.174.246.0 mask 255.255.255.0 192.168.1.1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;Here is a copy of our running switch config:&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;RuckusSWitch#sh running-config&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;/P&gt;&lt;P alt="" name="" rel="" target="" title="" type="" value=""&gt;Current configuration:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ver 08.0.90eT213&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;stack unit 1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; module 1 icx7150-c12-poe-port-management-module&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; module 2 icx7150-2-copper-port-2g-module&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; module 3 icx7150-2-sfp-plus-port-20g-module&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; stack-port 1/3/1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp; stack-port 1/3/2&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vlan 1 name DEFAULT-VLAN by port&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;router-interface ve 1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vlan 51 by port&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;tagged ethe 1/3/1&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;router-interface ve 51&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vlan 192 by port&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;untagged ethe 1/1/1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;router-interface ve 192&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;vlan 351 by port&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;tagged ethe 1/3/1&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;router-interface ve 351&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication web-server default local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication enable default local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication login default local&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;aaa authentication login privilege-mode&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;enable telnet password ..... &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;enable super-user-password .....&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;enable aaa console&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;hostname RuckusSWitch&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip add-host-route-first&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip router-id 192.168.2.1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;username admin password .....&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;sz registrar&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;interface management 1 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;ip address 192.168.45.44 255.255.255.0&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;interface ethernet 1/3/1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;speed-duplex 1000-full&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;interface ve 1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;interface ve 51&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;ip address 10.174.241.99 255.255.255.0&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;interface ve 192&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;ip address 192.168.1.1 255.255.255.0&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;interface ve 351&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;ip address 11.174.246.99 255.255.255.0&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;/P&gt;end&lt;BR /&gt;&lt;BR /&gt;Any and all help/suggestions are appreciated.</description>
      <pubDate>Thu, 13 Feb 2020 22:55:12 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28829#M1419</guid>
      <dc:creator>tony_butler_9y6</dc:creator>
      <dc:date>2020-02-13T22:55:12Z</dc:date>
    </item>
    <item>
      <title>Re: icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28830#M1420</link>
      <description>Our original configurations left out gateway as we had no router and were working on layer 2.&amp;nbsp; After adding the layer 3 switch with ve's we never went back and added the gateways.&amp;nbsp; Once we added the ve ip's as the gateways for each device in its subnet it worked like a charm.&amp;nbsp;&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Fri, 14 Feb 2020 01:38:58 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28830#M1420</guid>
      <dc:creator>tony_butler_9y6</dc:creator>
      <dc:date>2020-02-14T01:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: icx 7150 routing</title>
      <link>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28831#M1421</link>
      <description>Glad you got it.&amp;nbsp; Sorry, I hadn't responded earlier, but I had just gotten off work after spending about three hours a night sleeping much of the week.&amp;nbsp; I was exhausted.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;It is good that adding the Gateways worked because my next suggestions were to be to ask you if you left out some Access Lists in the posted configuration.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;As for the server, you shouldn't need these:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;PRE alt="" name="" rel="" target="" title="" type="" value=""&gt;route add 10.174.241.0 mask 255.255.255.0 192.168.1.1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;route add 11.174.246.0 mask 255.255.255.0 192.168.1.1&lt;/PRE&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;That is because there should be a route already by default on any Windows, Mac, or Linux box for 0.0.0.0 0.0.0.0 via 192.168.1.1, which is a catch-all..&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;You can verify that is present with "print route"&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;It simply means if it is not within 192.168.1.0/24 to forward everything to 192.168.1.1&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;*****&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I would highly recommend SSH instead of Telnet:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;PRE alt="" name="" rel="" target="" title="" type="" value=""&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;crypto key zeroize rsa&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;crypto key zeroize dsa&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;crypto key generate rsa mod 2048&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;PAUSE here="" giving="" it="" time="" to="" generate="" before="" generating="" a="" cert="" even="" though="" you="" immediately="" have="" a="" prompt=""&gt;
&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;crypto-ssl certificate generate&lt;/PAUSE&gt;&lt;/PRE&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;To validate it is enabled, you can type:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;PRE alt="" name="" rel="" target="" title="" type="" value=""&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;RuckusSWitch#show ip ssh&lt;/PRE&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;If you want, you can create an ACL to lockdown remote management.&amp;nbsp; Let's say you call this access lists 99.&amp;nbsp; You need only put in the permit statements because there is already an implicit deny at the end, but you can put specific hosts and subsets like this.&amp;nbsp; You can use wildcard masks, too if you like.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;PRE alt="" name="" rel="" target="" title="" type="" value=""&gt;ip access-list standard 99&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;permit host 10.1.2.3&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;permit 10.2.0.0 0.0.255.255&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;exit&lt;/PRE&gt;Locking down web and ssh management to your ACL above:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;PRE alt="" name="" rel="" target="" title="" type="" value=""&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ssh access-group 99&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;web access-group 99&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;/PRE&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;I usually setup logging to syslog and a console logout:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;PRE alt="" name="" rel="" target="" title="" type="" value=""&gt;console timeout 30&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;logging host 10.1.2.3&lt;/PRE&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;If it has Interet Access or there is an NTP server, I would certainly set the timezone and clock:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;PRE alt="" name="" rel="" target="" title="" type="" value=""&gt;clock summer-time&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;clock timezone us Eastern&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ntp&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&amp;nbsp;server 10.1.2.3&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;!&lt;/PRE&gt;Secure web management only should you want to use web management:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;PRE alt="" name="" rel="" target="" title="" type="" value=""&gt;no web-management http&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;web-management https&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;/PRE&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Some Banner:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;PRE alt="" name="" rel="" target="" title="" type="" value=""&gt;banner motd ^&lt;/PRE&gt;&lt;PRE alt="" name="" rel="" target="" title="" type="" value=""&gt;------------------------------------------------------------------------&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Some Name&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Some business warning text approved by your legal department...&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Asset 123456&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;------------------------------------------------------------------------&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;^&lt;/PRE&gt;A little hardening of SSH:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;PRE alt="" name="" rel="" target="" title="" type="" value=""&gt;ip ssh&amp;nbsp; authentication-retries 2&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip ssh&amp;nbsp; timeout 30&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip ssh&amp;nbsp; idle-time 30&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip ssh&amp;nbsp; scp disable&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;ip ssh&amp;nbsp; encryption disable-aes-cbc&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;/PRE&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Better logging:&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;PRE alt="" name="" rel="" target="" title="" type="" value=""&gt;logging console&amp;nbsp;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;logging persistence&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;/PRE&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;After this, you should use a tool such as Secure CRT or Putty selecting SSH to connect to the device.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;Should you want to see network flows, you can use pretty much any NetFlow Analizer tool.&amp;nbsp; Although I currently use Solar Winds Orion even though Manage Engine's NetFlow Analizer was better for me, you might find a free one.&amp;nbsp; I see Solar Winds has one, but you would probably want to check the licencing.&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;PRE&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;sflow agent-ip &lt;AN ip="" on="" your="" icx=""&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;sflow sample 512&lt;BR /&gt;sflow polling-interval 30&lt;BR /&gt;sflow destination 10.1.2.3&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;sflow enable&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;!&lt;/AN&gt;&lt;/PRE&gt;&lt;BR /&gt;On the physical interfaces you want to track, you most likley need to add "sflow forwarding"&lt;BR /&gt;&lt;BR /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;&lt;BR alt="" name="" rel="" target="" title="" type="" value="" /&gt;</description>
      <pubDate>Fri, 14 Feb 2020 13:08:39 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ICX-Switches/icx-7150-routing/m-p/28831#M1421</guid>
      <dc:creator>netwizz</dc:creator>
      <dc:date>2020-02-14T13:08:39Z</dc:date>
    </item>
  </channel>
</rss>

