cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
872
Views
5
Helpful
1
Replies

WS-C4507R+E Dropping UDP/3784 Malformed Packets

Umesh Shetty
Level 1
Level 1

Guys,

Been a long time but back with a hope of getting some help as usual.

 

I have a CloudGenix SDWAN device connected to a WS-C4507R+E switch. The CloudGenix has a Controller port which connect to a switchport on the 4500 , port is configured as an access port no special config.

The Controller port non stop sends UDP 3784 BFD packets to its remote DC device as keep alives.These packets are failing and I do not see them even on the access port(applied and ACL to match these packets no logs)

 

While we see on the CloudGenix device the controller is sending these packets but they are failing. Our initial test shows that these packets are not even seen on the directly connected switchport, So we did some further tests to identify if switch is dropping or the Controller is not sending the correct packets. 
  • Connected the CloudGenix controller port to a Laptop directly using a patch cord. Laptop was assigned the Default GW IP addres. Wireshark captures started and could see BFD packets on the Capture. What I see as a possible issue could be wireshark says these are malformed packets. 
  • Connected CloudGenix controller port to the swiitch interface GigabitEthernet5/47. Did an EPC capture on the switch interface GigabitEthernet5/47 but do not see these packets at all. Can see other packets though.
  • Did a EPC control-plane capture on that interface and do not see these packets. Can see other packets though.

Can't seem to find the correct reason for switch dropping/discarding these packets. Hope someone can help. Attached is the packet capture showing the malformed packets

 

Thank you in advance !!!

1 Reply 1

Umesh Shetty
Level 1
Level 1

There were two issues found 

 

1> CloudGenix BFD process uses port UDP 3784 which is not a standard port for multi hop BFD. FOr multihop BFD the port no is 4784.

 

2> Cisco 4500E in this case was dropping these packets in TCAM which in itself is a Bug and has been fixed with new releases and provides an option to disable BFD. This prevents inspection of BFD packets and hence the UDP 3784 packets are allowed . 

Disable BFD on Cisco IOS with - "feature bfd disable"

 

On older IOS' there is no work around but to upgrade the IOS and run the above command.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card