01-07-2014 11:01 AM - edited 03-07-2019 05:25 PM
Ok Cisco community, I'm running out of ideas on this problem and I could use some direction. I have a scenario where hosts will stop communicating with other hosts on the LAN. For example with a web server, the first time a webpage is rquested the page cannot be displayed. The second and all subsequent requests work fine until it sits idle for about 10-15 minutes and then it all happens again. This is happening on a 3750x stack with a 2921 router for remote office routing and an ASA 5515x for edge security -- it's a very simple environment.
I'm grasping at straws at this point, so I'm open to any suggestions.
Thank you!
01-07-2014 11:22 AM
Hello
Have you scanned your network for possible viruses pertaining to a potential DOS attacks?
Is this occurring between all hosts to server or host to host also?
Res
Paul
Sent from Cisco Technical Support iPad App
01-07-2014 11:38 AM
This is happening from host to host as well.
If we keep a continuous ping going from a host to the server, then that client doesn't have the problem to that server as long as the ping is running.
We will check for a virus at the application layer, but it seems that a DoS attack or other storm would also be manifest on the switch as well. I don't see any ports that are averaging over 5Mbits.
01-27-2014 12:34 PM
I started some packet captures on the switch to see what was going on under the hood. I found that the ASA was responding to ARP requests for internal servers. After digging around as to why this would happen I found that "proxy ARP" was probably the feature that would cause this. Sure enough "proxy ARP" was enabled on the inside interface. Once this was disabled the ASA stopped responding to ARP requests for hosts on the inside interface.
So far the problem seems to be resolved, I'll report back on any new findings.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide