Re: Strange results from a tcpdump, can anyone help?
- From: "maethlin" <maethlin@xxxxxxxxx>
- Date: 30 Mar 2006 09:53:09 -0800
Please see answers below:
Patrick Schaaf wrote:
"maethlin" <maethlin@xxxxxxxxx> writes:Only one ethernet port connected on each server.
I work in an environment with many separate vlans spanning several
switches (say about a dozen). Today we had an incident where suddenly
traffic was going ballistic on most ports in the network. Doing a
tcpdump on a particular host on this network, you could actually see
unicast traffic that was neither destined to or coming from the host.
Typical network flooding situation.
Note that all switches do what looks like unicast flooding, when they
never recently saw traffic for the destination MAC of the packet. This
can easily happen in a complex switch cloud, when broken L3 configuration
results in nonsymmetric, triangular traffic.
Also note that all switches revert to unicast flooding behaviour when their
MAC->Port tables become full.
We shut off some ports where some new windows servers were brought up
today. As soon as those ports were taken offline, then tcpdumps on the
other hosts went to normal (i.e. the only traffic you could see were
broadcasts, or unicasts to and from that host).
Did any of those windows servers have more than one ethernet port connected?
Probably not, or you would have mentioned it... If they did, maybe your
switches thought they were switches, too.
You mentioned VLANs. How were the ports of those windows serversThe ports for those servers were set to "Untagged" for the vlan they
configured in this regard? Untagged, tagged, open for all VLANs?
were supposed to participate in. They weren't set at all for all other
vlans. (note, these are HP Procurve switches)
How was IP configured on the windows server(s)? Any possibilityAs far as I can tell, IP is configured normally - when I turn portfast
that one of them took over one of the usual default gateways,
e.g. by the typical error of switching local and default gateway
IP under configuration? This could be the cause for triangular
traffic, as mentioned above.
on (and thus am able to bring up a server safely) I can connnect and
see that IP is correct, and default gateway is correctly set to be the
core switch (which also serves as the router/default gateway in this
network).
.
- References:
- Strange results from a tcpdump, can anyone help?
- From: maethlin
- Re: Strange results from a tcpdump, can anyone help?
- From: Patrick Schaaf
- Strange results from a tcpdump, can anyone help?
- Prev by Date: Re: 10M full forced port connected to 100M full Duplex port
- Next by Date: Re: Strange results from a tcpdump, can anyone help?
- Previous by thread: Re: Strange results from a tcpdump, can anyone help?
- Next by thread: Dead Netgear PE-102s
- Index(es):
Relevant Pages
|