AB Stratix 5700 configuration problem

nightline

Member
Join Date
Feb 2010
Location
Prinsenbeek
Posts
425
Gents,

I'm working on a new machine which has about 50 local EthernetIP addresses in use including PLC, 2 HMI's, 16 axis Kinetix 5700 servo rack, 9 PF527 vfd's, MAB guardlocking including pushbuttons, 3 PointIO stations, 4 Cognex Vision camera's etc.
All these addresses are in the 192.168.1.X range and connected to a 20 port Stratix 5700 full software managed switch.
The public address range is 10.10.10.X for example.
I've one default VLAN which has address 192.168.1.80.
The switch has also address 192.168.1.80 and is in IO tree of the PLC.

In the NAT table I've configured single rules for the PLC and HMI's and the switch, so these should be accessible from outside.

I also configured a gateway rule 192.168.1.1 to 10.10.10.1

The PLC is connected to switch port G1/2 and the public network is connected to switch port G1/1.

In the NAT table I can mark the VLAN 1 for both G1 ports.
If I mark one of these ports for VLAN 1, I loose all connections with the PLC, but I can reach the PLC from outside.
If I don't mark these VLAN 1, I can't reach the PLC from outside.

Can anyone point me what I have to do to get this working?

The PLC, HMI's and Switch should be accessible from the public network without loosing connection with all local addresses.

It's probably something simple or stupid, but it breaks my head!

I hope that any of you can shine a light on this.
Thanks in advance!

Jack
 
This may not be the problem, but what's your PLC & what's the number of connections to it over EtherNet? I've had older PLCs (L32Es) display the same behavior as they can only take 8 EIP connections. Once you remote into it, it would lose all other comms.

Also, please post your NAT config table for both private & public sides. I'm not entirely following everything you have configured.
 
The PLC is a ControlLogix L82SE.
I'm not sure about the amount of connections, and I'm unable to check right now.
But during the configuration of the whole system, we did a calculation on this.

I'll try to upload the image of the NAT config.
 
The PLC is a ControlLogix L82SE.
I'm not sure about the amount of connections, and I'm unable to check right now.
But during the configuration of the whole system, we did a calculation on this.

I'll try to upload the image of the NAT config.

Ah, the PLC is definitely not the problem here; the L82SE will handle those without any issue.
 
I've no idea how to insert an image as it asks for an URL...

So there is a tab for general (private to public) where I created the following rules:
private 192.168.1.121 > public 10.10.10.243 ( HMI-1 ) Type = Single
private 192.168.1.120 > public 10.10.10.242 ( HMI-2 ) Type = Single
private 192.168.1.80 > public 10.10.10.241 ( Switch )Type = Single
private 192.168.1.9 > Public 10.10.10.240 ( PLC ) Type = Single

On the right side of this Tab is a box where you can mark the VLAN for both th G1 ports.

There is also a tab Public to Private where I created the same rules.
 
How many vlan to you need?
And dont your gateway rule be 10.10.10.1 TO 192.168.1.1 ?

You are right on this, the gateway rule is 10.10.10.1 to 192.168.1.1

I've no idea how many VLAN's I need, the switch creates one native VLAN during the first setup.

I tried a second VLAN without IP address for all local addresses, and made the port setting for the PLC port to accessible to all VLAN's. But this didn't solve the problem.
 
Is your uplink port to the public range setup as an access port or a trunk port?

What VLAN is your public range on? (This needs to match the VLAN your private range sits on)
 
Is your uplink port to the public range setup as an access port or a trunk port?

What VLAN is your public range on? (This needs to match the VLAN your private range sits on)

In the VLAN settings I can only set one IP address.
This VLAN is configured by the switch during setup.
During this setup it got 192.168.1.80 which is also the private address of the switch.

In the NAT table the address 192.168.1.80 got rules to 10.10.10.241.
 
Do you think that I should create a second VLAN with the IP address 10.10.10.241 which is the public address of the switch and connect this to G1/1?

And connect VLAN 1 to all other ports?
 
Unless I am missing something in your description, the NAT should be applied to Gi1/1 configuration only.
Gi1/2 left as a regular port with Automation Device Smart pot macro applied.
Gi1/2 should be part of VLAN 1

Gi1/1 should be set for Switch for automation that automatically makes it as a trunk make sure you specify Native VLAN to match you upstream settings.
If your upstream switch is using a different native VLAN then this needs to be addressed on your switch by creating that VLAN.

Saying this, what is VLAN number for the rest of your "10.10..." network? it must match VLAN of your "10.10.." network.

It would help if you post you config file and network diagram showing all you VLANs.
 

Similar Topics

Hi Guys, I have two redundant Controllogix CPUs also connected to two redundant Stratix 5700 Managed switches. With mere Express Setup of the...
Replies
3
Views
452
Hey guys so I have this switch previously set up by someone else so the ip/gateway/subnet is all put into the switch - port 1 is set up to send...
Replies
2
Views
3,633
Hello, We decided use Gi1/Gi2 ports for connecting switches Daisy Chain. Standard ports we are using for connecting other devices. Situation...
Replies
7
Views
3,602
I'm having a terrible time configuring the NAT. This is exactly the same issue that many others have appeared to have. I've read everything I...
Replies
18
Views
13,474
I got one of the Stratix 5700 w/ NAT switches (1783-BMS10CGN) and cannot get NAT to function. I followed the NAT quickstart guide from the...
Replies
15
Views
20,065
Back
Top Bottom