<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IDSM with inline pairs causing mac move in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/idsm-with-inline-pairs-causing-mac-move/m-p/1764904#M56350</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I´ve just added the IDSM-2 blades on a 6500 and configured it but it did not work as I planned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This picture is a little scale what I tried to do, actually I had more vlans on the inspection.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 cores and a portchannel trunk in between them and for redundancy I´m using HSRP as the config shows.&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/4/9/6/57694-Core.JPG" alt="Core.JPG" class="jive-image-thumbnail jive-image" width="450" /&gt;&lt;/P&gt;&lt;P&gt;After I congfigured I´ve got these msgs and I could not figure out how to stop it: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Core1&lt;/P&gt;&lt;P&gt;%MAC_MOVE-SP-4-NOTIF: Host 001a.a2e4.e800 in vlan 6 is flapping between port Gi6/d1 and port Po1&lt;/P&gt;&lt;P&gt; %MAC_MOVE-SP-4-NOTIF: Host 001a.a2e4.e800 in vlan 7 is flapping between port Gi6/d1 and port Po1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAC 001a.a2e4.e800 is from Core2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Core2&lt;/P&gt;&lt;P&gt;%MAC_MOVE-SP-4-NOTIF: Host 0022.557b.c340 in vlan 6 is flapping between port&amp;nbsp; and port Po1&lt;/P&gt;&lt;P&gt;%MAC_MOVE-SP-4-NOTIF: Host 0022.557b.c340 in vlan 7 is flapping between port Po1 and port &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mac 0022.557b.c340 is from Core1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There was only one VLAN pair that did not have this problem, which was the VLAN L2 for the ISP router and the VLAN Outside for the FWSM . It also was the only VLAN that did not have HSRP working, I dont know if it has something to do. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Core 1 is the STP Root with priority of Zero and the Core 2 is the Backup Root with priority 4096&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any guesses ? &lt;/P&gt;</description>
    <pubDate>Sun, 10 Mar 2019 12:27:40 GMT</pubDate>
    <dc:creator>Rodrigo Gurriti</dc:creator>
    <dc:date>2019-03-10T12:27:40Z</dc:date>
    <item>
      <title>IDSM with inline pairs causing mac move</title>
      <link>https://community.cisco.com/t5/network-security/idsm-with-inline-pairs-causing-mac-move/m-p/1764904#M56350</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I´ve just added the IDSM-2 blades on a 6500 and configured it but it did not work as I planned.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This picture is a little scale what I tried to do, actually I had more vlans on the inspection.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have 2 cores and a portchannel trunk in between them and for redundancy I´m using HSRP as the config shows.&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/4/9/6/57694-Core.JPG" alt="Core.JPG" class="jive-image-thumbnail jive-image" width="450" /&gt;&lt;/P&gt;&lt;P&gt;After I congfigured I´ve got these msgs and I could not figure out how to stop it: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Core1&lt;/P&gt;&lt;P&gt;%MAC_MOVE-SP-4-NOTIF: Host 001a.a2e4.e800 in vlan 6 is flapping between port Gi6/d1 and port Po1&lt;/P&gt;&lt;P&gt; %MAC_MOVE-SP-4-NOTIF: Host 001a.a2e4.e800 in vlan 7 is flapping between port Gi6/d1 and port Po1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;MAC 001a.a2e4.e800 is from Core2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Core2&lt;/P&gt;&lt;P&gt;%MAC_MOVE-SP-4-NOTIF: Host 0022.557b.c340 in vlan 6 is flapping between port&amp;nbsp; and port Po1&lt;/P&gt;&lt;P&gt;%MAC_MOVE-SP-4-NOTIF: Host 0022.557b.c340 in vlan 7 is flapping between port Po1 and port &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mac 0022.557b.c340 is from Core1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There was only one VLAN pair that did not have this problem, which was the VLAN L2 for the ISP router and the VLAN Outside for the FWSM . It also was the only VLAN that did not have HSRP working, I dont know if it has something to do. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Core 1 is the STP Root with priority of Zero and the Core 2 is the Backup Root with priority 4096&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any guesses ? &lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 12:27:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-with-inline-pairs-causing-mac-move/m-p/1764904#M56350</guid>
      <dc:creator>Rodrigo Gurriti</dc:creator>
      <dc:date>2019-03-10T12:27:40Z</dc:date>
    </item>
    <item>
      <title>IDSM with inline pairs causing mac move</title>
      <link>https://community.cisco.com/t5/network-security/idsm-with-inline-pairs-causing-mac-move/m-p/1764905#M56351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see this log message frequently when using a switch to feed an IPS sensor if the same Ethernet frame is entering the same VLAN on two different interfaces. I can;t tell how your traffic is flowing but I think you have the same issue.&lt;/P&gt;&lt;P&gt;In my case it was not anything to worry about so I just ignored the messages.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Bob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 30 Aug 2011 21:18:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/idsm-with-inline-pairs-causing-mac-move/m-p/1764905#M56351</guid>
      <dc:creator>rhermes</dc:creator>
      <dc:date>2011-08-30T21:18:41Z</dc:date>
    </item>
  </channel>
</rss>

