04-15-2012 11:57 PM
Hi,
I've configured two ACE appliances with redundance (fault-tolerance VLAN).
Since the following messages appears on ACE's :
Apr 15 2012 14:43:59 : %ACE-4-405001: Received ARP RESPONSE collision from 192.168.10.253 e8.9a.8f.b2.68.7a on interface vlan100
Apr 15 2012 14:44:03 : %ACE-4-405001: Received ARP RESPONSE collision from 192.168.10.253 e8.9a.8f.b2.68.7a on interface vlan100
Apr 15 2012 14:44:05 : %ACE-4-405001: Received ARP RESPONSE collision from 192.168.10.253 e8.9a.8f.b2.68.7a on interface vlan100
Apr 15 2012 14:44:07 : %ACE-4-405001: Received ARP RESPONSE collision from 192.168.10.253 e8.9a.8f.b2.68.7a on interface vlan100
Apr 15 2012 14:44:09 : %ACE-4-405001: Received ARP RESPONSE collision from 192.168.10.253 e8.9a.8f.b2.68.7a on interface vlan100
ACE1/GAAS# sh arp
Context GAAS
================================================================================
IP ADDRESS MAC-ADDRESS Interface Type Encap NextArp(s) Status
================================================================================
192.168.10.1 00.1f.9f.f1.a9.a1 vlan100 GATEWAY 10 43 sec up
192.168.10.246 e8.9a.8f.b2.68.80 vlan100 INTERFACE LOCAL _ up
192.168.10.250 e8.9a.8f.b2.68.80 vlan100 VSERVER LOCAL _ up
192.168.10.253 e8.9a.8f.b2.68.80 vlan100 NAT LOCAL _ up
================================================================================
ACE2/GAAS# sh arp
Context GAAS
================================================================================
IP ADDRESS MAC-ADDRESS Interface Type Encap NextArp(s) Status
================================================================================
192.168.10.1 00.1f.9f.f1.a9.a1 vlan100 GATEWAY 11 86 sec up
192.168.10.247 e8.9a.8f.b2.68.7a vlan100 INTERFACE LOCAL _ up
192.168.10.250 e8.9a.8f.b2.68.7a vlan100 VSERVER LOCAL _ up
192.168.10.253 e8.9a.8f.b2.68.7a vlan100 NAT LOCAL _ up
================================================================================
Total arp entries 4
Has someone an Idea?
Thanks in advance
04-16-2012 12:56 AM
Can you show us the config of the admin context ?
Have you allocated mac address pools with different numbers ?
shared-vlan-hostid / peer shared-vlan-hostid
04-16-2012 01:00 AM
sure, here's the admin context configuration :
ACE1/Admin# sh run
Generating configuration....
logging enable
logging buffered 4
logging queue 2000
boot system image:c4710ace-t1k9-mz.A5_1_2.bin
hostname ACE1
interface gigabitEthernet 1/1
shutdown
interface gigabitEthernet 1/2
switchport access vlan 100
no shutdown
interface gigabitEthernet 1/3
shutdown
interface gigabitEthernet 1/4
switchport access vlan 200
no shutdown
ft interface vlan 200
ip address 10.1.1.2 255.255.255.0
peer ip address 10.1.1.3 255.255.255.0
no shutdown
ft peer 1
heartbeat interval 300
heartbeat count 10
ft-interface vlan 200
ft group 1
peer 1
priority 150
associate-context Admin
inservice
context GAAS
allocate-interface vlan 100
username admin password 5 $1$449pMeGu$NwD2lPttjANuMq/gxgv4A1 role Admin domain
default-domain
username www password 5 $1$w43pZtK3$ZllEobQFqTbdYWQl2V3.n0 role Admin domain de
fault-domain
ssh key dsa 1024 force
No, I've don't allocated mac address pools? Should I do that?
04-16-2012 01:08 AM
Yep.
Also can you give us the output of the "show ft group detail" ?
04-16-2012 01:10 AM
Here's :
ACE1/Admin# sh ft group detail
FT Group : 1
No. of Contexts : 1
Context Name : Admin
Context Id : 0
Configured Status : in-service
Maintenance mode : MAINT_MODE_OFF
My State : FSM_FT_STATE_ACTIVE
My Config Priority : 150
My Net Priority : 150
My Preempt : Enabled
Peer State : FSM_FT_STATE_STANDBY_HOT
Peer Config Priority : 100
Peer Net Priority : 100
Peer Preempt : Enabled
Peer Id : 1
Last State Change time : Fri Apr 13 14:52:15 2012
Running cfg sync enabled : Enabled
Running cfg sync status : Running configuration sync has completed
Startup cfg sync enabled : Enabled
Startup cfg sync status : Startup configuration sync has completed
Connection sync enabled : Enabled
Bulk sync done for ARP : 0
Bulk sync done for LB : 0
Bulk sync done for ICM : 0
Bulk sync done for ND : 0
04-16-2012 01:19 AM
strange, you have different mac addresses on both units. The standby unit should never reply to arp requests
04-16-2012 01:25 AM
Now I've configure the following on the Admin context :
shared-vlan-hostid 1
peer shared-vlan-hostid 2
But I don't think that it's make something different?
ACE1/GAAS# sh arp
Context GAAS
================================================================================
IP ADDRESS MAC-ADDRESS Interface Type Encap NextArp(s) Status
================================================================================
192.168.10.1 00.1f.9f.f1.a9.a1 vlan100 GATEWAY 10 133 sec up
192.168.10.88 00.27.13.b8.d1.e0 vlan100 LEARNED 14 14233 sec up
192.168.10.246 e8.9a.8f.b2.68.80 vlan100 INTERFACE LOCAL _ up
192.168.10.250 e8.9a.8f.b2.68.80 vlan100 VSERVER LOCAL _ up
192.168.10.253 e8.9a.8f.b2.68.80 vlan100 NAT LOCAL _ up
================================================================================
Total arp entries 5
ACE2/GAAS# sh arp
Context GAAS
================================================================================
IP ADDRESS MAC-ADDRESS Interface Type Encap NextArp(s) Status
================================================================================
192.168.10.1 00.1f.9f.f1.a9.a1 vlan100 GATEWAY 11 293 sec up
192.168.10.247 e8.9a.8f.b2.68.7a vlan100 INTERFACE LOCAL _ up
192.168.10.250 e8.9a.8f.b2.68.7a vlan100 VSERVER LOCAL _ up
192.168.10.253 e8.9a.8f.b2.68.7a vlan100 NAT LOCAL _ dn
================================================================================
Total arp entries 4
Thanks for your help!
04-16-2012 01:27 AM
Open a case, I don't know why the second ACE sends ARP messages.
04-16-2012 01:35 AM
Thanks a lot for your help!
Ok, I'll open a case...
04-16-2012 01:42 AM
Is there any impact on the service ? Arp collisions in L2 adjacent devices ?
Maybe this issue is purely cosmetic.
04-17-2012 01:22 AM
Hi Surya,
So, I've open a case by Cisco... and we've found the solution to my problem!
To help the communities I put the solution here :
I've configure one ft group for the Admin context and for the vlan in Admin context all was good!
But I've a another context and I don't have configure a ft group for this context and that was the problem...
Each context should be or must be defined by one ft group.
That's it
Best regards
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide