05-10-2018 03:13 PM - edited 03-08-2019 02:59 PM
Having a strange issue on one of my 3750 switches and hoping someone might be able shed some light on whats happening. We are enforcing NAC on our network and we are having an issue where one of the switches stops accepting snmp authentication (only from this device). When testing the authentication from the NAC management we get an authentication failure. When I log into the switch, and try and ping the NAC device, I dont get a response. When I clear the arp entry from the switch, I am able to ping the NAC device again, but only for a few minutes, and then the same thing happens again. Anyone have any ideas on what might cause this?
05-10-2018 03:26 PM
I am not sure what the issue is here and suggest this approach to troubleshoot it:
1) when the problem is happening do show arp and record the arp entry in question.
2) clear the arp entries
3) ping the NAC device
4) show arp and record the arp entry in question
5) wait till the problem starts again
6) show arp and record the arp entry in question
7) post the outputs
It will be interesting to see what is the original arp entry when you are having the problem, to see what is the arp entry when it is working, and to see if the original arp entry comes back when it is not working or is a different entry.
Once we have this information we will evaluate what is our next step.
HTH
Rick
05-14-2018 02:42 PM
Here are the outputs
Cannot Ping
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.1.1.137 0 0050.5689.7d60 ARPA Vlan1
Cleared ARP cache and can ping
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.1.1.137 0 0050.5689.7d60 ARPA Vlan1
After 30 seconds, cannot ping
Protocol Address Age (min) Hardware Addr Type Interface
Internet 10.1.1.137 0 0050.5689.7d60 ARPA Vlan1
05-16-2018 07:45 AM
Thanks for the output. This is surprising. I expected to see a change in the arp entry. But this output shows exactly the same entry each time. So we need to look further for the cause of the issue. Can you tell us about the topology of the network? Is 10.1.1.137 locally connected on this switch? Or does the IP packet go through some other device(s) to get to that address? Is layer 3 routing enabled on this switch or is it a layer 2 only switch?
HTH
Rick
05-17-2018 10:30 AM
This is a Layer 3 switch with routing enabled. The Server is not directly connected to this switch, we have a 20MB fiber link to the building where this switch is. We have several other switches in the same location and do not have this issue. I am starting to think that there may be an issue with the IOS on this switch as I also get disconnected occasionally for no reason, other times I have to ssh a few times before I can access the switch.
05-18-2018 06:41 AM
Thanks for the additional information. Can you tell us whether the mac address shown in the arp entry is the address of the NAC device, or is the address of some intermediate device/next hop?
HTH
Rick
05-18-2018 07:09 AM
Yes, it is the same MAC.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide