Gratuitous ARP ????

HI,
Have a simple doubt, Will cisco switch send gratuitous arp if HSRP not enabled ???? in which conditions a cisco switch\router\firewall send gratuitous ARP ???

There are some threads regarding that, take a look at this one.
https://learningnetwork.cisco.com/thread/16335

Similar Messages

  • Gratuitous ARPs do not populate the router ARP Table

    Hello,
    In order to debug an ARP problem in a Firewall cluster environment, I connected a one-armed router on the public VLAN of the firewall cluster, in order to observe the ARP cache behaviour during a switchover. I configured a loopback interface on this router and  a default route to this loopback interface to simulate a real router.
    When a switchover occurs between firewall cluster members, the active member sends Gratuitous ARPs for all NATed IP addresses. In my environment, I have 110 NATed addresses configured on the firewall.
    By launching a "debug arp" on the one armed router,  I clearly see all 110 gratuitous ARPs arriving on the router, but the ARP cache of the router is NOT populated with the 110 entries...
    Note  : The command is configured on the one armed router :
    Router(config)# ip arp gratuitous local
    What can be the problem ? Is there any condition for a router to accept Gratuitous ARPs ?
    Thank you for any help
    Yves

    Hi
    Gratuitous arp is used when a host wants to inform the switch that the mac-address has changed eg.
    You have a cluster which has redundant connections and an IP to mac-address mapping. If the active NIC fails the IP address is moved across to the standby NIC but the standby NIC has a different mac-address. So the cluster sends out a gratuitous arp which informs the switch of the new IP to mac-address mapping.
    The reason you might not want to allow gratuitous arp is that you might not want your switch updating it's arp table based on annoucements from devices on the LAN as you could very easily spoof mac-addresses and corrupt the arp cache.
    HTH
    Jon

  • Question about "no ip gratuitous-arp" command in IOS

    Does the "no ip gratuitous-arp" command affect gratuitous arps sent by the router (for example, when hsrp causes a secondary router to assume role of primary) or does it affect gratuitous arps received by the router (for example, gratuitous arps with the spoofed IP address of the router).

    I do not have direct experience with this command. But I think that the documentation is clear that the command restricts the router sending gratuitous arp and does not affect the router receiving gratiutous arp.
    The documentation is fairly clear that its restriction on gratiutous arp is a restriction on sending gratiutous arp when a remote client has learned an IP address via PPP negotiation and the address is in a local address pool. Assuming that this part of the documentation is accurate it would have no affect on the router sending gratiutous arp in HSRP takeover situations.
    HTH
    Rick

  • No gratuitous arp N1k when second subgroup comes up again

    Hello,
    we have an Nexus 1000v with PortChannel to no clustered upstream Switches.
    Port-Profile Configuration:
    config attributes:
      switchport mode trunk
      switchport trunk allowed vlan 2,6-7,64,150,607,630
      switchport trunk native vlan 1
      channel-group auto mode on sub-group cdp
      no shutdown
    If one Link goes down, the VM of this Link will change to the second Link. During this change i see a maximum of one lost Packet in the Ping to this VM.
    If the first Link still comes up, I see something that I don't understand.
    After 6-7 seconds I have 6-7 Packets lost in the Ping to the VM that changes the Link.
    The MAC of the VM will change from one Link to the other in the MAC-Address-Table on the Upstream Switches after this time.
    In the Documentation I read only about gratuitous arps, when the link fails.
    How can I reduce the Packet lost?

    I have one link from each host to each upstream switch in this port channel.
    This is a test system with two ESX-Hosts and two upstream switches (C2960G).
    Here the Configuration of the upstream switch Ports:
    interface GigabitEthernet0/2
    description esx-netz1_1
    switchport trunk allowed vlan 2,6,7,64,150,607,630
    switchport mode trunk
    spanning-tree portfast trunk
    spanning-tree bpdufilter enable
    spanning-tree bpduguard enable
    In every Host I have four PNICs. Two for the channel, one for vMotion and one for the service console.

