Cisco C3650 causes "crit - arp req detected an IP conflict" alerts on Juniper Netscreen Firewall.

Hi All,
I am posting this issue on the Cisco community site, I've also posted it in the J-net discussion forums.
I have three Netscreen-25 firewalls on my LAN. Two are configured as a NSRP pair/cluster and the thrid is a standalone firewall. All firewalls were running ScreenOS 5.4.0r27.0 (Firewall+VPN) and they work/worked perfectly, though a few weeks ago I noticed that all the netscreen firewalls were logging critical errors:
One FW shows this - logged every 30 seconds
crit - arp req detected an IP conflict (IP 10.2.26.242, MAC 88f0310dba31) on interface ethernet1
Other FW shows this - logged every 30 seconds
arp req detected an IP conflict (IP 10.30.235.242, MAC 88f0310dba31) on interface ethernet2
Both show the same MAC.
Now I don't appear to have any problems with network services, but the these log entries are causing concern.
I have a 100% switched cisco network. I was able to track the MAC address down to a new Cisco C3650 48 port switch which i recently installed. As soon as I disconnect the switch, the critical alerts stop. As soon as I plug the C3650 switch back into the network the alerts start coming in. I have not configured this new C3650 in any special way, I have configured it in the same as all my other Cisco switches. If I plug a Cisco 3560, or 2960 (basically any other cisco switch i got) I do not get the alerts on the Netscreen FW's.
I have upgraded the software on my cisco switch to the latest version (IOS XE 03.03.04SE) and have upgraded one of my Netscreen firewalls to ScreenOS 5.4.0r28a.0 (Firewall+VPN) - the latest version. But still the critical "arp req detected an IP conflict" alerts are coming in every 30 seconds.
It's got to be something to do with the new Cisco 3650 - though I don't know what it could be. On the networking side of things everything seems to be working OK.
Please can anybody advise as what the problem might be?
Thanks in advance.

