ssh 10.0.7.2 -l root
cp /etc/config/network /etc/config/network.org
vi /etc/config/network
config device option name 'br-lan' option type 'bridge' list ports 'eth0.1'
config device option name 'br-vlan1' option type 'bridge' list ports 'eth0.1'
config interface 'lan' option device 'br-lan' option proto 'static' option ipaddr '192.168.1.1' option netmask '255.255.255.0' option ip6assign '60'
config interface 'vlan1' option device 'br-vlan1' option proto 'static' option ipaddr '10.0.7.2/24' option gateway '10.0.7.1' list dns '10.0.7.1'
ping 10.0.7.2 -t
It's important to me that i understand what I'm doing rather than relying on magic,
You say that config was working with the following setting active ?!?!:OpenWRT -> Network -> Interfaces -> lan -> Edit -> Tab: Firewall Settings -> LAN ?And if you changed that to "unspecified" your loosing connection ?
config interface 'vlan1' option device 'br-vlan1' option proto 'static' option ipaddr '10.0.7.2/24' <--- wrong option gateway '10.0.7.1' list dns '10.0.7.1'
config interface 'vlan1' option device 'br-vlan1' option proto 'static' option ipaddr '10.0.7.2' <--- right option netmask '255.255.255.0' <--- right option gateway '10.0.7.1' list dns '10.0.7.1'
it's hard to configure an infra from far away
I factory reset, then applied these settings (did not touch anything else like firewall), and rebooted, still disconnected. Current config attached.
show interfaces switchport
Name: Gi1/0/1Switchport: EnabledAdministrative Mode: trunkOperational Mode: trunkAdministrative Trunking Encapsulation: dot1qOperational Trunking Encapsulation: dot1qNegotiation of Trunking: OnAccess Mode VLAN: 1 (default)Trunking Native Mode VLAN: 1 (default)Administrative Native VLAN tagging: enabledVoice VLAN: noneAdministrative private-vlan host-association: noneAdministrative private-vlan mapping: noneAdministrative private-vlan trunk native VLAN: noneAdministrative private-vlan trunk Native VLAN tagging: enabledAdministrative private-vlan trunk encapsulation: dot1qAdministrative private-vlan trunk normal VLANs: noneAdministrative private-vlan trunk associations: noneAdministrative private-vlan trunk mappings: noneOperational private-vlan: noneTrunking VLANs Enabled: ALLPruning VLANs Enabled: 2-1001Capture Mode DisabledCapture VLANs Allowed: ALLProtected: falseUnknown unicast blocked: disabledUnknown multicast blocked: disabledAppliance trust: noneName: Gi1/0/2Switchport: EnabledAdministrative Mode: static accessOperational Mode: downAdministrative Trunking Encapsulation: negotiateNegotiation of Trunking: OffAccess Mode VLAN: 2 (VLAN0002)Trunking Native Mode VLAN: 1 (default)Administrative Native VLAN tagging: enabledVoice VLAN: noneAdministrative private-vlan host-association: noneAdministrative private-vlan mapping: noneAdministrative private-vlan trunk native VLAN: noneAdministrative private-vlan trunk Native VLAN tagging: enabledAdministrative private-vlan trunk encapsulation: dot1qAdministrative private-vlan trunk normal VLANs: noneAdministrative private-vlan trunk associations: noneAdministrative private-vlan trunk mappings: noneOperational private-vlan: noneTrunking VLANs Enabled: ALLPruning VLANs Enabled: 2-1001Capture Mode DisabledCapture VLANs Allowed: ALLProtected: falseUnknown unicast blocked: disabledUnknown multicast blocked: disabledAppliance trust: noneName: Gi1/0/3Switchport: EnabledAdministrative Mode: static accessOperational Mode: downAdministrative Trunking Encapsulation: negotiateNegotiation of Trunking: OffAccess Mode VLAN: 3 (VLAN0003)Trunking Native Mode VLAN: 1 (default)Administrative Native VLAN tagging: enabledVoice VLAN: noneAdministrative private-vlan host-association: noneAdministrative private-vlan mapping: noneAdministrative private-vlan trunk native VLAN: noneAdministrative private-vlan trunk Native VLAN tagging: enabledAdministrative private-vlan trunk encapsulation: dot1qAdministrative private-vlan trunk normal VLANs: noneAdministrative private-vlan trunk associations: noneAdministrative private-vlan trunk mappings: noneOperational private-vlan: noneTrunking VLANs Enabled: ALLPruning VLANs Enabled: 2-1001Capture Mode DisabledCapture VLANs Allowed: ALLProtected: falseUnknown unicast blocked: disabledUnknown multicast blocked: disabledAppliance trust: noneName: Gi1/0/4Switchport: EnabledAdministrative Mode: static accessOperational Mode: downAdministrative Trunking Encapsulation: negotiateNegotiation of Trunking: OffAccess Mode VLAN: 4 (VLAN0004)Trunking Native Mode VLAN: 1 (default)Administrative Native VLAN tagging: enabledVoice VLAN: noneAdministrative private-vlan host-association: noneAdministrative private-vlan mapping: noneAdministrative private-vlan trunk native VLAN: noneAdministrative private-vlan trunk Native VLAN tagging: enabledAdministrative private-vlan trunk encapsulation: dot1qAdministrative private-vlan trunk normal VLANs: noneAdministrative private-vlan trunk associations: noneAdministrative private-vlan trunk mappings: noneOperational private-vlan: noneTrunking VLANs Enabled: ALLPruning VLANs Enabled: 2-1001Capture Mode DisabledCapture VLANs Allowed: ALLProtected: falseUnknown unicast blocked: disabledUnknown multicast blocked: disabledAppliance trust: noneName: Gi1/0/5Switchport: EnabledAdministrative Mode: static accessOperational Mode: downAdministrative Trunking Encapsulation: negotiateNegotiation of Trunking: OffAccess Mode VLAN: 5 (VLAN0005)Trunking Native Mode VLAN: 1 (default)Administrative Native VLAN tagging: enabledVoice VLAN: noneAdministrative private-vlan host-association: noneAdministrative private-vlan mapping: noneAdministrative private-vlan trunk native VLAN: noneAdministrative private-vlan trunk Native VLAN tagging: enabledAdministrative private-vlan trunk encapsulation: dot1qAdministrative private-vlan trunk normal VLANs: noneAdministrative private-vlan trunk associations: noneAdministrative private-vlan trunk mappings: noneOperational private-vlan: noneTrunking VLANs Enabled: ALLPruning VLANs Enabled: 2-1001Capture Mode DisabledCapture VLANs Allowed: ALLProtected: falseUnknown unicast blocked: disabledUnknown multicast blocked: disabledAppliance trust: noneName: Gi1/0/6Switchport: EnabledAdministrative Mode: trunkOperational Mode: downAdministrative Trunking Encapsulation: dot1qNegotiation of Trunking: OffAccess Mode VLAN: 1 (default)Trunking Native Mode VLAN: 7 (VLAN0007)Administrative Native VLAN tagging: enabledVoice VLAN: noneAdministrative private-vlan host-association: noneAdministrative private-vlan mapping: noneAdministrative private-vlan trunk native VLAN: noneAdministrative private-vlan trunk Native VLAN tagging: enabledAdministrative private-vlan trunk encapsulation: dot1qAdministrative private-vlan trunk normal VLANs: noneAdministrative private-vlan trunk associations: noneAdministrative private-vlan trunk mappings: noneOperational private-vlan: noneTrunking VLANs Enabled: ALLPruning VLANs Enabled: 2-1001Capture Mode DisabledCapture VLANs Allowed: ALLProtected: falseUnknown unicast blocked: disabledUnknown multicast blocked: disabledAppliance trust: noneName: Gi1/0/7Switchport: EnabledAdministrative Mode: dynamic autoOperational Mode: downAdministrative Trunking Encapsulation: negotiateNegotiation of Trunking: OnAccess Mode VLAN: 1 (default)Trunking Native Mode VLAN: 1 (default)Administrative Native VLAN tagging: enabledVoice VLAN: noneAdministrative private-vlan host-association: noneAdministrative private-vlan mapping: noneAdministrative private-vlan trunk native VLAN: noneAdministrative private-vlan trunk Native VLAN tagging: enabledAdministrative private-vlan trunk encapsulation: dot1qAdministrative private-vlan trunk normal VLANs: noneAdministrative private-vlan trunk associations: noneAdministrative private-vlan trunk mappings: noneOperational private-vlan: noneTrunking VLANs Enabled: ALLPruning VLANs Enabled: 2-1001Capture Mode DisabledCapture VLANs Allowed: ALLProtected: falseUnknown unicast blocked: disabledUnknown multicast blocked: disabledAppliance trust: none
Ok, I think I've got what you want.
show running-config
It's really hard to get SSH to work on this switch, it's very old, just a device to learn on before I deem myself worthy of better hardware.
ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 username@ciscoswitch
switch#show running-configBuilding configuration...Current configuration : 5809 bytes!! Last configuration change at 13:01:15 UTC Wed Dec 13 2023! NVRAM config last updated at 16:10:25 UTC Tue Dec 12 2023!version 12.2no service padservice timestamps debug datetime msecservice timestamps log datetime msecno service password-encryption!hostname switch!boot-start-markerboot-end-marker!enable secret 5 REDACTED!!!no aaa new-modelclock timezone UTC -5clock summer-time UTC recurringswitch 1 provision ws-c3750x-24system mtu routing 1500!!ip domain-name home!mls qos map cos-dscp 0 8 16 24 32 46 48 56mls qos srr-queue input bandwidth 70 30mls qos srr-queue input threshold 1 80 90mls qos srr-queue input priority-queue 2 bandwidth 30mls qos srr-queue input cos-map queue 1 threshold 2 3mls qos srr-queue input cos-map queue 1 threshold 3 6 7mls qos srr-queue input cos-map queue 2 threshold 1 4mls qos srr-queue input dscp-map queue 1 threshold 2 24mls qos srr-queue input dscp-map queue 1 threshold 3 48 49 50 51 52 53 54 55mls qos srr-queue input dscp-map queue 1 threshold 3 56 57 58 59 60 61 62 63mls qos srr-queue input dscp-map queue 2 threshold 3 32 33 40 41 42 43 44 45mls qos srr-queue input dscp-map queue 2 threshold 3 46 47mls qos srr-queue output cos-map queue 1 threshold 3 4 5mls qos srr-queue output cos-map queue 2 threshold 1 2mls qos srr-queue output cos-map queue 2 threshold 2 3mls qos srr-queue output cos-map queue 2 threshold 3 6 7mls qos srr-queue output cos-map queue 3 threshold 3 0mls qos srr-queue output cos-map queue 4 threshold 3 1mls qos srr-queue output dscp-map queue 1 threshold 3 32 33 40 41 42 43 44 45mls qos srr-queue output dscp-map queue 1 threshold 3 46 47mls qos srr-queue output dscp-map queue 2 threshold 1 16 17 18 19 20 21 22 23mls qos srr-queue output dscp-map queue 2 threshold 1 26 27 28 29 30 31 34 35mls qos srr-queue output dscp-map queue 2 threshold 1 36 37 38 39mls qos srr-queue output dscp-map queue 2 threshold 2 24mls qos srr-queue output dscp-map queue 2 threshold 3 48 49 50 51 52 53 54 55mls qos srr-queue output dscp-map queue 2 threshold 3 56 57 58 59 60 61 62 63mls qos srr-queue output dscp-map queue 3 threshold 3 0 1 2 3 4 5 6 7mls qos srr-queue output dscp-map queue 4 threshold 1 8 9 11 13 15mls qos srr-queue output dscp-map queue 4 threshold 2 10 12 14mls qos queue-set output 1 threshold 1 100 100 50 200mls qos queue-set output 1 threshold 2 125 125 100 400mls qos queue-set output 1 threshold 3 100 100 100 400mls qos queue-set output 1 threshold 4 60 150 50 200mls qos queue-set output 1 buffers 15 25 40 20mls qos!!spanning-tree mode pvstspanning-tree extend system-idauto qos srnd4!!!!vlan internal allocation policy ascending!ip ssh version 2!!interface FastEthernet0 no ip address!interface GigabitEthernet1/0/1 switchport trunk encapsulation dot1q switchport mode trunk srr-queue bandwidth share 1 30 35 5 queue-set 2 priority-queue out mls qos trust dscp macro description cisco-router auto qos trust spanning-tree portfast trunk spanning-tree bpduguard enable!interface GigabitEthernet1/0/2 switchport access vlan 2 switchport mode access switchport port-security switchport port-security aging time 2 switchport port-security violation restrict switchport port-security aging type inactivity macro description cisco-desktop spanning-tree portfast spanning-tree bpduguard enable!interface GigabitEthernet1/0/3 switchport access vlan 3 switchport mode access switchport port-security switchport port-security aging time 2 switchport port-security violation restrict switchport port-security aging type inactivity macro description cisco-desktop spanning-tree portfast spanning-tree bpduguard enable!interface GigabitEthernet1/0/4 switchport access vlan 4 switchport mode access switchport port-security switchport port-security aging time 2 switchport port-security violation restrict switchport port-security aging type inactivity macro description cisco-desktop spanning-tree portfast spanning-tree bpduguard enable!interface GigabitEthernet1/0/5 switchport access vlan 5 switchport mode access switchport port-security switchport port-security aging time 2 switchport port-security violation restrict switchport port-security aging type inactivity macro description cisco-desktop spanning-tree portfast spanning-tree bpduguard enable!interface GigabitEthernet1/0/6 switchport trunk encapsulation dot1q switchport trunk native vlan 7 switchport mode trunk switchport nonegotiate srr-queue bandwidth share 1 30 35 5 queue-set 2 priority-queue out mls qos trust cos macro description cisco-wireless auto qos trust spanning-tree bpduguard enable!interface GigabitEthernet1/0/7!interface GigabitEthernet1/0/8!interface GigabitEthernet1/0/9!interface GigabitEthernet1/0/10!interface GigabitEthernet1/0/11!interface GigabitEthernet1/0/12!interface GigabitEthernet1/0/13!interface GigabitEthernet1/0/14!interface GigabitEthernet1/0/15!interface GigabitEthernet1/0/16!interface GigabitEthernet1/0/17!interface GigabitEthernet1/0/18!interface GigabitEthernet1/0/19!interface GigabitEthernet1/0/20!interface GigabitEthernet1/0/21!interface GigabitEthernet1/0/22!interface GigabitEthernet1/0/23!interface GigabitEthernet1/0/24!interface GigabitEthernet1/1/1!interface GigabitEthernet1/1/2!interface GigabitEthernet1/1/3!interface GigabitEthernet1/1/4!interface TenGigabitEthernet1/1/1!interface TenGigabitEthernet1/1/2!interface Vlan1 ip address 10.0.0.2 255.255.255.0!ip default-gateway 10.0.0.1ip classlessip http serverip http secure-server!ip sla enable reaction-alerts!!line con 0line vty 0 4 password REDACTED login length 0line vty 5 15 password REDACTED login length 0!end