cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
292
Views
0
Helpful
1
Replies

Inappropriate unicast flooding on 2924XL

srd
Level 1
Level 1

Hi,

I'm seeing unicast traffic on ports which it should not reach.

The management VLAN is configured as VLAN 16.

A router (in this case an AS5300 running IOS 11.3(11b)T2) is attached to port FastEthernet 0/9 on the 2924XL. The port is configured as a multi-VLAN port (in VLANs 1,3 and 98).

Various servers are connected to the other ports in VLANs 3 and 98, and Fa 0/24 is connected to a 3512XL (VLAN 1 at both ends).

Any machine (all but one runs Linux 2.4.x with either VIA Rhine or DEC Tulip ethernet hardware - the exception is a Sun Ultra 10 running Solaris 8) on a port in VLAN 98 sees all traffic destined for the router from MOST other machines in VLAN 98.

The router is routing the traffic correctly. The frames have, according to tcpdump on any of the machines at least, the correct ethernet address of the router.

The switch has the router's ethernet address in its dynamic MAC address table and has assigned it to the correct VLANs.

port block unicast on any of the server ports stops this traffic showing up. Which suggests to me that the switch thinks it doesn't know the router's address.

Help? :)

Config extracts:

interface FastEthernet0/9

description Aphrael (core router)

port storm-control broadcast action filter

port storm-control broadcast threshold rising 128 falling 96

port storm-control multicast action filter

port storm-control multicast threshold rising 32 falling 16

switchport multi vlan 1,3,98

switchport mode multi

!

interface FastEthernet0/10

description Vanion

port storm-control broadcast action filter

port storm-control broadcast threshold rising 128 falling 96

port storm-control multicast action filter

port storm-control multicast threshold rising 32 falling 16

switchport access vlan 98

spanning-tree portfast

no cdp enable

1 Reply 1

ciscomoderator
Community Manager
Community Manager

Often times complex troubleshooting issues are best addressed in an interactive session with one of our trained technical assistance engineers. While other forum users may be able to help, it’s often difficult to do so for this type of issue.

To utilize the resources at our Technical Assistance Center, please visit http://www.cisco.com/tac and to open a case with one of our TAC engineers, visit http://www.cisco.com/tac/caseopen

If anyone else in the forum has some advice, please reply to this thread.

Thank you for posting.

Review Cisco Networking for a $25 gift card