I have a question about ARP and HSRP traffic. Here's the situation. I have 2 6509's with MSFC's running HSRP for about 60 VLANs. All users are using the virtual IP as their gateway. On one of the segments we have an AS/400. Every night the AS/400 is brought down for maintence and backups. Sometimes it's down for over 4hrs. This causes it to be removed from the arp tables on the MSFC's. When they bring this back on-line I only see an ARP entry in one of the 6509's. I can't get an ARP entry to show up on the second unless I ping from the router interface on that segment. If I ping from any other VLAN it timesout.
Do redundant HSRP routers syncronze their ARP tables?
Why wouldn't a ping from another VLAN force an arp request to be sent from that router?
The easy one first - HSRP routers do not synchronize their ARP tables.
As for the ping request from another VLAN forcing an ARP request, I am assuming that you are having the secondary router ping the AS/400 using the address of another VLAN as the source address. In this case, I suspect that an ARP request is being sent, and either no reply is received or the echo response is sent to the primary router, and the primary router may not have a path on the originating VLAN to the secondary router. Your description makes it obvious that there is a connection between the two 6509s, and this connection can carry the VLAN on which the AS/400 resides. Is this connection between the switches set up as a trunk cabable of carrying all of your VLANs? Also, after the ping attempt from another VLAN, does the MSFC have an ARP entry for the AS/400, even though the ping was not successful?
regarding your second question, the arp request may be going out but not getting back, you have to snif it or run the debug if there are not many arp going on the router.. to see if the responce from the server is getting back..
Also check the encapsulation of the frame- what types of encap it is - arpa or something else.
One important thing to keep in mind is that ARP tables are local to a device. When a request comes in, and there is no entry, an ARP is sent on the corresponding LAN segment. Your AS400 presumably also has the HSRP adress as def. gw. Its reply will therefore always be sent to the active interface in the standby group. That is why you only see an ARP entry in one 6509. At the moment of a failure, the second one will take over and very quickly have an ARP entry for the AS400.
When you ping from the interface, you are using the local IP adress. This adress is in the same subnet, hence it does not go to the def.gw. and you get your ARP entry. This is all perfectly logical.
What do you mean with: If I ping from any other VLAN it timesout?
Is there no reply to the ping packets? Or does the entry time out? I suppose that you mean the first. This points to a potential problem in your IP routing config. To pinpoint it, more specific info will be needed.
[toc:faq]The ProblemOn traditional switches whenever we have a trunk
interface we use the VLAN tag to demultiplex the VLANs. The switch needs
to determine which MAC Address table to look in for a forwarding
decision. To do this we require the switch to do...
[toc:faq]Introduction:Netdr is a tool available on a RSP720, Sup720 or
Sup32 that allows one to capture packets on the RP or SP inband. The
netdr command can be used to capture both Tx and Rx packets in the
software switching path. This is not a substitut...
IntroductionOSPF, being a link-state protocol, allows for every router
in the network to know of every link and OSPF speaker in the entire
network. From this picture each router independently runs the Shortest
Path First (SPF) algorithm to determine the b...