XGS1930-24 External Traffic problem

tczauderna
tczauderna Posts: 28  Freshman Member
Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula

I just got a new XGS1930 model and I have a strange problem. Despite configuring GW DNS, unfortunately the switch does not have access to external services including Nebula. However, I am connected to this switch with a laptop on port 2 and the exact same communication works correctly. I have updated the firmware to the latest version. I admit that this is the first time I have encountered such a situation. Has anyone encountered a similar situation?

«1

All Replies

  • tczauderna
    tczauderna Posts: 28  Freshman Member
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula

    I will add that internal communication works correctly according to the diagnostics on the switch.

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,854  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @tczauderna,

    I assume your switch has configured the correct IP address, default gateway, and DNS server. Your XGS1930-24(actually is XGS1930-28) can't connect to Nebula because it isn't in any Nebula org/site now.

    • If you want to use Nebula to manage this switch, please add it to your organization/site.
    • If you just want to check the Internet connectivity, you can access Menu > Management > Diagnostic page to test.
    Zyxel Melen


  • tczauderna
    tczauderna Posts: 28  Freshman Member
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula

    Maybe to avoid any assumptions I am pasting the configuration, there is no neurological data here

    As you can see with this configuration it doesn't work correctly. I am connected through this switch with my laptop and I have exactly the same DNS gateway configuration and I have correct communication

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,854  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @tczauderna,

    Could you help to collect the tech support file so I can help to check?

    You can follow this FAQ to collect and share it with me via private message.

    Zyxel Melen


  • tczauderna
    tczauderna Posts: 28  Freshman Member
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula

    I'm still looking for some restrictions on UTM fortigate but unfortunately I don't see anything that could block the traffic. because as you can see it's not just about nebula but also the local service.
    As you can see DNS itself communicates outside but ICMP traffic doesn't.

    P.S. There's no curl or wget interface on the switch sometimes it would be useful

  • tczauderna
    tczauderna Posts: 28  Freshman Member
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula
    edited February 18

    Remove the tech support by Zyxel Melen

    Here it may be interesting because it looks a bit like it doesn't assign this Default GW to the virtual VLAN interface. And maybe we have a problem here or maybe I didn't notice something somewhere

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,854  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @tczauderna,

    Could you help me do some ping tests? The destinations are "10.0.10.1" and "1.1.1.1".

    Also, here's Nebula switch offline troubleshooting guide for reference:

    https://community.zyxel.com/en/discussion/17937/zyxel-nebula-switch-troubleshooting-guide

    Zyxel Melen


  • tczauderna
    tczauderna Posts: 28  Freshman Member
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula

    as for nebula, you know, until we figure out what's wrong with the communication on the switch, Nebula won't work

  • tczauderna
    tczauderna Posts: 28  Freshman Member
    Zyxel Certified Network Administrator - WLAN Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Security Zyxel Certified Network Administrator - Nebula

    ZON and laptop connected to this switch

  • Zyxel_Melen
    Zyxel_Melen Posts: 2,854  Zyxel Employee
    Zyxel Certified Network Engineer Level 1 - Switch Zyxel Certified Network Administrator - Switch Zyxel Certified Network Administrator - Nebula Zyxel Certified Sales Associate

    Hi @tczauderna,

    According to the ping test result, the problem should be on your gateway. It seems like the switch can ping to the gateway but cannot ping to the Internet.

    Zyxel Melen