05-12-2019 03:35 AM
Hi,
I faced an old problem
6509 msfc--internal-switch port--(outside)FWSM module L2 trnsparentmode(inside)--Switch(same 6509)--port9/5--pc1
VLAN 10 vlan 100
there is one FWSM module installed in 6509 chassis , outside zone connected to vlan 10 then to MSFC layer 3 interface vlan 10,,FWSM is confiured as layer 2 transparent mode, inside zone connected to vlan 100, and pc1 putted into same inside vlan 100. pc1's default gateway is configured pointed to interface vlan 10.
there are two 6509, and configured hsrp on interface vlan 10.
Problem:
the problem is mac address entry timeout in vlan 100 is 5 minutes, and arp timeout for outside interface vlan 10 is 4 hours
but the traffic from interface vlan 10 to PC1 (in vlan 100,same l2 domian), the source mac address is hardware mac address and not hsrp vip virtual mac address, So in vlan 100 mac address table , the virtual mac address of hsrp gateway will be flushed after 5 minutes and disappear. so pc1 traffic send to gateway will be flooded in whole vlan 100.
there are lot of backup traffic in vlan 100 from other side of FWSM , so flooding traffic congest one low bandwidth path.
I found some solution:
1、config mac aging timeout upto 5 hour,more thank arp timeout,but I am afraid there is harmful for many other traffic
2、 config arping in vlan 100 one pc, but this is not a Scala solution
but solutuon up is not very good for customer, cutomer don't want to adjust mac aging time and run arping
my question is :
Is there any possible to config gratuitous arp on 6509 to send gratuitous arp (source mac is hsrp virtual mac) at some interval, such as 4 minutes before mac address aging out
another question:
IF arp timeout before reach last second,can switch send proactive arp request out to refresh arp table before arp entry timeout and avoid lost packet between switch clear up arp entry and request new arp.
thank you
Jere
05-12-2019 11:56 PM
HI
I found reseaon of this problem
because on FWSM module didn't permit HSRP traffic from outside zone to inside zone vlan, so if there are no many traffic existed in inside zone vlan , no arp to refresh hsrp vip virtual mac , so virtual mac gone with wind.
I add acl permit hsrp signaling to 224.0.0.2 1985, so hsrp signaling traffic can reach inside vlan isolated by FWSM, so refresh mac address table on inside vlan of same 6500
thank you!
Jere
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide