cancel
Showing results for 
Search instead for 
Did you mean: 

Frequent ARP request broadcast for Who has x.x.255.255? from S-Series root switch in RSTP VLAN

Frequent ARP request broadcast for Who has x.x.255.255? from S-Series root switch in RSTP VLAN

Edwin
New Contributor
We are getting average of 1 pps and peaks of 60 pps of these packets, from Wireshark trace.

Please kindly share information on what is the cause of these broadcasts and how to minimize the frequency.

TIA.

Screenshots of Wireshark decode and IO graph below:

5cb74c14bb95440081ded7d93f80958f_RackMultipart20160421-66535-b2kn23-arp_001_inline.jpg



5cb74c14bb95440081ded7d93f80958f_RackMultipart20160421-4448-17w0crf-arp_002_inline.jpg





14 REPLIES 14

Edwin
New Contributor
Just found an article from Juniper.net, http://www.juniper.net/documentation/en_US/junos13.3/topics/concept/ip-directed-broadcast-ex-series.html which details the mechanics of IP Directed Broadcast from a remote administration task (such as a backup server) to the hosts in a specified subnet. We have several servers north of the RSTP VLAN in a firewalled DMZ, that handle backup and patch management tasks for the workstations in the subject subnet. So, perhaps the root and backup root switches are forwarding the remote IP Directed Broadcasts as ARP requests for Who has x.x.255.255 in the subject subnet? How best to check / confirm this? Mirror the suspect interfaces to the Wireshark PC interface, perhaps and collect and analyze traces?

Edwin
New Contributor
I will check on the parallel patch cords next week WPL; it's weekend her now. Just a side query please, what is the probable cause or reason for an ARP request from the root and backup root switches for an IP address that is actually the subnet mask for our RSTP VLAN, and on a regular or periodic basis? Will all hosts in the subnet respond to these broadcasts? The Wireshark trace captured only broadcasts and unicasts to and from the PC running Wireshark. Thanks.

Mel78__CISSP__E
New Contributor III
Then likely is a loop. Do you have 2 or more parallel patch cords connected betwwen the root switch and backup root switch ?

Edwin
New Contributor
Sorry, the source IP addresses are for the root and backup root S-series switches for the RSTP VLAN network.

Mel78__CISSP__E
New Contributor III
Theres nothing i can do when you mask out the source ip of the broadcast storm.

Likely is a STP loop that causes broadcast storm.

You can use ELRP to protect your own switch but you can never eliminate the root cause if you cannot block the source.

GTM-P2G8KFN