12-01-2011 12:17 AM - edited 03-07-2019 03:41 AM
Good morning,
in our datacenter we are using two 3750G stack as L2 core switches; in the last year we're suffering a strange problem: we're seeing unicast traffic spread over all trunk ports (basically all the uplink to the satellite switches). In the beginning we thougth it was an unicast flooding, but latest test show that:
- access ports are not affected by this issue: if we connect a sniffer to a port in access (not in span) we are seeing only normal traffic (broadcast/multicast)
- trunk ports are affected by this issue: if we connect a sniffer to a port in trunk (not in span) we are seeing unicast traffic!
- during the issues the mac address table is not full
- it seems that if we restrict the number of vlan on the trunk (e.g. 1-100) we're seeing odd traffic but only of the allowed vlan (no inter vlan flooding)
Can anyone give us a suggestion? We thougth it was an IOS bug and this summer we upgrading the IOS to the 12.2 (55) version
Thank you so much!
Marco Canova
12-02-2011 06:56 AM
Hi Marco,
Have you checked whether vtp pruning is enabled or not?
can you try configuring vtp pruning and see if that fixes the issue.
conf ter
vtp pruning..
VTP has to be enabled globally
cheers
Somu
Rate helpful posts
12-05-2011 12:25 AM
Hi Somu,
yes vtp pruning is enabled everywhere, but we think it's not working properly. The next step we planned is enabling manually only the useful vlan on every trunk (at the moment all the vlan are allowed on every trunk).
I'll let you know in the next days.
Thank you so much
mc
12-05-2011 05:43 AM
Hi,
Is you L3 switches in the data centre running HSRP
If so
You unicast flooding issues could be being caused by the lack of adjustment of the
MAC address aging timer
mac−address−table aging−time 14400 (seconds)
This should equal the ARP cach time of 4 Hours (14400 Seconds )
HTH
Alex
12-05-2011 08:18 AM
Hi Alex,
I saw that suggestion, I didn't think about our L3 core (that use HSRP) I focused on our L2 core. Well we could try.
I'll let you know.
mc
12-15-2011 12:53 AM
About flooding: we analyzed the wireshark capture and saw that most of the traffic was Microsoft NLB ... We're trying to fix the issues according to this document:
mc
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide