Jump to content

MrP

Members
  • Posts

    5
  • Joined

  • Last visited

Everything posted by MrP

  1. Does anyone know why I only get excessive broadcasts on uplink/trunk ports on not on any edge/access ports? When I mirror the uplink and capture the traffic via Wireshark, the ARP broadcasts are coming from a particular VLAN, but is not coming out on any of the edge/access ports on that VLAN.
  2. I think this is a strong possibility. There are other captures I have that are almost purely Gratuitous ARPs from the same virtual TMS Server. I will have another read through before I decide how I'm going to implement it. I will let you know the result. Thank you all for your help.
  3. You might be onto something. We don't manage the configuring of our UCS Switch so I can't see the configuration unfortunately - my vision from a networking perspective stops at the HP switches it is connected to. The .89 address is the virtual server for video conferencing (TMS) and the .5 address is a video conferencing unit.
  4. Hi Marshall, it's not always the same device, but they are always related devices on the same subnet (10.163.255.0/24), ie they are always video conferencing units or servers for video conferencing.
  5. Hi All, We've been experiencing excessive broadcasts in my company for a while now which sometimes cause brief outages. I started running Wireshark to capture broadcasts during these storms by mirroring the uplink port of one of the switches. The output of the capture is as follows:- 289837 2013-11-04 16:43:46.503029000 Vmware_a2:00:c0 Broadcast ARP Who has 10.163.255.5? Tell 10.163.255.89 289838 2013-11-04 16:43:46.503036000 Vmware_a2:00:c0 Broadcast ARP Who has 10.163.255.5? Tell 10.163.255.89 289839 2013-11-04 16:43:46.503044000 Vmware_a2:00:c0 Broadcast ARP Who has 10.163.255.5? Tell 10.163.255.89 289840 2013-11-04 16:43:46.503053000 Vmware_a2:00:c0 Broadcast ARP Who has 10.163.255.5? Tell 10.163.255.89 289841 2013-11-04 16:43:46.503060000 Vmware_a2:00:c0 Broadcast ARP Who has 10.163.255.5? Tell 10.163.255.89 289842 2013-11-04 16:43:46.503066000 Vmware_a2:00:c0 Broadcast ARP Who has 10.163.255.5? Tell 10.163.255.89 289843 2013-11-04 16:43:46.503071000 Vmware_a2:00:c0 Broadcast ARP Who has 10.163.255.5? Tell 10.163.255.89 289844 2013-11-04 16:43:46.503078000 Vmware_a2:00:c0 Broadcast ARP Who has 10.163.255.5? Tell 10.163.255.89 289845 2013-11-04 16:43:46.503083000 Vmware_a2:00:c0 Broadcast ARP Who has 10.163.255.5? Tell 10.163.255.89 289846 2013-11-04 16:43:46.503089000 Vmware_a2:00:c0 Broadcast ARP Who has 10.163.255.5? Tell 10.163.255.89 289847 2013-11-04 16:43:46.503094000 Vmware_a2:00:c0 Broadcast ARP Who has 10.163.255.5? Tell 10.163.255.89 289848 2013-11-04 16:43:46.503100000 Vmware_a2:00:c0 Broadcast ARP Who has 10.163.255.5? Tell 10.163.255.89 This literally goes on for hundreds or thousands of packets within the same second. Does this mean I have a loop somewhere in the network causing duplicate ARP Broadcast packets? The device (10.163.255.89) is a server for video conferencing units and 10.163.255.5 is a video conferencing unit. When we get these broadcast storms, the captures seems only to pick up these ARPs from devices on the video conferencing VLAN which is an end-to-end VLAN, therefore it is geographically spread across most of the network with QoS priority so when this happens, it throttles all of the uplinks, sometimes causing outages. As far as I know MSTP is configured on all switches, but I'm relatively new to this network and there are over 200 switches. Thanks in advance for any advice on this.
×
×
  • Create New...