cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
12513
Views
25
Helpful
5
Replies

ipv6 between nx/os nexus 7K and ASA firewall

phoffswell
Level 1
Level 1

Hi -

I'm receiving a strange message from my Nexus 7010:

Jan 30 09:45:22 10.1.3.1 : 2012 Jan 30 09:45:22 EST: %ICMPV6-3-ND_LOG:  icmpv6 [4740]  Inconsistent RA retrans-timer on Vlan24, ours is: 0, from fe80::21b:54ff:fef7:9205

Jan 30 09:45:22 10.1.3.1 : 2012 Jan 30 09:45:22 EST: %ICMPV6-3-ND_RA_LOG:  icmpv6 [4740]  fe80::21b:54ff:fef7:9205 on Vlan24 Current-hop-limit:64, m-bit:0, o-bit:0, rtr-lifetime:1800, reachable-time:0, retrans-timer:1000

Jan 30 09:48:33 10.1.3.1 : 2012 Jan 30 09:48:33 EST: %ICMPV6-3-ND_LOG:  icmpv6 [4740]  Inconsistent RA retrans-timer on Vlan24, ours is: 0, from fe80::21b:54ff:fef7:9205

Jan 30 09:48:33 10.1.3.1 : 2012 Jan 30 09:48:33 EST: %ICMPV6-3-ND_RA_LOG:  icmpv6 [4740]  fe80::21b:54ff:fef7:9205 on Vlan24 Current-hop-limit:64, m-bit:0, o-bit:0, rtr-lifetime:1800, reachable-time:0, retrans-timer:1000

I cannot find any documentation as to what this means!

I have not made any adjustments to retransmit timers on either device.

Is there some inconsistant default setting on ra retrans-timer between the asa and the nexus?

1 Accepted Solution

Accepted Solutions

you should mark this question as answered then. thx!

Sent from Cisco Technical Support iPad App

View solution in original post

5 Replies 5

phoffswell
Level 1
Level 1

I answered the question myself.  The log is saying that the neighbor (*:9205) has a retransmit timer of 1000.

When I check the nexus, I see:

CORE# show ipv6 nd interface vlan ..

ICMPv6 ND Interfaces for VRF "default"

Vlan24, Interface status: protocol-up/link-up/admin-up

  IPv6 address: ...

  IPv6 interface DAD state:  VALID

  ICMPv6 active timers:

      Last Neighbor-Solicitation sent: 00:07:14

      Last Neighbor-Advertisement sent: 00:07:09

      Last Router-Advertisement sent: 00:03:14

      Next Router-Advertisement sent in: 00:00:27

  Router-Advertisement parameters:

      Periodic interval: 200 to 600 seconds

      Send "Managed Address Configuration" flag: false

      Send "Other Stateful Configuration" flag: false

      Send "Current Hop Limit" field: 64

      Send "MTU" option value: 1500

      Send "Router Lifetime" field: 1800 secs

      Send "Reachable Time" field: 0 ms

      Send "Retrans Timer" field: 0 ms

      Suppress RA: Disabled

      Suppress MTU in RA: Disabled

  Neighbor-Solicitation parameters:

      NS retransmit interval: 1000 ms

  ICMPv6 error message parameters:

      Send redirects: true

      Send unreachables: false

Just do this, to match the nexus retrans timer with the firewall:

CORE(config-if)# ipv6 nd retrans-timer 1000

you should mark this question as answered then. thx!

Sent from Cisco Technical Support iPad App

Cisco's forum does not allow you to answer your own question, so I cannot mark my own response at the correct answer.

If it makes you feel better, I'll mark yours as the correct answer, since it's the first, and only response I've gotten.

I saw this log:

2014 Aug 14 11:23:28 IIG-SWC2-NX %ICMPV6-3-ND_RA_LOG:  icmpv6 [6690]  fe80::60ff:fe9c:8e42 on Ethernet7/2 Current-hop-limit:64, m-bit:0, o-bit:0
, rtr-lifetime:1800, reachable-time:0, retrans-timer:0

and # sho ipv6 nd int ethernet 7/2:

      Send "Retrans Timer" field: 0 ms

How should I do?

yep, worked for me.. Thanks

Review Cisco Networking for a $25 gift card