Hi All,
I have updated my post on the juniper forum, so will update this thread too with the same information...
Firstly thanks for your replies. I have RSTP enabled on all my switches. These new Cisco C3650 series switches are connected to the exsiting switches (in a fibre ring) using a SFP modules /fibre patch leads.
In the current setup I cannot see how there could be a layer 2 loop because the 3650 is connected via a single physical link, whether that be using a SFP module/fibre patch lead or a single gigabit ethernet port directly connected using a cat5e patch lead into another gigabit ethernet port. So in both cases only 1 link/path exists.
On the netscreen-25 the critical error reports the MAC address of the connected/trunk link port on the Cisco 3650:
"arp req detected an IP conflict (IP 10.2.26.242, MAC 88f0310df431) on interface ethernet1"
On the cisco this is the:
xxxxxxx-hh1-cat15#sh interfaces gigabitEthernet 1/1/1
GigabitEthernet1/1/1 is up, line protocol is up (connected)
  Hardware is Gigabit Ethernet, address is 88f0.310d.f431 (bia 88f0.310d.f431)
  MTU 1500 bytes, BW 1000000 Kbit/sec, DLY 10 usec,
     reliability 255/255, txload 1/255, rxload 1/255
  Encapsulation ARPA, loopback not set
  Keepalive not set
  Full-duplex, 1000Mb/s, link type is auto, media type is 1000BaseSX SFP
  input flow-control is off, output flow-control is unsupported
  ARP type: ARPA, ARP Timeout 04:00:00
  Last input 00:00:00, output never, output hang never
  Last clearing of "show interface" counters never
  Input queue: 0/2000/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 16000 bits/sec, 25 packets/sec
  5 minute output rate 6000 bits/sec, 9 packets/sec
     350837 packets input, 29807313 bytes, 0 no buffer
     Received 234182 broadcasts (156724 multicasts)
     0 runts, 0 giants, 0 throttles
     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
     0 watchdog, 156724 multicast, 0 pause input
     0 input packets with dribble condition detected
     119555 packets output, 9923683 bytes, 0 underruns
     0 output errors, 0 collisions, 1 interface resets
     12154 unknown protocol drops
     0 babbles, 0 late collision, 0 deferred
     0 lost carrier, 0 no carrier, 0 pause output
     0 output buffer failures, 0 output buffers swapped out
xxxxxx-hh1-cat15#
And second Cisco 3650 also triggers a similar alert:
on the Netscreen-25
"arp req detected an IP conflict (IP 10.2.26.242, MAC 88f0310dba31) on interface ethernet1"
On the Cisco 3650:
xxxxx-hh1-cat14#sh interfaces gigabitEthernet 1/1/1
GigabitEthernet1/1/1 is up, line protocol is up (connected)
  Hardware is Gigabit Ethernet, address is 88f0.310d.ba31 (bia 88f0.310d.ba31)
  MTU 1500 bytes, BW 1000000 Kbit/sec, DLY 10 usec,
     reliability 255/255, txload 1/255, rxload 1/255
  Encapsulation ARPA, loopback not set
  Keepalive not set
  Full-duplex, 1000Mb/s, link type is auto, media type is 1000BaseSX SFP
  input flow-control is off, output flow-control is unsupported
  ARP type: ARPA, ARP Timeout 04:00:00
  Last input 00:00:00, output never, output hang never
  Last clearing of "show interface" counters never
  Input queue: 0/2000/0/0 (size/max/drops/flushes); Total output drops: 0
  Queueing strategy: fifo
  Output queue: 0/40 (size/max)
  5 minute input rate 1596000 bits/sec, 156 packets/sec
  5 minute output rate 83000 bits/sec, 77 packets/sec
     5236243 packets input, 4667733334 bytes, 0 no buffer
     Received 1400163 broadcasts (930724 multicasts)
     0 runts, 0 giants, 0 throttles
     0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored
     0 watchdog, 930724 multicast, 0 pause input
     0 input packets with dribble condition detected
     2353505 packets output, 204910425 bytes, 0 underruns
     0 output errors, 0 collisions, 1 interface resets
     75948 unknown protocol drops
     0 babbles, 0 late collision, 0 deferred
     0 lost carrier, 0 no carrier, 0 pause output
     0 output buffer failures, 0 output buffers swapped out
xxxxxx-hh1-cat14#
As per above if I change the uplink port on the Cisco 3650, all that happens is the MAC address reported on the Netscreen changes to show the MAC of the new physically connected port.
If I connect the switches redundantly, the STP recalculates and as expected some ports go into the BLK states. But in the end the Netscreen will still report the MAC addresses of the active/FWD'ing trunk link ports. As I have two Cisco 3650's I get alerts for two MAC addresses.
I must stress that if I replace any of the new Cisco 3650 with the older Cisco 3560, 3560v2, 2960 series switches (connected in exactly the same way) I do NOT get any alerts. I only get alerts when i plug in the Cisco C3650.
So something definitely to do with new switches, but I can't see what it can be?
If I can provide anymore info that you need please let me know..
Regards

Similar Messages

  • Configuring Cisco ACS 5.1 with Juniper Netscreen Firewall wit Radius & Tacacs+

    Hello,
    Can anybody tell me the step-by-step configuration of Cisco ACS 5.1, to configured it with Juniper Netscreen Firewall for radius & tacacs+ authentication and authorization?
    I am able to configure this with Cisco ACS 4.2 with customise VSA file but can't understand how to configure it on ACS 5.1.
    Thanks in Advance.

    Hi Eduardo,
    Can you tell me how to map ACS 4.2?
    service=junos-exec
    local-user-name=Engineering
    Into the new "shell profiles" on ACS 5.2? How do I verify these attributes are passed onto ACS 5.2? I don't have access to a sniffer or tap nor do I have writes on this box. I have to instruct our systems folks to investigate. It has been a back and forth battle.
    Also, I'd like to see where I'd map this on ACS 5.2.  Keep in mind in both cases I have a JUNOS config mapping to a login user Engineer and operations respectively.
    local-user-name=opertions
    allow-commands=((^ping *)|(^mtrace *)|(^traceroute *)|(^monitor *))
    deny-commands= ((^start *)|(^file delete *)|(^file rename *)|(^request *)|(^set cli restart-on-upgrade *)|(^set cli prompt *)|(^set chassis *)|(^set date *)|(^test *)|(^clear *)|(^op *))

  • Can ios 5.0.1 (9A406) install on my ipad 1, (9A405) causing no sim card detectted

    can ios 5.0.1 (9A406) install on my ipad 1, (9A405) causing no sim card detectted.............
    HELP ME

    thanks' for ur help... but it didn't work.  i have tried to re-restore the software with ipsw ext. still no sim card.......... and funny, it happen since the first update 9A405 released. i updated my ipad 1 since.
    now i use my ipad1 just for playing games....... can't playing internet since 2 months ago.........  