  • Gratuitous ARP in Nexus 7000

    We are in the process of migrating our servers from Cat6500 (HSRPv1) to Nexus 7000 (HSRPv2). The HSRP virtual ip address remains the same after the migration. During the migration, we will shut down the Layer3 interface vlan on the Cat6500 and create the new Layer 3 interface vlan on the N7K. Because we are migrating to HSRPv2, the HSRP virtual MAC address will change.  Would like to check if there is there any way for the N7K to send gratuitous ARP to all the servers so that their ARP cache are refreshed. does "ip arp gratuitous update" help ?  THanks Eng Wee

    Hi Eng Wee,
    Nexus sends gratuitous arp by default. This command is enabled on the interface by default. There is nothing special that you need to do for the switch to send the gratuitous arps.
    JayaKrishna

  • Gratuitous arp problem

    When cisco 2851 mgcp gateway lost connection to the call manager, it will start sending out gratuitous arp which cause the McAfee intrushield reports arp spoofing. Anyone know why the gateway send out gratuitous arp?

    Sorry for the delay. here is the debug mgcp all on that router.
    192.168.10.50 is the CCM.

  • DHCP conflict due to Gratuitous ARP.

    One of my wireless VLAN DHCP scope on cisco core switch is often exhausted due to Gratuitous ARP.
    Please help me to check what is the cause of this.

    I have a VLAN with DHCP SCOPE and layer 3 configured on core switch.
    the DHCP pool often gets exhausted and when I do show ip dhcp conflict most of the IPs conflicted due to Gratuitous arp
    CORESWITCH#   show ip dhcp conflict  
    172.28.106.195    Gratuitous ARP     Oct 14 2014 04:44 PM                                    
    172.28.106.54     Gratuitous ARP     Oct 14 2014 04:49 PM                                    
    172.28.106.189    Gratuitous ARP     Oct 15 2014 12:28 PM                                    
    172.28.106.55     Gratuitous ARP     Oct 17 2014 02:05 PM                                    
    172.28.106.74     Gratuitous ARP     Oct 21 2014 09:39 AM                                    
    172.28.106.72     Gratuitous ARP     Oct 23 2014 02:26 PM                                    
    172.28.106.89     Gratuitous ARP     Oct 28 2014 03:09 PM                                    
    172.28.106.119    Gratuitous ARP     Nov 03 2014 01:39 PM                                    
    172.28.106.124    Gratuitous ARP     Nov 05 2014 08:03 AM                                    
    172.28.106.127    Gratuitous ARP     Nov 05 2014 02:56 PM                                    
    172.28.106.131    Gratuitous ARP     Nov 08 2014 01:59 PM                                    
    172.28.106.153    Gratuitous ARP     Nov 10 2014 12:14 PM                                    
    172.28.106.139    Gratuitous ARP     Nov 11 2014 07:57 AM                                    
    172.28.106.143    Gratuitous ARP     Nov 11 2014 09:28 AM                                    
    172.28.106.157    Gratuitous ARP     Nov 11 2014 02:36 PM                                    
    172.28.106.156    Gratuitous ARP     Nov 11 2014 07:55 PM                                    
    172.28.106.162    Gratuitous ARP     Nov 13 2014 06:48 PM                                    
    172.28.106.187    Gratuitous ARP     Nov 18 2014 01:57 PM                                    
    172.28.106.176    Gratuitous ARP     Nov 19 2014 02:30 PM                                    
    172.28.106.53     Gratuitous ARP     Nov 19 2014 02:47 PM                                    
    172.28.106.199    Gratuitous ARP     Nov 20 2014 11:18 AM                                    
    172.28.106.61     Gratuitous ARP     Nov 20 2014 01:27 PM                                    
    172.28.106.56     Gratuitous ARP     Nov 20 2014 01:39 PM                                    
    172.28.106.63     Gratuitous ARP     Nov 21 2014 02:15 PM                                    
    172.28.106.85     Gratuitous ARP     Nov 24 2014 07:17 PM                                    
    172.28.106.92     Gratuitous ARP     Nov 25 2014 10:47 AM                                    
    172.28.106.95     Gratuitous ARP     Nov 25 2014 02:14 PM                                    
    172.28.106.97     Gratuitous ARP     Nov 27 2014 04:19 PM                                    
    172.28.106.100    Gratuitous ARP     Nov 28 2014 09:18 AM                                    
    172.28.106.79     Gratuitous ARP     Nov 28 2014 11:09 AM                                    
    172.28.106.104    Gratuitous ARP     Nov 28 2014 05:20 PM                                    
    172.28.106.129    Gratuitous ARP     Dec 01 2014 09:53 AM                                    
    172.28.106.130    Gratuitous ARP     Dec 01 2014 11:19 AM                                    
    172.28.106.133    Gratuitous ARP     Dec 01 2014 11:36 AM                                    
    172.28.106.134    Gratuitous ARP     Dec 01 2014 03:04 PM                                    
    172.28.106.135    Gratuitous ARP     Dec 01 2014 03:47 PM                                    
    172.28.106.136    Gratuitous ARP     Dec 01 2014 04:13 PM                                    
    172.28.106.137    Gratuitous ARP     Dec 02 2014 12:28 PM                                    
    172.28.106.141    Gratuitous ARP     Dec 03 2014 09:33 AM                                    
    172.28.106.149    Gratuitous ARP     Dec 05 2014 02:01 PM                                    
    172.28.106.151    Gratuitous ARP     Dec 05 2014 04:21 PM                                    
    172.28.106.173    Gratuitous ARP     Dec 08 2014 06:40 PM                                    
    172.28.106.182    Gratuitous ARP     Dec 09 2014 09:28 AM                                    
    172.28.106.158    Gratuitous ARP     Dec 09 2014 04:46 PM                                    
    172.28.106.185    Gratuitous ARP     Dec 09 2014 05:05 PM                                    
    172.28.106.188    Gratuitous ARP     Dec 10 2014 02:56 PM                                    
    172.28.106.186    Gratuitous ARP     Dec 10 2014 06:19 PM                                    
    172.28.106.193    Gratuitous ARP     Dec 12 2014 12:48 PM                                    
    172.28.106.75     Gratuitous ARP     Dec 16 2014 02:37 PM                                    
    172.28.106.68     Gratuitous ARP     Dec 16 2014 04:05 PM                                    
    172.28.106.80     Gratuitous ARP     Dec 16 2014 06:02 PM                                    
    172.28.106.81     Gratuitous ARP     Dec 17 2014 03:11 PM                                    
    172.28.106.84     Gratuitous ARP     Dec 19 2014 02:03 PM                                    
    172.28.106.115    Gratuitous ARP     Dec 23 2014 10:35 AM                                    
    172.28.106.78     Gratuitous ARP     Dec 23 2014 01:37 PM                                    
    172.28.106.121    Gratuitous ARP     Dec 24 2014 06:18 PM                                    
    172.28.106.125    Gratuitous ARP     Dec 26 2014 10:02 AM                                    
    172.28.106.161    Gratuitous ARP     Dec 29 2014 12:01 PM                                    
    172.28.106.181    Gratuitous ARP     Dec 29 2014 03:08 PM                                    
    172.28.106.184    Gratuitous ARP     Dec 30 2014 05:25 PM                                    
    172.28.106.66     Gratuitous ARP     Jan 02 2015 09:44 AM                                    
    172.28.106.194    Gratuitous ARP     Jan 03 2015 03:14 PM                                    
    172.28.106.106    Gratuitous ARP     Jan 07 2015 01:54 PM                                    
    172.28.106.112    Gratuitous ARP     Jan 07 2015 04:32 PM                                    
    172.28.106.113    Gratuitous ARP     Jan 08 2015 04:48 PM                                    
    172.28.106.103    Gratuitous ARP     Jan 09 2015 12:53 PM                                    
    172.28.106.164    Gratuitous ARP     Jan 13 2015 12:13 PM                                    
    172.28.106.155    Gratuitous ARP     Jan 13 2015 03:54 PM                                    
    172.28.106.168    Gratuitous ARP     Jan 13 2015 05:12 PM                                    
    172.28.106.169    Gratuitous ARP     Jan 14 2015 05:07 PM                                    
    172.28.106.170    Gratuitous ARP     Jan 14 2015 05:50 PM                                    
    172.28.106.197    Gratuitous ARP     Jan 16 2015 06:18 PM                                    
    172.28.106.60     Gratuitous ARP     Jan 19 2015 07:56 AM                                    
    172.28.106.88     Gratuitous ARP     Jan 19 2015 05:17 PM                                    
    172.28.106.94     Gratuitous ARP     Jan 20 2015 12:46 PM                                    
    172.28.106.101    Gratuitous ARP     Jan 21 2015 10:15 AM                                    
    172.28.106.102    Gratuitous ARP     Jan 21 2015 02:08 PM                                    
    172.28.106.147    Gratuitous ARP     Jan 28 2015 11:04 AM                                    
    172.28.106.159    Gratuitous ARP     Jan 28 2015 12:37 PM                                    
    172.28.106.128    Gratuitous ARP     Jan 28 2015 02:27 PM                                    
    172.28.106.165    Gratuitous ARP     Jan 29 2015 12:31 PM                                    
    172.28.106.166    Gratuitous ARP     Jan 30 2015 07:40 AM                                    
    172.28.106.178    Gratuitous ARP     Jan 30 2015 02:20 PM                                    
    172.28.106.183    Gratuitous ARP     Jan 30 2015 02:39 PM                                    
    172.28.106.69     Gratuitous ARP     Feb 02 2015 09:40 AM                                    
    172.28.106.76     Gratuitous ARP     Feb 02 2015 07:18 PM                                    
    172.28.106.91     Gratuitous ARP     Feb 02 2015 08:17 PM                                    
    172.28.106.93     Gratuitous ARP     Feb 02 2015 08:20 PM                                    
    172.28.106.200    Gratuitous ARP     Feb 04 2015 01:41 PM                                    
    172.28.106.96     Gratuitous ARP     Feb 05 2015 09:57 AM                                    
    172.28.106.111    Gratuitous ARP     Feb 05 2015 01:42 PM                                    
    172.28.106.108    Gratuitous ARP     Feb 06 2015 08:04 AM                                    
    172.28.106.122    Gratuitous ARP     Feb 09 2015 05:11 PM                                    
    172.28.106.174    Gratuitous ARP     Feb 11 2015 06:17 PM                                    
    172.28.106.179    Gratuitous ARP     Feb 12 2015 06:18 PM                                    
    172.28.106.83     Gratuitous ARP     Feb 16 2015 03:56 PM

  • Unknown router granted dynamic ARP, now what?

    I have discovered that the Cisco ASA5505 we are using for a firewall is granting a dynamic arp to an SMC router on the outside interface which has access to the internet. The IP address is not that of the single IP granted for the outside interface to the internet, but it is in the range under the net mask (8 addresses).
    I tried using a non-MAC exempt rule in the AAA section to block this, but this doesn't seem to be a good solution.
    Is the router coming in from the outside?  Has the outside interface been breached?  Apparently the ASA5505 doesn't think the router is violating an access rules.
    The dynamic ARP appeared over the week end, when the normal equipment was shut down, but the firewall left running.  Too bad the ARP table doesn't time stamp when this occurred.
    The unknown router has the same MAC address that was found during the middle of last week.  This appearance just started at the middle of last week.
    I do not know what router this is, so I now have concern.
    What steps should I take to track this down?  (I am not an experienced seasoned security IP person)

    Dear PK:
    I did some reading on my own regarding "Gratuitous ARP" and understand that now, but am having problems discovering how the ASA5505 learned the ARP, since apparently the "show mac" command is not available under the ASA 5505 software (I am using the CLI window)
    The available show commands are "show arp" and "show IP" which is close but doesn't give me what I need.
    It could be that the connection on the other end of my dedicated IP (1 address) is changing or stopping and starting and then sending the Grat arp, as this seems most reasonable, but I would like to confirm that this is so.
    It also doesn't help that last week Columbia University in New York scanned our block of addresses and attempted to sit upon both the http and telnet ports.  Their laboratory is set up to scan banks of IP numbers and find misconfigured routers or security appliances.
    Randall

