- Community Home
- >
- Networking
- >
- Legacy
- >
- Switches, Hubs, Modems
- >
- Unicast Flooding network-wide
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Discussions
Forums
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-01-2010 06:07 AM
тАО11-01-2010 06:07 AM
We are seeing some strange behaviour in our fully HP-switched Layer-2 network.
Basically our setup is as follows: We have a ring of 5 core-switches (8212zl), connecting into our datacenters to a wide variety of rackswitches (anything from 1800 to 28xx series)
For a while now, we are seeing unicast packets to be flooded out of all the core-ports.
I recently connected a linux-box straight into on of our core-routers and ran a tcpdump, and i am seeing all traffic for any specific vlan to be sniffed by tcpdump. Source and destination mac-addresses are known in the core, so these should not be passed to this linux box.
On a side-note, we are also seeing a spanning-tree topology change every 42 seconds on the switches. It will be hard to track down where this change occurs (?)
Anyone has any clue where to begin?
Solved! Go to Solution.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-01-2010 10:52 AM
тАО11-01-2010 10:52 AM
SolutionI would start by looking at the logs on the core switches, see if either the root or the blocked link move around. You have the root on one of the 8212zl switches?
If that's OK, you could try temporarily disabling spanning tree on individual (simply connected) edge parts of your network with bpdu-filter. That forces the port to forwarding and drops BPDUs. You might be able to isolate the fault that way.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-02-2010 05:41 AM
тАО11-02-2010 05:41 AM
Re: Unicast Flooding network-wide
I hope you have resolved.
Another thought, you may want to enable the Instrumentation Monitor feature and view results. Not that this is a DOS attack, however I have read that DOS attacks can cause a CPU to take to long to respond to new events, which can lead to a breakdown of Spanning Tree or other features. A delay of several seconds typically indicates a problem. Information on this can be found in the HP ProCurve Switch Software Access Security Guide.
I hope this helps and look forward to reading resolution to this.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-02-2010 05:44 AM
тАО11-02-2010 05:44 AM
Re: Unicast Flooding network-wide
Pretty sure it is not a DOS attack, since our Arbor doesnt see any of this.
It will be very hard to track down the constant toplology changes I think.
The network consists of over 300 rackswitches, all connecting to the 5 core-switches.
Shutting down portions of the spanning-tree topology will not work i'm afraid.
-J
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-02-2010 05:46 AM
тАО11-02-2010 05:46 AM
Re: Unicast Flooding network-wide
All rackswitches are dual-connected to at least 2 core-switches, so starting to filter bpdu's will create loops...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-02-2010 06:19 AM
тАО11-02-2010 06:19 AM
Re: Unicast Flooding network-wide
Finding where:
dot1dStpRootCost or dot1dStpRootPort are changing might be a place to start.
Good hunting!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-02-2010 01:57 PM
тАО11-02-2010 01:57 PM
Re: Unicast Flooding network-wide
Olaf
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-02-2010 02:23 PM
тАО11-02-2010 02:23 PM
Re: Unicast Flooding network-wide
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-02-2010 02:30 PM
тАО11-02-2010 02:30 PM
Re: Unicast Flooding network-wide
Many thanks for your replies.
Managed to track down the evil by issueing a:
"show spann debug
Turned out to be a buggy Dell-blade switch who was in a constant reboot-loop, causing a continuous topology change.
(for what it's worth: Dell's take exactly 42 seconds to reboot:-))
Shut down the links and all is stable again.
PS: there are roughyly 3000 Mac-adresses in the table. Not cool to flush them every 40 seconds.
Thanks for your responses, it's all quiet on the western front now.
-J
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-02-2010 02:39 PM
тАО11-02-2010 02:39 PM
Re: Unicast Flooding network-wide
If you like I'd be more than happy to try to get you in touch with an HP sales type to help you replace that nasty, buggy Dell equipment :)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
тАО11-02-2010 02:43 PM
тАО11-02-2010 02:43 PM
Re: Unicast Flooding network-wide
well, yes, there are a few exception.We have a few Dell blade-servers, and they connect through built-in blade-switches (only a few)
Thanks anyway :-)