cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
29243
Views
20
Helpful
6
Replies

%C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: Packet received with invalid source MAC address (00:00:00:00:00:00)

Dear Folkz,

I've 4500 switch & getting the below error on gig 3/1 where my VM ware server is connected(VM ware is installed in HP platform). Kindly let me know that how to stop this error in my cisco switch. Thanks in advance :-

017474: Aug 14 13:17:19.193 IST: %C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: (Suppressed 145 times)Packet received with invalid source MAC address (00:00:00:00:00:00) on port Gi3/1 in vlan 51

017475: Aug 14 20:04:24.386 IST: %C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: (Suppressed 2 times)Packet received with invalid source MAC address (00:00:00:00:00:00) on port Gi3/1 in vlan 51

017476: Aug 15 07:40:49.992 IST: %C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: (Suppressed 1 times)Packet received with invalid source MAC address (00:00:00:00:00:00) on port Gi3/1 in vlan 51

017477: Aug 15 08:13:05.664 IST: %C4K_REDUNDANCY-5-CALENDAR_RATELIMIT: The calendar has been successfully synchronized to the standby supervisor24 times since last calendar syslog

017478: Aug 16 08:13:01.973 IST: %C4K_REDUNDANCY-5-CALENDAR_RATELIMIT: The calendar has been successfully synchronized to the standby supervisor24 times since last calendar syslog

017479: Aug 16 09:36:33.516 IST: %C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: (Suppressed 1 times)Packet received with invalid source MAC address (00:00:00:00:00:00) on port Gi3/1 in vlan 51

017480: Aug 16 15:36:33.584 IST: %C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: (Suppressed 1409 times)Packet received with invalid source MAC address (00:00:00:00:00:00) on port Gi3/1 in vlan 80

017481: Aug 16 21:36:32.996 IST: %C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: (Suppressed 4933 times)Packet received with invalid source MAC address (00:00:00:00:00:00) on port Gi3/1 in vlan 80

017482: Aug 17 03:36:32.865 IST: %C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: (Suppressed 4174 times)Packet received with invalid source MAC address (00:00:00:00:00:00) on port Gi3/1 in vlan 80

017483: Aug 17 08:12:58.293 IST: %C4K_REDUNDANCY-5-CALENDAR_RATELIMIT: The calendar has been successfully synchronized to the standby supervisor24 times since last calendar syslog

017484: Aug 17 09:37:01.937 IST: %C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: (Suppressed 3769 times)Packet received with invalid source MAC address (00:00:00:00:00:00) on port Gi3/1 in vlan 80

017485: Aug 17 15:37:15.962 IST: %C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: (Suppressed 2269 times)Packet received with invalid source MAC address (00:00:00:00:00:00) on port Gi3/1 in vlan 80

017486: Aug 17 21:37:16.436 IST: %C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: (Suppressed 1484 times)Packet received with invalid source MAC address (00:00:00:00:00:00) on port Gi3/1 in vlan 80

Regards,

Amir

1 Accepted Solution

Accepted Solutions

InayathUlla Sharieff
Cisco Employee
Cisco Employee

Amir,

1. %C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: Packet received with invalid source MAC address ( [mac-addr] ) on port [char] in vlan [dec]

A packet was received with an all zero or a multicast source address. The packet is treated as invalid and no learning is done. Excessive flow of such packets can waste CPU cycles. This message is rate-limited and is displayed only for the first such packet received on any interface or VLAN. Subsequent messages will display cumulative count of all such packets received in given interval on all interfaces.

Recommended Action: Check the switch configuration file to find the source of these packets on the specified port and take corrective action to fix them at the source end. You can also enable port security on that interface to shutdown the port if the incoming rate of packets with invalid source mac address is too high by issuing the switchport port-security limit rate invalid-source-mac command.

Error msg in your logs:

017474: Aug 14 13:17:19.193 IST: %C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: (Suppressed 145 times)Packet received with invalid source MAC address (00:00:00:00:00:00) on port Gi3/1 in vlan 51

Logging messages point to problem on devices sending the frames to the switch, NIC that created the frame encapsulated it with Source MAC filed 00:00:00:00:00:00 which is treated as invalid by the switch. As per our knowledge base most common reason when all zero MAC addresses are generated are PCs running Win 7 going to hibernate more and inactive VMWare machines.