  • Registry edit Apple requires is causing windows to not detect files on the DVD drive

    Registry edit Apple requires is causing windows to not detect files on the DVD drive. If I set up the registry it requires then the files will not be dected & if I do it the way windows requires then the files will be detected but ITunes will not be able to use the optical drive. Is there any kind of patch or something someone can help me with?
    Thanks O'Bie

    To fix registry, refer to this article:
    iTunes for Windows: "Registry settings" warning when opening iTunes
    http://support.apple.com/kb/TS3299

  • "Logic has detected a possible conflict "" -- HELP!

    The full error message is, "Logic has detected a possible conflict between one or more third party MIDI or audio drivers. Be sure to install the latest drivers for all audio and MIDI equipment connected to your computer, and remove any older or unused drivers."
    OK, where exactly on my mac do these older or unused drivers live???

    I've looked through some old threads on this issue and some seem to have been produced by track automation, which wouldn't be causing my issue as none of my tracks have automation.
    Everything has worked perfectly up until just today; the only thing that changed was I installed the 3.0.1 version of Guitar Rig 3. I thought it might have something to do with the driver for Rig Kontrol hardware, so I deleted and reinstalled... Same Conflict message. So I force-quit Logic and opened a track that was all software instruements -- same problem.
    Can anyone help me? I am desperate here!!!

  • GarageBand has detected a possible conflict between one or more third party

    I have 200 computers that when you launch GarageBand 3.0.5 it comes up with the error:
    GarageBand has detected a possible conflict between one or more third party MIDI or audio drivers
    Our image is basically 10.5.6 with mainly Adobe CS 3 suite. No other sound programs or anything sound or video related was installed besides iLife 06 and I'm not sure what is causing the issue. I have tried reinstalling iLife 06 and run all updates available from Apple and repairing permissions. I have went through the plugins in /Library/Audio folder and haven't had any luck at all.
    What gets me is under the admin account I have it working fine by removing the default emagic plugin in /Library/Audio/ etc.. but if I log in as a regular user without admin privileges i get the error.
    I have tried deleting pref files in the users Preferences folder, but I just can't find a workaround.
    It kinda seems to be like a permissions issue since the Admin account works, but I have tried pushing permissions 777 to /Library/Application Support/ and to /Library/Audio and to /Applications/Garageband.app and still no results.
    I was blaming an Apple update because things worked fine before, I'm not sure what caused it. I reinstalled the combo update and that didn't help either.
    I reformatted and installed 10.5 and upgraded using the combo updater to 10.5.6 and installed iLife 06 and installed all available updates from Apple like I have in the image and things work fine.
    But I need to get this working on our image.........Anyone have any ideas as to what could possible be the issue and might know a fix????
    Google searches the solutions I have found are repairing permissions and deleting plugins. I have tried repairing permissions and have no plugins besides the defaults, but I have already removed the emagic one and nothing else is in there.
    Thanks!!

    To get me through the year I deleted a bunch of Microsoft Office Receipts in /Library/Receipts and it fixed the issue.
    I have no idea why, deleting a receipt from another app shouldn't affect anything, but it worked. I spent many hours trying to figure out a solution and this worked!
    We are running iLife 09 now and no issues so far!

  • " LogicPro has detected a possible conflict error "

    Hi All,
    I know this has been flagged before as a known issue but I cant see a specific answer based on my set up.
    Error message :
    " LogicPro has detected a possible conflict between one or more third party midi or audio drivers "
    Background :
    I have two macs, a macbook pro and a mac pro. On my macbook pro ( older system ) I have both Logic 7 & Logic Studio, On my macpro I only have Logic Studio.
    I had a completed track on Logic 7, when trying to open in logic 8 I got the mentioned error, But when I copied the track to my new mac pro system i got the same error again, the mac pro is a recent buy and a fresh install.
    Can some one please advise on how to resolve this issue, do i need to remove all automation data from the original copy within logic 7 then transfer across ?
    Really keen to sort out as planning to wipe my macbook pro and re-start from scratch when snow-leopard is released
    Hope someone can advise
    Cheers
    Andy

    I guess I'd search for all drivers, and see what comes up. Delete al that aren't Core audio, and make sure I have the current M-Audio driver for your device and re-install it. Just a guess, really...

  • Detect / Resolve Conflicts: Automatically detect and resolve conflicts

    Hi
    From documentation:http://technet.oracle.com/products/oracle9i/daily/jun05.html
    " Detect / Resolve Conflicts: Automatically detect and resolve conflicts "
    I know that the detection of the conflicts between versions is automatic, but I didn't know that the resolution was also automatic.
    So Can you tell me, please, in which cases the resolution of conflicts is automatic?
    thank you in advance
    (sorry for the previous message)

    Just to follow up on Arun's reply: The Workspace Manager manual has the correct information (i.e., conflicts are detected automatically, but must be resolved manually). The error is just in the OTN document that you refer to.

  • "garageband has detected a possible conflict..."

    I see that this problem has come up a lot in the past but none of the solutions I've found have worked so far. I'm working on fixing garageband for the computers in my high school's music tech lab and this is the error message I'm getting:
    "garageband has detected a possible conflict between one or more third party MIDI or audio drivers"
    I've tried deleting the "com.apple.garageband.plist" file in Library/Preferences/, but to no avail.
    I've also looked for drivers in: Library/Audio/Midi Drivers but we are using the M-Audio Keystation 61es (http://www.m-audio.com/products/en_us/Keystation61es.html) which doesn't require drivers, so there is nothing in that folder...
    There are at least 2 computers in the lab that are having this issue. GB works in the "Teacher" admin account but not in "Student", so I'm running a Permissions Repair in disk utility for one of the computers right now. The rest of them work in "Student".
    In the meantime, is there anything I have overlooked...? Would like to have this issue dealt with by later today or tomorrow... thanks! here's some info:
    Mac OS X version 10.5.8
    Model: iMac
    MIDI: M-Audio Keystation 61es
    The only other things plugged into the computer are headphones and a mouse/keyboard.

    Thanks for the suggestion. I had been looking in student/library/. I went to Macintosh HD/library, took the com.apple.garageband.plist file and the EmagicUSBDriver.plugin and threw them both into a temp file on the desktop. Opened up garageband and the issue is still present... I'll restart and see what happens, would deleting the files completely make any difference then having them in a different folder?
    Otherwise would the permissions repair work? I'm hoping we don't have to end up reformatting these computers...
    Thanks for the quick response!

  • Netscreen firewall authentication by Cisco ACS

    Since Netscreen firewall only supports RADIUS authentication, is Cisco ACS server able to support it? If yes, which version and where can I find more info about it?

    If it supports RADIUS then ACS should be able to support it.
    I belive the latest version of ACS is V6.33, you can download a trial version from this site.
    All the information you require should be here:
    http://www.cisco.com/en/US/products/sw/secursw/ps2086/index.html
    HTH
    PJD

  • Logic Pro *8 has detected a possible conflict between one or more...

    NOTE: This has NOTHING to do with opening Logic 7 sessions in Logic 8. This warning repeatedly pops up when starting Logic Pro 8, and when opening new sessions, and when adding tracks...and it's just unbeatable.
    Logic Pro has detected a possible conflict between one or more third party MIDI or audio drivers.
    I only suppose this could be either the Oxygen 8, or Digidesign 002 drivers? But Im certain that I do NOT use the 002 drivers.
    Anyone know about this? I only started seeing this problem after upgrading to both Leopard, and Logic Pro 8.
    Could my dongle be the problem? Hehe, I still have that plugged in from Logic 6!
    Ouch, this problem is so persistent I'm going to go back to Logic Pro 7.

    hi.
    Having just experienced this problem, I tried reinstalling the pace InterLok Extensions but this did not help. I then uninstalled the extensions (using the uninstaller script provided by pace) and now everything works. I need pace for some software i own so this is not a permanent solution for me...
    (I experienced this problem using logic 7.2.3 on OSX 10.4.11)
    Message was edited by: damien lock

  • DHCP Reservation problems caused by ARP proxy?

