Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Passport 8600 duplicate arp request

Status
Not open for further replies.

ineagu

Technical User
Jun 24, 2004
4
CA
hello,
I have Passport 8600 that sends an arp broadcast even though an entry exists in its arp table. This PP "arps" every 15 sec and because it has 2100 entries this makes the CPU go to 100%
thanks for any help

Ilie Neagu
Bell canada
Montreal, Canada
 
Are you running SMLT? What's the image version? Try looking for layer-2 loop caused by misconfiguration on MLT/SMLT.
 
hello,
The software version is 3.3 (no upgrade plans yet). There is no SMLT maybe MLT I'd have to check. If there is a layer 2 loop I would imagine that the CPU would be at 100% all the time not just every 15 sec or so.
We re checking now to see if a management station would poll a lot of other devices that would generate these ARP.
But this doesn't explain why the Passport is sending an ARP broadcast while it has the IP address in its arp table already.
Thank you for your time
Ilie Neagu
 
Maybe virus causes broadcast storm or something like that. Btw I strongly suggest you to upgrade your version...I heard that now Nortel does not provide support if your version is too old.
 
I agree, upgrade the code and get away from 3.3 I recently had a problem where 2 passport 8600's connected via IST could not see all the networks etc in their ARP tables although all entries and routing tables were ok. I upgraded to 3.7 and all worked ok.
 
On the ERS8600: Disabling IP direct-broadcast
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
config vlan <VID> ip directed-broadcast disable
config ethernet <slot/port> ip directed-broadcast disable


It is on by default on the 8600's and image 15.4.0.0 on BCN routers.
 
hello,
Nortel investigated this problem and it was due to the fact that another switch on the network was sending Spannong Tree TCN every minute or so.
thanks all for your help

Ilie Neagu
 
From the BCN help:

Function: When this parameter is enabled, a packet addressed to an IP broadcast address goes to all systems on the target network. By default, directed broadcast is enabled.

Caution: Internet service providers have reported forged ICMP echo request packets sent to IP addresses (SMURF attacks), sometimes resulting in severe network congestion. To prevent these attacks, directed broadcast must be disabled.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top