<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Received ARP response collision from in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/received-arp-response-collision-from/m-p/1348159#M743228</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;KS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.  It's not actually a host.  It is an SVI on an access switch.  My capture however, doesn't show return traffic&lt;/P&gt;&lt;P&gt;2. another problem has cropped up...i can no longer see the traffic making it through the firewall...I'll have to figure that out before I can move forward ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bruce Summers&lt;/P&gt;&lt;P&gt;DHS OCIO&lt;/P&gt;&lt;P&gt;Network Engineering&lt;/P&gt;&lt;P&gt;bruce.summers@associates.dhs.gov&lt;/P&gt;&lt;P&gt;bb:  202-503-7628&lt;/P&gt;&lt;P&gt;desk: 228-813-4838&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 21 Feb 2010 23:46:20 GMT</pubDate>
    <dc:creator>Bruce Summers</dc:creator>
    <dc:date>2010-02-21T23:46:20Z</dc:date>
    <item>
      <title>Received ARP response collision from</title>
      <link>https://community.cisco.com/t5/network-security/received-arp-response-collision-from/m-p/1348155#M743176</link>
      <description>&lt;P&gt;I'm trying to work out this issue...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;source, switchA =&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.0.4&lt;/P&gt;&lt;P&gt;FW1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; =&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.0.1&lt;/P&gt;&lt;P&gt;FW1_Transit =&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.4.1&lt;/P&gt;&lt;P&gt;FW2_Transit =&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.4.7&lt;/P&gt;&lt;P&gt;FW1_VLAN =&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.12.0 /25&lt;/P&gt;&lt;P&gt;destination, SwitchB = 192.168.12.10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I setup a capture to watch the traffic and see it all the way onto the destination VLAN (192.168.12.0/25).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, I dont see the traffic coming back&amp;nbsp; on this VLAN Interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I setup a policy NAT as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list PNAT-3612 extended permit ip any 192.168.12.0 255.255.255.128&lt;BR /&gt;global (TD_3Tier_HQ_App_NLB) 1 interface&lt;BR /&gt;nat (TD_3Tier_Web_2_App) 1 access-list PNAT-3612 outside&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which appears to cause the traffic to come back on that interface, BUT, I dont see it hit the ACL, and the log output shows the following error:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Received ARP response collision from 192.168.12.10/8843.e17f.9041 on interface TD_3Tier_HQ_App_NLB (this being the name of the vlan interface)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this implying a duplicate IP somewhere?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bruce&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:12:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/received-arp-response-collision-from/m-p/1348155#M743176</guid>
      <dc:creator>Bruce Summers</dc:creator>
      <dc:date>2019-03-11T17:12:56Z</dc:date>
    </item>
    <item>
      <title>Re: Received ARP response collision from</title>
      <link>https://community.cisco.com/t5/network-security/received-arp-response-collision-from/m-p/1348156#M743188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ooops....Sorry folks...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I typed all that out, it got me to thinking...possibly I do have a duplicate...checked another switch, and there it was...duplicate IP...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bruce&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Feb 2010 19:59:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/received-arp-response-collision-from/m-p/1348156#M743188</guid>
      <dc:creator>Bruce Summers</dc:creator>
      <dc:date>2010-02-21T19:59:38Z</dc:date>
    </item>
    <item>
      <title>Re: Received ARP response collision from</title>
      <link>https://community.cisco.com/t5/network-security/received-arp-response-collision-from/m-p/1348157#M743193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;well,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;that got rid of the duplicate ip and error, but i'm still not seeing the traffic hitting that return interface...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thought the P NAT would take care of that...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bruce&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Feb 2010 20:01:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/received-arp-response-collision-from/m-p/1348157#M743193</guid>
      <dc:creator>Bruce Summers</dc:creator>
      <dc:date>2010-02-21T20:01:53Z</dc:date>
    </item>
    <item>
      <title>Re: Received ARP response collision from</title>
      <link>https://community.cisco.com/t5/network-security/received-arp-response-collision-from/m-p/1348158#M743212</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bruce,&lt;/P&gt;&lt;P&gt;If the response traffic isn't coming back you need to check the following.&lt;/P&gt;&lt;P&gt;1. capture on the desination host and make sure it is responding and make sure it is sending the response to the correct mac address.&lt;/P&gt;&lt;P&gt;2. Make sure the destination host has a route to get back to the source host network. If you need to check it's default gateway you need to do make sure that GW has a route back to the source network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Feb 2010 21:43:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/received-arp-response-collision-from/m-p/1348158#M743212</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-02-21T21:43:21Z</dc:date>
    </item>
    <item>
      <title>Re: Received ARP response collision from</title>
      <link>https://community.cisco.com/t5/network-security/received-arp-response-collision-from/m-p/1348159#M743228</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;KS,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.  It's not actually a host.  It is an SVI on an access switch.  My capture however, doesn't show return traffic&lt;/P&gt;&lt;P&gt;2. another problem has cropped up...i can no longer see the traffic making it through the firewall...I'll have to figure that out before I can move forward ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bruce Summers&lt;/P&gt;&lt;P&gt;DHS OCIO&lt;/P&gt;&lt;P&gt;Network Engineering&lt;/P&gt;&lt;P&gt;bruce.summers@associates.dhs.gov&lt;/P&gt;&lt;P&gt;bb:  202-503-7628&lt;/P&gt;&lt;P&gt;desk: 228-813-4838&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 Feb 2010 23:46:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/received-arp-response-collision-from/m-p/1348159#M743228</guid>
      <dc:creator>Bruce Summers</dc:creator>
      <dc:date>2010-02-21T23:46:20Z</dc:date>
    </item>
  </channel>
</rss>