  • ARP detstination mac-address 0000.0000.0000

    Internet Router--->3550 Switch-->Nortel Contivity
    63.169.164.134-->63.169.164.140--> 63.169.140.136
    All the devices are having public IP addresses and are in Vlan 100.
    Sometimes the Internet Router is not able to ping or connect to the Contivity where as the switch is able to access both the devices (Internet Rtr & Contivity).
    While checking on the switch & Internet rtr i capture the following logs.
    Switch#sh log
    Mar 25 11:17:17.990 EDT: IP ARP: creating incomplete entry for IP address: 63.169.164.136 interface Vlan100
    Mar 25 11:17:17.990 EDT: IP ARP: sent req src 63.169.164.140 0012.800b.a780,dst 63.169.164.136 0000.0000.0000 Vlan100
    Internet RTR#sh log
    Mar 25 11:17:17 EDT: IP ARP: rcvd req src 63.169.164.140 0012.800b.a780, dst 63.169.164.136 GigabitEthernet0/1
    Mar 25 11:20:54 EDT: IP ARP: rcvd req src 63.169.164.138 0018.b964.66fc, dst 63.169.164.145 GigabitEthernet0/1
    We have done a static ARPA entry in internet rtr for Contivity but still the issue remains same. The moment the issue persists again i tried to clear the arp on switch but it didn't make router to get reply from Contivity when i did the same clear arp-cache on internet rtr, it started getting communicate with Contivity.
    I am not able to find the solution of this issue and the reason for that, now every time i have to do clear ip arp-cache on rtr whenever the issue comes down.
    Also i want to understand the situation when a dest mac-address can be 0000.0000.0000.
    Any help on this will be appreciated.
    Thanks.

    Bhupesh
    If a router receives a packet to forward to a destination address which is on a local LAN but the destination IP address does not appear in the arp table then the router creates an incomplete entry in the ARP table (it is incomplete because the router does not have the destination MAC address and is attempting to learn it). The router creates the incomplete entry in the ARP table and sends an ARP request. If the router receives an ARP response then it puts the destination MAC address into the ARP table and the entry is now complete. If no ARP response is received the router will purge the incomplete entry. Note that the router can not forward the IP packet that caused the incomplete entry and the router will drop that IP packet.
    In considering the problem with contivity I had been assuming that the problem was on rtr. But it occurs to me that it is quite possible (and even likely given the fact that you mention which is that in the problem the switch can still ping contivity ) that the problem is on contivity. I wonder if for some reason contivity gets an incorrect MAC for rtr? I suspect that clear arp on rtr fixes the problem because as it clears the arp table I believe that rtr will send a gratuitous arp which refreshes the ARP entry in contivity. In the time of the problem can you check the table in contivity?
    HTH
    Rick

  • Box-to-box redundancy and ARP question

    In a box-to-box failover scenario are the MAC addresses of both active and standby CSS11503s supposed to match up? The reason I ask relates to an issue where without clearing the ARP cache on the Default GW (a PIX with a default ARP timeout of 240 minutes) all services were unreachable via the VIPs.

    the addresses are not the same but the CSS sends a gratuitous arp upon failover to advertise the new mac-address.
    Gilles.

  • DHCP Reservation problems caused by ARP proxy?

    We have been having recurring problems at three of our new school sites with printer IP addresses. We have created the address reservations in our DHCP servers (Windows Server 2012) but several times per week, the address shows up as a "BAD ADDRESS" in the DHCP leases and the printer never does get a good lease until we recreate the reservation and power cycle the printer. This is happening across several different printer models.
    Because this is only happening at our new sites, I've been investigating possible reasons. The configurations are mostly identical at our new sites and old; we have 3750X's at the old sites and 3850's (and one school with 4500X's) at the new sites. We have the correct IP helpers on every VLAN - one for each of our DHCP servers and one for each ISE node. ISE doesn't respond to the DHCP requests, it only listens for them to profile the endpoints. I've also begun enforcing ISE at one of the sites to see if it was just related to IP conflicts - no luck so far.
    Today I was fixing a printer reservation and came across something interesting. At one of the new schools, the MDF ARP table reported that 10.24.12.20 was assigned to a workstation (it is supposed to be assigned to a printer).  When I ran a check on the port in the IDF associated with that IP address to find the IP that was associated with the device, the device had an IP of 10.24.12.26. This caused me to start looking for ARP problems.
    I went looking for a difference in the configs on the 3850's and the 4500X's compared to the 3750X's at the older sites. Here's what I found when I did a "sh run all":
    4500X:
    ip arp poll queue 1000
    ip arp poll rate 1000
    no ip arp proxy disable
    ip arp gleaning tftp
    ip arp gleaning udp
    ip arp incomplete retry 20
    ip arp incomplete entries 5000
    ip arp incomplete enable
    ip arp inspection log-buffer entries 32
    ip arp inspection log-buffer logs 5 interval 1
    ip sticky-arp
    no ip gratuitous-arps
    The 3750X only has the following ARP commands:
    ip sticky-arpno ip gratuitous-arps
    ip arp inspection log-buffer entries 32ip arp inspection log-buffer logs 5 interval 1
    I was looking in particular at the "no ip arp proxy disable" on the 4500 and 3850's. I'm wondering if the newer switches are working as ARP proxies and causing problems with the printers. It doesn't seem that the 3750X's or older are doing this, or even have the commands. I am headed down the wrong path here? What are the repercussions of disabling the arp proxy on the newer switches to test it?
    Thanks

    Hi,
    if you have proxy arp then you should see multiple IP mapped to same MAC( the one from the device with proxy arp enabled), is this the case ?
    Regards
    Alain
    Don't forget to rate helpful posts.

  • Sh arp

    when given sh arp will it should show all the servers/machines arp resolution ?am able to see a few only wheras a lot are there..pls discuss..

    Devices on a LAN learn about other devices by one of three ways:
    1. They need to send a packet to that device for the first time.
    2. Another device sends an ARP request to them.
    3. Another device sends a gratuitous ARP.
    To answer your question, yes, it is possible (and maybe likely) that devices exist on a LAN without being and a particular devices ARP cache. (Layer two switches are a good example, as they rarely need layer 3 communication to devices other than their default gateway).

  • ARP TIMEOUT doesn't work

                           Hi All,
    I have devices which don’t send gratuitous arp when they plugged into a L3 switch. A problem occurs when one of this devices fails - and is replaced by another one (with another mac -- IP the same). The l3 switch doesn't update his ARP Table with the new mac and so the ping fails. When I clear the arp cache -> the arp table is updated by a new arp - request and the ping works.
    The next workaround was to modify the ARP TIMEOUT to 60 sec. So when is swap an failed device - this takes longer then 60 sec - I thought that the arp cache is cleared in the meanwhile for this interface BUT it wasn't
    How affect's the arp timeout - timer on the arp cache. I modified it many different values but the arp entry does not disappear??
    thx
    max

    I believe that you are confusing the arp table and the cam table. You are correct that the associated entries in the cam for an interface are purged if the switch interface goes down. And in my experience the entries in the arp table are purged if the interface on which they are learned goes down. But frequently the device doing the arp is the layer 3 router and not the switch to which the PC or server was connected. So the old PC is removed, the replacement PC is booted up and configured, and the entry in the arp table does not change.
    Max
    I am surprised to read your post. In my experience setting the arp timeout has been effective. Would it be possible for you to recreate the issue and to post some outputs of events during the test? In particular I would be interested to see the output of debug arp and the output of show ip interface for the interface where the test device is connected (to verify the arp setting).
    HTH
    Rick

  • How does ARP work on WAN port and on IP alias

    I have 10  public ip addresses  and I have only 1 WAN port . So I have created aliases on the WAN port of the  firewall . Then  I have forwarded the ports of all the public ips to internal machines . The questions I have 
    1. Will the alias broadcast mac address ?
    2.Will the WAN interface broadcast mac address ?
    3. How will the upstream device will know which IP has which mac ?
    4. What is the use of proxy arp in this scenario ?
    5. Does gratuitous arp play any role here .?
    Here is the setup
    ISP link Fibre Connection >ISP device >Switch >Firewall >LAN computers 
    Please let me know the arp flow over the wan and the working of IP alias . 

    Hi,
    APs on a different subnet then you have to
    1. configure DHCP option 43 on the APs subnet
    2. put in a DNS entry for CISCO-LWAPP-CONTROLLER.localdomain. 
    3. Use IP helper address on the Router
    Check step 4,5& 6 in Layer 3 LWAPP WLC Discovery Algorithm:
    http://www.cisco.com/c/en/us/support/docs/wireless-mobility/wireless-lan-wlan/70333-lap-registration.html
    Hope this helps you to understand.
    Regards
    Dont forget to rate helpful posts

  • Arp broadcasts & dhcpv6 sollicits & neighbour advertisements visible

    We have a setup with 5500 controller with a couple of SSID (2 WPA2 , 1 Open).
    The 'Controller - General - Broadcast Forwarding' option is set on disabled.
    DHCP proxy is enabled.
    Multicast is also disabled.
    P2P Blocking action is Drop.
    Issue1: Arp broadcasts
    When sniffing on the encrypted SSIDs we see ARP requests for the default gateway (received by DHCP) of the clients.
    The ARP requests are coming from clients located on different accesspoints.
    When we do this on the open SSID not a single ARP request is visible. Which is as far as I understand the way it should work because proxy arp is enabled by default.
    'The WLC acts as an ARP proxy for WLAN clients by maintaining the MAC address-IP address associations. This allows the WLC to block duplicate IP address and ARP spoofing attacks. The WLC does not allow direct ARP communication between WLAN clients. This also prevents ARP spoofing attacks directed at WLAN client devices.' from http://www.cisco.com/en/US/docs/solutions/Enterprise/Mobility/secwlandg20/ch4_2_SPMb.html#wp1307340
    Is this a bug or just something about WPA2 that I don't understand ?
    Issue2: Dhcpv6 sollicits & Neighbour Advertisements
    The same issue as the Arp broadcasts is also popping up with Dhcpv6 sollicits & Neighbour Advertisements, although this is the same for the WPA2 as for the Open SSID.
    We're seeing DHCPv6 sollicits (to ff02::1:2) from clients on different AP's when sniffing.
    We're seeing Neighbour Advertisements (icmpv6 to ff02::1) from clients on different AP's when sniffing.
    Why is this forwarded ? Shouldn't this be blocked by the controller ? Also a bug ?
    Thanks,
    Wim

    I'm not a fan of "me too" posts but I'll chime in with "me too" here anyway. Thanks for this thread: for the longest time I thought I was the only one seeing this issue! Before I found this I did a lot of searching and packet capture analysis and in an effort to help anyone else dealing with it, my findings are below.
    CSCub65575 seems to still be present in 7.2.111.3 based on packet captures I did yesterday. On another WiSM2 running 7.4.100.0 I noticed that gratuitous ARP traffic is still forwarded downstream to wireless clients. That is listed as a fixed version on CSCub65575 and I'm not sure if this is intentional or not but I figured it was worth mentioning.

Maybe you are looking for

  • Cannot install AA3 on Windows 7 Home Premium

    I run the Setup file, and right after I choose my language, a window flashes up and vanishes almost instantly and nothing else happens. Does anyone else have this problem and if so, how do I fix it? Thank you.

  • Windows storage server 2008 R2 ISO

    Hi All, from where I can download ISO image for Windows storage server 2008 R2 Standard?  The key is written on the sticker which is on the Server which is for windows server 2008 Storage r2.Please let me know can i use this key for windows server 20

  • What is "safaritools" and why does it want access to my account?

    I'm having Safari 4.0.3 crashes on PowerBook G4 running Tiger 10.4.11 -- like everyone else. But, I've also been getting this strange popup every now and then -- it looks like a regular Apple popup --- that asks for access to the account manager or k

  • Dynamic programming using cl_abap_typedescr

    I have created a field catalog for an ALV grid dynamically using cl_alv_table_create=>create_dynamic_table (I am on 46B and cannot use the new version).  How do I create the structure and therefore internal table to pass into the it_outtab parameter

  • Bluetooth Volume Control

    I have a iPhone 3GS 32GB with IPFW 3.1.2 (7D11) but i noticed that there is no option for volume control for bluetooth devices. I have a Sony Ericsson HBH-IS800 and they work great but the music is always so loud. I tried to use the volume limiter an