ACtion Plan:

=========

I would suggest to investigate whats is connected to this port, check NIC ,application or drivers and update them accordingly.

Please note that packets with invalid MAC address will be dropped anyway, all other Cisco Catalyst switches are silently dropping these packets in HW, 4k platform is explicitly generating logging message when such event is observed.

On 4k you can disable logging regarding this event (or actually tell switch to drop frame on ASIC level instead of CPU) with following command "mac address-table static 0.0.0 vlan 120 drop" this command is available since IOS 12.2(53)SG7 and later. Actually, there is enhancement bug addressing how invalid mac addresses and associated logging messages are being handled by 4k platform -> " cscto67828".
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCto67828

 hope that this helps, if you have any further questions or comments do not hesitate on letting me know. I'm here to help.

HTH

Regards

Inayath

*Plz rate if this info is helpfull.

View solution in original post

6 Replies 6

InayathUlla Sharieff
Cisco Employee
Cisco Employee

Amir,

1. %C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: Packet received with invalid source MAC address ( [mac-addr] ) on port [char] in vlan [dec]

A packet was received with an all zero or a multicast source address. The packet is treated as invalid and no learning is done. Excessive flow of such packets can waste CPU cycles. This message is rate-limited and is displayed only for the first such packet received on any interface or VLAN. Subsequent messages will display cumulative count of all such packets received in given interval on all interfaces.

Recommended Action: Check the switch configuration file to find the source of these packets on the specified port and take corrective action to fix them at the source end. You can also enable port security on that interface to shutdown the port if the incoming rate of packets with invalid source mac address is too high by issuing the switchport port-security limit rate invalid-source-mac command.

Error msg in your logs:

017474: Aug 14 13:17:19.193 IST: %C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: (Suppressed 145 times)Packet received with invalid source MAC address (00:00:00:00:00:00) on port Gi3/1 in vlan 51

Logging messages point to problem on devices sending the frames to the switch, NIC that created the frame encapsulated it with Source MAC filed 00:00:00:00:00:00 which is treated as invalid by the switch. As per our knowledge base most common reason when all zero MAC addresses are generated are PCs running Win 7 going to hibernate more and inactive VMWare machines.

ACtion Plan:

=========

I would suggest to investigate whats is connected to this port, check NIC ,application or drivers and update them accordingly.

Please note that packets with invalid MAC address will be dropped anyway, all other Cisco Catalyst switches are silently dropping these packets in HW, 4k platform is explicitly generating logging message when such event is observed.

On 4k you can disable logging regarding this event (or actually tell switch to drop frame on ASIC level instead of CPU) with following command "mac address-table static 0.0.0 vlan 120 drop" this command is available since IOS 12.2(53)SG7 and later. Actually, there is enhancement bug addressing how invalid mac addresses and associated logging messages are being handled by 4k platform -> " cscto67828".
http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCto67828

 hope that this helps, if you have any further questions or comments do not hesitate on letting me know. I'm here to help.

HTH

Regards

Inayath

*Plz rate if this info is helpfull.

Dear Inayath,

Thanks for your input :-) :-)

Regards,

Amir

Amir,

Could I request you to mark this thread as answered if this has solved your issue or infomraiton you are looking for and rate the post if usefull. If you have any further query please do let me know .

Thanks

Inayath

1994.faheem
Level 1
Level 1

Dear Amir,

Here i get the same error in our wireless VLAN, also it's an Open SSID we are providing free wifi using third-party RADIUS server for OTP authentication. so kindly requesting you to give me some suggestions for securing this type of events or securing open SSID ?

in last time when we get the same error, all our access and distribution level trunk ports are get stucked (yellow light sticked).

Please give me your contact no if you have the answer or call me below given contact no,
Mob No-8574447735

C4K_L2MAN-6-INVALIDSOURCEADDRESSPACKET: (Suppressed 46 times)Packet received with invalid source MAC address (00:00:00:00:00:00) on port Gi2/6 in vlan 100

 

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card