<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ACE in bridged mode - ARP and Probes in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/cisco-ace-in-bridged-mode-arp-and-probes/m-p/2739850#M42899</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have ACE 30 module context in bridged mode.&lt;/P&gt;&lt;P&gt;Everything works fine, but the probes to the real server on the Standby are in a Failed state. After troubleshooting for a while, I have found, that this is somehow related to L2 and ARP responses.&lt;/P&gt;&lt;P&gt;- Routing on the client side is pointing to 10.126.120.1 (this is a HSRP IP where 10.126.120.2 and .3 are real IP addresses) - this is vlan 2750&lt;/P&gt;&lt;P&gt;- Routing on server side is pointing to 10.126.120.4 (this is a HSRP IP where 10.126.120.5 and .6 are real IP addresses) - this is vlan 2751&lt;/P&gt;&lt;P&gt;- On Active ACE module, I can ping all of the addresses, i.e. 10.126.120.1-6&lt;/P&gt;&lt;P&gt;- On Standby ACE module, I can ping only client side IP addresses, i.e. 10.126.120.1-3.&lt;/P&gt;&lt;P&gt;- On Standby ACE, I cannot ping server-side router interfaces, i.e. 10.126.120.4-6 and there is no entry in the ARP table for these IPs.&lt;/P&gt;&lt;P&gt;- Routers are able to ping Active ACE BVI interface IP address 10.126.120.10&lt;/P&gt;&lt;P&gt;- Routers are unable to ping Standby ACE BVI interface IP address 10.126.120.11&lt;/P&gt;&lt;P&gt;- Routers don't receive ARP for Standby ACE BVI IP address.&lt;/P&gt;&lt;P&gt;- When i manually trigger the ACE module failover, probes start working just fine on both ACE modules until ARP times out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this an expected behaviour?&lt;/P&gt;&lt;P&gt;Do you have an explanation about this behaviour?&lt;/P&gt;&lt;P&gt;From loadbalancing perspective, everything is working fine.&lt;/P&gt;&lt;P&gt;From the Probe perspective, I expect, that the probe on Standby ACE unit is using Standby BVI IP address 10.126.120.11, it is unable to get ARP for the corresponding server route and hence fails the probe.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here comes the relevant config and state from the Standby ACE module:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;0cc1-ace12/dclb# show arp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;Context dclb&lt;BR /&gt;================================================================================&lt;BR /&gt;IP ADDRESS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MAC-ADDRESS&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Interface&amp;nbsp; Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Encap&amp;nbsp; NextArp(s) Status&lt;BR /&gt;================================================================================&lt;BR /&gt;10.126.120.1&amp;nbsp;&amp;nbsp;&amp;nbsp; 00.00.0c.07.ac.01&amp;nbsp; vlan2750&amp;nbsp; GATEWAY&amp;nbsp;&amp;nbsp;&amp;nbsp; 39&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 182 sec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;10.126.120.2&amp;nbsp;&amp;nbsp;&amp;nbsp; e0.2f.6d.2c.23.c0&amp;nbsp; vlan2750&amp;nbsp; LEARNED&amp;nbsp;&amp;nbsp;&amp;nbsp; 37&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5961 sec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;10.126.120.3&amp;nbsp;&amp;nbsp;&amp;nbsp; e0.2f.6d.2c.23.80&amp;nbsp; vlan2750&amp;nbsp; LEARNED&amp;nbsp;&amp;nbsp;&amp;nbsp; 35&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5957 sec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;10.126.120.10&amp;nbsp;&amp;nbsp; e0.5f.b9.ab.8c.35&amp;nbsp; vlan2750&amp;nbsp; LEARNED&amp;nbsp;&amp;nbsp;&amp;nbsp; 40&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5955 sec&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;10.126.120.4&amp;nbsp;&amp;nbsp;&amp;nbsp; 00.00.00.00.00.00&amp;nbsp; bvi1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; GATEWAY&amp;nbsp;&amp;nbsp;&amp;nbsp; -&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; * 3 req&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dn&lt;BR /&gt;10.126.120.11&amp;nbsp;&amp;nbsp; e0.5f.b9.ab.8c.11&amp;nbsp; bvi1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; INTERFACE&amp;nbsp; LOCAL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; _&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up&lt;BR /&gt;================================================================================&lt;BR /&gt;Total arp entries 6&lt;BR /&gt;0cc1-ace12/dclb#&lt;BR /&gt;0cc1-ace12/dclb#&lt;BR /&gt;0cc1-ace12/dclb# show run interface&lt;BR /&gt;Generating configuration....