cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
706
Views
0
Helpful
4
Replies

Wireless ARP requests that disable switchports

tajennings
Level 1
Level 1

Hello,

I have here an interesting issue. We have a mac address authentication scheme for our wireless structure and we have found that if a wireless client is not registered on the network, it sends multicast arp requests via the wired connection which ends up forcing the switch to errdisable the port due to going over the default 16 arp requests/second.

This can be solved by just disabling wireless or registering the wireless mac on the network but my question is why would the wireless client send arps via the wired connection in the first place?

4 Replies 4

jeff.kish
Level 7
Level 7

What wired connection are you talking about? Are the clients using wireless and also plugged into a switch?

If a client has multiple NICs, the OS determines which one to use. If you look at Network Connections in XP, for example, you can order which NIC should be used when multiple ones are installed. In general, by default the wired connection is used since it's faster.

I'm not sure if that's what you're looking for or not... haha.

Yes, the clients are connecting to both wireless and wired networks.

So basically why would the OS be sending ARP requests out via wired network when the wireless nic is refused access due to not being registered and does not recieve a IP address from DHCP?

Hi Everyone,

I'm not sure if this helps or not, but do you need to have multicasting running on your switches? If you don't need to multicast, then maybe you can disable that, use unicast instead, and maybe that will remove the multicast arp packets. If you have a Wireless LAN Controller, check to see if multicasting is turned on. I only have unicast mode running. Did you use a packet sniffer like wireshark to find the multicast packets? Maybe you can find where they're coming from by checking the packets. Hope this helps!

Well, ARP requests aren't actually multicasts, but if they were then that'd be a good suggestion.

So you're saying that the client does NOT get an address via either wireless or wired? Is it giving itself an APIPA (169.x.x.x)? If so, it would start ARPing out anything it tries to connect it, and that would just depend on the programs running on the client.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card