Sup7L-E unicast flooding:ARP refreshes but MAC doesnot

I have two 4507 switches configured HSRP, 45-1 is the active gateway of vlan2. Last week we found vlan2 was sufferring unicast flooding which was explainded by case#8 at this link
http://www.cisco.com/c/en/us/support/docs/ip/hot-standby-router-protocol-hsrp/10583-62.html?referring_site=smartnavRD#t8. Then I changed the mac aging-time to 4 hours as the link suggests.
The problem seemed resolved. But after 20 hours, the problem reoccurred. I checked the ARP table and MAC table, the ARP entry of the IP address whitch caused the flooding updated 3 minutes ago. But there was no MAC entry for  the MAC address of this IP address!!! I pinged this IP address from 45-2 so the entry was established. After the weekend, I check the switches this morning, it reoccurred again.
In my opinion, the MAC entry must update as soon as the ARP entry updates,  then how could this happened again and again after the MAC aging-time was changed the same with ARP timeout?
Is there same case?Could anyone help?
The engines are SUP7L-E and the IOS is cat4500e-universalk9.SPA.03.04.00.SG.151-2.SG. TAC found no bugs by now.

I can't speak for other Cisco L3 devices at this point but the experience I am having shows that the ARP table entry is having the age reset to zero for every packet that passes through that MSFC destined for the host in question. When the table doesn't have an entry we can send a ping to that host from another host on a different VLAN. The MSFC will send an ARP request to which the destination host will reply. This will put an entry in the ARP table with an age of zero. It will also generally update the mac-address-table along the path we are concerned with. I can monitor the age of the ARP entry and before it ages out (4 hours by default) send another ping packet. At that point I can show the entry in the ARP table and it has reset the age back to zero.
In an HSRP configuration, if the standby HSRP MSFC is the one receiving the packet that is destined for the host he will refresh his ARP table entry from the ARP reply sent from the host and send the packet on its merry way. However, when the host replies to the packet itself he will send that packet to the active HSRP MSFC on the other switch and not to the standby HSRP MSFC. If you continue with the ping packets then the ARP table entry on the standby HSRP MSFC continuously gets reset to zero but the mac-address-table entry will eventually age out because that switch is never seeing any return traffic from the host.
I would agree with you that it should only reset with an ARP reply and I think that would be in accordance with RFC standards. That is not the behavior we are seeing however. We're continuing in the lab to test and observe to make sure we completely understand the behavior we are seeing but so far that seems to be the case.
Thanks,
Tyler

Similar Messages

  • Unicast Flooding on Nexus 5020 with ESXi 5 vMotion

    We recently began testing VMware ESXi 5.0 on our production network.  After observing some heavy discards (3-10 million at times) on the 10G uplinks FROM our core 6509s TO the Nexus 5Ks we began some investigation.  We started by capturing traffic on vPCs from the Nexus 5K to the 6509s.  We found a tremendous amount of unicast vMotion traffic transmitting from the 6509s to the Nexus 5Ks.  Unicast vMotion traffic should never touch the 6509s core switches since it is layer two traffic.  We found that our problem was two fold.  Problem number one was the fact that on the ESXi 5 test cluster we had vMotion and the management vm kernel nics in the same subnet.  This is a known issue in which ESXi replies back using the management virtual mac address instead of the vMotion virtual mac address.  Therefore the switch never learns the vMotion virtual mac address thus flooding all of the vMotion traffic.  We fixed problem number 1 by creating a new subnet for the vMotion vm kernel nics and we also created a new isolated vlan across the Nexus 5Ks that does not extend to the cores, modifying the vDistributed switch port group as necessary.  To verify that the vMotion traffic was no longer flooding we captured traffic locally on the N5K, not using SPAN but simply eves dropping on the vMotion VLAN as an access port.  The testing procedure involved watching the CAM table on the 5K, waiting for the vMotion mac addresses to age out then starting a vMotion from one host to another.  Doing this process we were able to consistently capture flooded vMotion traffic onto our spectator host doing the captures.  The difference from problem 1 was that the flooding did not include all of the vMotion conversation as before but when vMotioning 1-2 servers we saw anywhere from 10ms to 1 full second of flooding then it would stop.  The amount of flooding varied but greatly depended on whether the traffic traversed the vPC between the 5Ks or not.  We were able to make the flooding much worse by forcing the traffic across the vPC between the N5Ks.
    Has anyone else observed this behavior with N5Ks or VMware on another switching platform?
    We were able to eliminate the vMotion flooding by pinging both vMotion hosts before beginning the vMotion. It seems that if VMware would setup a ping to verify connectivity between the vMotion hosts before starting the vMotion it would eliminate the flooding.
    A brief description of the network..
    Two 6509 core switches with layer 2 down to two Nexus 5020 running NX-OS version 5.0(3)N2(2b) using 2232PP FEX for top-of-rack.  For testing purposes each ESXi host is dual-homed with one 10G link (CNA) to each N5K through the FEX.  VMware is using vDistributed switch with a test port-group defined for the ESXi 5 boxes.
    For curiosities sake we also observed packet captures from ESX 4.1 where we saw similar unicast flooding although it was near not as many packets as in ESXi 5.
    We have a case open with TAC and VMware to track down the issue but were curious if anyone else has observed similar behavior or had any thoughts.
    Thanks
    Cody

    Essentially the fix was to (a) turn off mac aging on the vmotion vlan on the 5K, (b) remove the L3 addressing from the vmotion vlan by not extending it to the 6K, and for good measure we (c) dedicated 2x10G ports per server just for multi-nic vmotion. These three measures did the trick.

  • Unicast Flood impact

    Hi All,
    I was interested in knowing the impact of unicast flooding in network. In a situation where the mac table entries timeout earlier than the arp cache entries and all traffic for those hosts are unicast flooded in that vlan, will this kind of unicast flood forwarding be handled by the ASIC or will it be punted to the CPU causing the CPU util to rise ?
    Thanks in Advance 
    Regards
    Umesh

    Disclaimer
    The Author of this posting offers the information contained within this posting without consideration and with the reader's understanding that there's no implied or expressed suitability or fitness for any purpose. Information provided is for informational purposes only and should not be construed as rendering professional advice of any kind. Usage of this posting's information is solely at reader's own risk.
    Liability Disclaimer
    In no event shall Author be liable for any damages whatsoever (including, without limitation, damages for loss of use, data or profit) arising out of the use or inability to use the posting's information even if Author has been advised of the possibility of such damage.
    Posting
    I believe the blocking will also be done in hardware.  One possible hardware performance issue that flooding might cause, the switch has to replicate the packet to multiple ports.  Depending on the switch architecture, this might cause some issues.
    For example, the original 3560/3750 series has a 32 Mbps fabric.  Suppose a one gig ingress stream enters one of a 3560G's gig ports.  If the stream is replicated to all the other ports, at ingress, just that one stream might create more than 40 Gbps of egress traffic that needs to transit the fabric.

  • MacBook 2006 w/Snow Leopard; HP B210 printer; print problem; error message: One or more components of the HP printing software are corrupted or missing. Reinstalled software but Mac will not cause printer to print.

    ? MacBook 2006 w/Snow Leopard; HP B210 printer; print problem; error message: "One or more components of the HP printing software are corrupted or missing..." Reinstalled software but Mac will not cause printer to print.  My MacBook Pro works fine with same wireless printer.

    Hi ArielAce , thanks for getting back to me!
    I would recommend downloading and running the HP Print and Scan Doctor.
    Please keep me posted!
    Please click “Accept as Solution " if you feel my post solved your issue, it will help others find the solution.
    Click the “Kudos, Thumbs Up" on the right to say “Thanks" for helping!
    Jamieson
    I work on behalf of HP
    "Remember, I'm pulling for you, we're all in this together!" - Red Green.

  • I have to upload video from my hewlett packard t200 camcorder to my mac. but mac won't recognize the camcorder files. i even bought flip4mac by tele stream which so far is useless. please help me use my camcorder with my iMac os mountain lion 10.8.2

    i have to upload video from my hewlett packard t200 camcorder to my mac. but mac won't recognize the camcorder files. i even bought flip4mac by tele stream which so far is useless. please help me use my camcorder with my iMac os mountain lion 10.8.2
    i tried to get the installation disc for the camcorder but mac wont' recognize it becaue it is windows based i guess.
    i just bought the camcorder a few months ago and when my computer crashed thought i'm finally getting a mac...it's been a costly venture which has resulted in more frustration than before my pc.
    now the things i want to use with my mac that i thought would be even simpler...are not even useable...
    help

    That camera shoots H.264 in an .avi wrapper.
    You will have to transfer the files via the Finder.
    Get a free copy of MPEG Streamclip and convert them to QuickTime .mov using the H.264 codec if you are presumably editing in iMovie.
    Note that your list of video codecs won't look like mine as I have Final Cut Pro, but H.264 is definitely an option for you.

  • Trouble with slow Macbook Air. I have first generation MacBook Air and have a hard time keeping hard drive from being full. Right now, I have almost 5 gigs available, but mac is slow and I keep getting color wheel when I use Mail. Any suggestions?

    Trouble with slow Macbook Air. I have first generation MacBook Air and have a hard time keeping hard drive from being full. After trashing many docs, I have almost 5 gigs available, but mac is slow and I keep getting color wheel when I use Mail. I'd like to install Lion, but now I'm afraid it will slow down my machine even further. Do I have enough free hard disc space? Is Mail problem related to free hard disc space? Thanks for your help!

    7gb of free disc space is required to install Lion.  Read this about how to free up disc space: http://pondini.org/OSX/DiskSpace.html.  Also, advice on how to speed up your mac: http://www.maclife.com/article/feature/25_ways_speed_your_mac

  • I am trying to use apple configurator with ipads. I have been successful with all our ipads but 1. It will not allow me to add apps. The error I get is that it is refreshed but with errors e

    I am trying to use apple configurator with ipads. I have been successful with preparing and supervising all ipads but one. When preparing it in configurator, I receive an error that it is refreshed but with an error. Under supervise, I am not able to add apps. I have erased all content to start over but this does not work either

    Are you trying to restore a backup, or just sync some apps? Do you have profiles installed on the device?
    Have you plugged the ipad into iTunes, and did a fresh install? I'm assuming the device went through the prepare setup properly. You many have to unsupervise it first, then plug it into iTunes to wipe it completely.
    I'd then do each step seperately. Prepare it, then install 1 app, if that works, try another app, then maybe a profile.

  • I want to install Windows but Mac showed message that related partition should be in NTFS format. In which way I could format windows partition.

    I want to installWindows but Mac showed message that related partition should be in NTFS format.In which way I could format windows partition.

    Go back and re-read the guide which is also part of and in the Apple Boot Camp Assistant.
    Boot Camp Installation Guide
    Boot Camp FAQ
    Windows 7 FAQ
    Apple - Support - Boot Camp

  • HT1338 i want to refresh my mac book i for got the password

    i want to refresh my mac book i for got the password

    Boot from your Leopard installation DVD, and use the menus to reset your password.
    NOTE:  I said your Leopard DVD, because you are posting to the Leopard forum.  If you are really using Mountain Lion, then you would boot via your Recovery partition (boot holding Command-R), then reset your password.
    Message was edited by: BobHarris

  • In windows cmd lueo used \ \ server and get to the pc but mac as done

    in windows cmd lueo used \ \ server
    and get to the pc but mac as done

    Your question (if it is one) makes no sense whatever.
    Please describe your problem in greater detail, and include details of what Mac you have and what version of OS X.

  • When is apple going to do something about this recent flood of spam to .mac

    when is apple going to do something about this recent flood of spam to .mac. i have had .mac for 4 years and in the last few months im getting like 10 junk mails a day. all for worthless investment tips. i came on here to find alot of others getting the same junk mail from the same sender. so it is obviously a target to .mac addresses and not just mine. come on apple, this has been happening for a few months now and is getting worse. are you going to do anyhthing about it on the server side of things? im paying over $100 for .mac and expect a fix. anybody else with this problem please please sound off here. we need a fix for this.

    yes, i agree. over 3 years with 3 .mac addresses and this is the first time i've had any sort of a problem... and it's becoming an onslaught.
    plus, not only is the mac filter not working, my mail 2.0.5 filter is not working. can someone let me know why these are not going into my junk folder? i think i've got it set up correctly as these are ticked:
    enable junk mail filtering
    move it to the junk mailbox (automatic)
    (exempt) sender in my address book
    (exempt) message is addressed using my full name
    trust junk mail headers set by my ISP
    can anyone from mac let us know that you are aware of the current problem and are at least looking into it?
    also, here's another recent thread:
    http://discussions.apple.com/thread.jspa?threadID=544461&tstart=45
      Mac OS X (10.1.x)  

  • Hi, I am trying to download the trial version of photoshop but it is stuck on 42% (has been for several hours). I have tried refreshing but it doesn't work. I am using Yosemite OS X.

    Hi, I am trying to download the trial version of photoshop but it is stuck on 42% (has been for several hours). I have tried refreshing but it doesn't work. I am using Yosemite OSX 10.10.3. Any suggestions?

    Re: creative cloud hangs at 42%

  • I am trying to reinstall mountain lion but Mac book pro failed to install.

    I am trying to reinstall mountain lion but Mac book pro failed to install

    Please detail ALL you have done so far in the way of troubleshooting?   Need this info to avoid the been there done that scenarios.
    Have you read for possible solutions over in the "More Like This" thread over here?----------------------->

  • Downloaded os x 5.16 GB and installation but mac shows beta version

    downloaded os x 5.16 GB and installation but mac shows beta version.
    HOW TO RECTIFY MY MAC OS.

    Miracle of all miracles, I can actually see the included image: Build = 14A299I

  • TS3276 the connec doctor sr but mac mail won't connect?

    How do you connect to gmail in mac mail when the connection doctor says the connection was successful to the server but mac mail won't connect even after re-inputting the password?

    mac mail won't connect to the Comcast POP or smpt servers
    So your saying that you have comcast at home and it works fine from this machine?
    If you mail works fine at home, then if it doesn't work on the road, it most likely isn't your machine.  It is some other problem:
    -- with the other network
    -- perhaps comcast is preventing foreign mail from working.
    Beth's experience & help
    http://home.comcast.net/~bethkatz/MacMailSetup.html
    You need to contact comcast.
    http://forums.comcast.com/
    http://customer.comcast.com/contact-us/

Maybe you are looking for