&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;interface vlan 2750&lt;BR /&gt;&amp;nbsp; description &amp;gt;MSFC:dc&lt;BR /&gt;&amp;nbsp; bridge-group 1&lt;BR /&gt;&amp;nbsp; fragment min-mtu 28&lt;BR /&gt;&amp;nbsp; access-group input BPDU&lt;BR /&gt;&amp;nbsp; access-group input ACL&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;&amp;nbsp; ip route inject vlan 2750&lt;BR /&gt;interface vlan 2751&lt;BR /&gt;&amp;nbsp; description &amp;gt;MSFC:dclb&lt;BR /&gt;&amp;nbsp; bridge-group 1&lt;BR /&gt;&amp;nbsp; fragment min-mtu 28&lt;BR /&gt;&amp;nbsp; access-group input BPDU&lt;BR /&gt;&amp;nbsp; access-group input ACL&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;interface bvi 1&lt;BR /&gt;&amp;nbsp; ip address 10.126.120.11 255.255.255.224&lt;BR /&gt;&amp;nbsp; peer ip address 10.126.120.10 255.255.255.224&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Relevant router ARP table:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family:courier new,courier,monospace;"&gt;0cc1-s11#show ip arp vrf dclb 10.126.120.11&lt;BR /&gt;Protocol&amp;nbsp; Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Age (min)&amp;nbsp; Hardware Addr&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp; Interface&lt;BR /&gt;Internet&amp;nbsp; 10.126.120.11&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&amp;nbsp;&amp;nbsp; Incomplete&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ARPA&amp;nbsp; &amp;nbsp;&lt;BR /&gt;0cc1-s11#show ip arp vrf dclb 10.126.120.10&lt;BR /&gt;Protocol&amp;nbsp; Address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Age (min)&amp;nbsp; Hardware Addr&amp;nbsp;&amp;nbsp; Type&amp;nbsp;&amp;nbsp; Interface&lt;BR /&gt;Internet&amp;nbsp; 10.126.120.10&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp;&amp;nbsp; e05f.b9ab.8c35&amp;nbsp; ARPA&amp;nbsp;&amp;nbsp; Vlan2751&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Alexander&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Sep 2015 14:25:33 GMT</pubDate>
    <dc:creator>Alexander Pickar</dc:creator>
    <dc:date>2015-09-09T14:25:33Z</dc:date>
    <item>
      <title>Cisco ACE in bridged mode - ARP and Probes</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-in-bridged-mode-arp-and-probes/m-p/2739850#M42899</link>
      <description>Probes on ACE30 Standby module are in a failed state due to problems in ARP resolution.</description>
      <pubDate>Wed, 09 Sep 2015 14:25:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-in-bridged-mode-arp-and-probes/m-p/2739850#M42899</guid>
      <dc:creator>Alexander Pickar</dc:creator>
      <dc:date>2015-09-09T14:25:33Z</dc:date>
    </item>
    <item>
      <title>Please attach a diagram</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-in-bridged-mode-arp-and-probes/m-p/2739851#M42900</link>
      <description>&lt;P&gt;Please attach a diagram because&amp;nbsp;you might have some unnecessary elements or&amp;nbsp;I don't understand all the details well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A bridged HA-pair should interconnect two VLANs via two parallel paths.&amp;nbsp;A single broadcast domain and a single subnet&amp;nbsp;(10.126.120.0)&amp;nbsp;is formed. All hosts in this broadcast domain (both servers and clients) should have&amp;nbsp;the same&amp;nbsp;default gateway (either 10.126.120.1 or 10.126.120.4). Layer2 traffic within the broadcast domain should use the active links in the spanning tree.&amp;nbsp;Loop guard function should be disabled on the switchports (internal subinterfaces) towards the ACE. The two spanning tree instances (2750,2751) are combined into a merged spanning tree so the priorities should be tuned to fix which one&amp;nbsp;(which side)&amp;nbsp;is the root.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check the spanning tree port states on the links connecting towards the ACE.&lt;/P&gt;</description>
      <pubDate>Sat, 19 Sep 2015 17:02:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-in-bridged-mode-arp-and-probes/m-p/2739851#M42900</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2015-09-19T17:02:07Z</dc:date>
    </item>
  </channel>
</rss>

