cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1096
Views
0
Helpful
1
Replies

Strange ARP storm on network

epeeler
Level 1
Level 1

I'm seeing a large number of arp requests on a network that is 161.253.232.0/22. This is a lab environment. The arp packets are "who has 161.253.232.255". My questions are:

1. is it normal to see an arp request FOR (not destined to) the broadcast address for a subnet?

2. Because of the netmask used, the broadcast address should actually be 235.255 and not 232.255. Could I be seeing some kind of limitation of the IP stack on the devices that are doing the arping wherein they can't deal with the non-standard subnet mask that this subnet uses?

1 Reply 1

jaregalado
Level 1
Level 1

Hi,

Interesting scenario, as you point out the correct broadcast address for your network should be 161.253.235.255

The IP address seen on the ARP request is a usable IP address under your IP addressing scheme, as weird as it may look at first glance 161.253.232.255/22 can be safely assigned as the available IP range is 161.253.232.1/22 to 161.253.235.254/22

A quick explation can be found on:

http://expertanswercenter.techtarget.com/eac/knowledgebaseAnswer/0,295199,sid63_gci1053572,00.html

So, I think there's nothing wrong with your network, and no, ARP requests for the broadcast address are not normal behavior.

Best regards.

Review Cisco Networking for a $25 gift card