    We have been having recurring problems at three of our new school sites with printer IP addresses. We have created the address reservations in our DHCP servers (Windows Server 2012) but several times per week, the address shows up as a "BAD ADDRESS" in the DHCP leases and the printer never does get a good lease until we recreate the reservation and power cycle the printer. This is happening across several different printer models.
    Because this is only happening at our new sites, I've been investigating possible reasons. The configurations are mostly identical at our new sites and old; we have 3750X's at the old sites and 3850's (and one school with 4500X's) at the new sites. We have the correct IP helpers on every VLAN - one for each of our DHCP servers and one for each ISE node. ISE doesn't respond to the DHCP requests, it only listens for them to profile the endpoints. I've also begun enforcing ISE at one of the sites to see if it was just related to IP conflicts - no luck so far.
    Today I was fixing a printer reservation and came across something interesting. At one of the new schools, the MDF ARP table reported that 10.24.12.20 was assigned to a workstation (it is supposed to be assigned to a printer).  When I ran a check on the port in the IDF associated with that IP address to find the IP that was associated with the device, the device had an IP of 10.24.12.26. This caused me to start looking for ARP problems.
    I went looking for a difference in the configs on the 3850's and the 4500X's compared to the 3750X's at the older sites. Here's what I found when I did a "sh run all":
    4500X:
    ip arp poll queue 1000
    ip arp poll rate 1000
    no ip arp proxy disable
    ip arp gleaning tftp
    ip arp gleaning udp
    ip arp incomplete retry 20
    ip arp incomplete entries 5000
    ip arp incomplete enable
    ip arp inspection log-buffer entries 32
    ip arp inspection log-buffer logs 5 interval 1
    ip sticky-arp
    no ip gratuitous-arps
    The 3750X only has the following ARP commands:
    ip sticky-arpno ip gratuitous-arps
    ip arp inspection log-buffer entries 32ip arp inspection log-buffer logs 5 interval 1
    I was looking in particular at the "no ip arp proxy disable" on the 4500 and 3850's. I'm wondering if the newer switches are working as ARP proxies and causing problems with the printers. It doesn't seem that the 3750X's or older are doing this, or even have the commands. I am headed down the wrong path here? What are the repercussions of disabling the arp proxy on the newer switches to test it?
    Thanks

    Hi,
    if you have proxy arp then you should see multiple IP mapped to same MAC( the one from the device with proxy arp enabled), is this the case ?
    Regards
    Alain
    Don't forget to rate helpful posts.

  • Cisco Nexus 1000V - DMZ - ARP

    Hi there,
    Thanks for reading.
    I have a VM (VM1) connected to a Nexus 1000V distributed switch. The 1000V has a connection to our DMZ (physically, an interface on our Cisco ASA 5520) which has 3 other VMs that are successfully serving up in the DMZ. The problem is that a SHOW ARP run on the ASA shows the other VM's MAC addresses but not VM1.
    The vSphere properties for all VMs (including VM1) participating in the DMZ are the same:
    Network label
    VLAN ID
    Port Group
    State - Link Up
    DirectPath I/O - Inactive "Direct Path I/O has been explicitly disabled for this port"
    The one major difference between VM1 and the others is they are multihomed and have a foot in our private network space. I think the absence of a private IP on VM1 is not the source of the problem. All the VMs recognized as directly connected to the ASA (except VM1).
    Have you ever seen this kind of thing before?
    Thanks again for reading!
    Bob

    FYI: we solved this problem on the VM side.  We removed the network object with VMWare and recreated it.  Once that delete-recreate was complete, I saw the VM1 mac in the firewall.

  • Cisco Valet Connector refuses to be detected by windows

    I have bought Three of these products and all three do the same thing. I plug it in, run the setup and the setup never finishes, I can leave it up for hours and it refuses to do ANYTHING. I have talked with Live Chat and have downloaded the drivers, tried to update them manually, tried to install them using the cisco connect setup software and it tells me it cannot install and that i need to call customer service. IVE DONE THAT ALREADY AND THEY TOLD ME TO BUY ANOTHER ONE. I will refuse to buy another cisco product if we cant figure this out. 
    Device manager wants to install it as a (Disk Drive) and NOTHING ELSE. I have manually installed the drivers for the product but it tells me the hardware doesnt respond. and if i try to update them manuall it says the drivers i am trying to install aren't for the product i am installing them for and it closes out. WHAT THE HECK IS THE PROBLEM WITH THIS THING!? Why does it continue to want to be a usb thumb drive when it's supposed to be a network adapter?!?!?!?!?!??!?!?!?!?!
    OS: Windows 7 Ultimate 64 Bit
    Drivers used: Ones with product, v3.0.10.0 from website
    HELP ME OR I WILL NEVER ALLOW A CISCO OR LINKSYS PRODUCT AGAIN

    I have seen the similar problem with Valet connector and resolved by formatting the storage device.
    Try  this link and see if that works.

  • Cisco 2112 WALN Controller unable to detect Aironet 1252

    I'm new to this.
    Got new Aironet 1252 and trying to hook up to 2112 Controller. There are already two existing WAPs linked to the controller but the new one is not showing up. I need step-by-step instructions how to get it working as I'm not sure where to start
    I attached the config of the aironet
    Please assist

    Hi,
    The AP is in Autononous mode.. so it will not work with the WLC till we convert itto LWAPP or CAPWAP... Please download the latest capwap / LWAPP image from the below link for1252 AP ( image = c1250-rcvk9w8-tar.124-21a.JA2.tar                                                                                                                                                                                                                               )
    http://www.cisco.com/cisco/software/release.html?mdfid=281235915&flowid=6779&softwareid=280775090&release=12.4%2821a%29JA2&rellifecycle=&relind=AVAILABLE&reltype=latest
    and then get the TFTPd32 on your laptop and install it.. make sure the AP and the laptop ethernet interface are in the same subnet and try pinging the AP bvi inte IP from your LAptop.. if we are able to then..
    Point the image on the tftp server by going to the right directory.. then issue the belkow command ..
    ap#archive download-sw /force-reload /overwrite tftp:///image.tar
    ex
    Assuming 10.10.10.1 is ur tftp server.. change accordingly..
    ap#archive download-sw /force-reload /overwrite tftp://10.10.10.1/c1250-rcvk9w8-tar.124-21a.JA2.tar
    This will reload and come up with LWAPP image and the AP will join the WLC and thne you need to configure on the WLC to get this up based on your requirements...
    lemme know if this answered your question..
    Regards
    Surendra
    ====
    Please dont forget to rate the posts which answered your question and mark it as answered or was helpfull

Maybe you are looking for

  • A boolean that does not seem to work in an ifstatement

    hey guys im really new to Java so please forgive my ignorance. i am coding a program that is about vistors to a museum. I have a boolean in an if statement that is meant to work like this.. If numberOfVisitors = 10 then it should set the boolean to t

  • Why can't I transfer my movies to my devices?

    Why can't I transfer my movies from my iTunes library to my devices?  Some movies transfer and some don't.  All bought on iTunes!

  • CSS vertical-align problem

    I cant figure out why the valign isnt working on my page.. http://www.v4.skiingbc.info/pages/skiarea2.php?Name=Test1212&TrailMaps=X&FS=√&LP=√ CSS Sheet: http://v4.skiingbc.info/v4.css I want all text to be middle aligned in the table cells... If some

  • CIF 168 error .. Data in apo is correct

    Hi All,    I am getting the CIF 168 error:- Status of order in R/3 on General tab of Co03 :-   Total Quantity: 946   Delivered Quantity: 685 In rrp3 view in APO:    there is the production order with receipt quantity 261 Error Details:- =============

  • Sharing variable across Threads created by ThreadFactory

    Hi, I am initializing an ExecutorService as: static ExecutorService service = Executors.newFixedThreadPool(16, new ThreadFactory() { @Override public Thread newThread(Runnable r) { Thread t = new Thread(r); t.setContextClassLoader("<<My_Class_Loader"