cancel
Showing results for 
Search instead for 
Did you mean: 

ARP CACHE POISONING

ARP CACHE POISONING

Aviv_Kedem
Contributor
Hello Community,

I use ip mac conflict log only. AP75XX/AP65XX. WING 5.8.6+/5.9+.
Recently, in several deployments I saw a lot of this type of logs messages:

...%DATAPLANE-4-ARPPOISON: ARP CACHE POISONING: Conflicting snoop entry found :Ethernet Src Mac: ....., Ethernet Dst Mac: FF-FF-FF-FF-FF-FF, ARP Src Mac: ...., ARP Dst Mac: 00-00-00-00-00-00, ARP Src IP: ...., ARP Target IP: ...., Snoop Table MAC = ...., Snoop Table IP = ....

It seems the router is flooding some different info about mac adress table info with AP.
Can it cause any network issues ?

Thanks,

Aviv Kedem
13 REPLIES 13

Joffre_Flores
New Contributor
With best practice all its ok

Aviv_Kedem
Contributor
Hello All,

This issue may appear if used vc for ap6532 + other vc for ap7532 on the same vlan?
We need it for configuration provosioning of these two models of ap.

Thanks,

Aviv

Ondrej_Lepa
Extreme Employee
HI Aviv,

it rather depends on the source address - you see that destination is FF::FF / 00::00 which looks like Gratuitous ARP

Try to search for the source and if found, confirm you do not have IP conflict.

Regards,
Ondrej

Many thanks guys.

Aviv

Timo1
New Contributor II
Do you use a firewall cluster? See this offend, if two MAC address share the same IP. This is mostly, if it's a cluster.

If you use a cluster you can set "ip arp trust" to the interface or disable the check under the firewall policy:
no ip-mac conflict

no ip-mac routing conflict

GTM-P2G8KFN