Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Routing on 6509

If I have a 6509 that I am routing with... and I have an ip on a vlan. 6 ports in the vlan. When it routes a packet through that vlan... does it forward the packet out all interfaces in that vlan??

Here is where the question stems from. I have a 5500 with an 8510 router in it. The 5500 has a server plugged into port 10/12. The 8510 has a port channel int 1.256. The server (port 10/12) is in vlan 256. I am spanning to a different port (10/4) to do packet caps and see all kinds of tcp traffic (the span port is a host port not a trunk) not destined for the server...

5 REPLIES
Hall of Fame Super Silver

Re: Routing on 6509

Marty

I think it would require a bit more specific information to be able to help solve your issue (in particular some details about how your SPAN is configured, and how the VLAN and trunks are configured, and it would be very helpful to have some particulars about at least a couple of packets in the capture that you did not expect). But in general I believe that we can provide a high level answer to your question. What the router/switch does in forwarding a packet depends on a couple of things. If the packet destination is multicast then the frame is flooded to switch ports (dependent on whether IGMP/CGMP is configured and active). If the packet destination is unicast then the switch looks for the destination MAC in its layer 2 forwarding table (CAM on your switch). If it finds a match in the CAM it is forwarded to the specific port, but if it does not find a match in the CAM the frame is flooded to all ports in the VLAN.

Also of note, when the router made a forwarding decision it needed to resolve the IP address to a MAC. You would think this implies that the MAC should be in the CAM. But since the ARP timeout on the router (4 hours by default) is longer than the CAM aging timer there is a real possibility that the router will forward frames which may be flooded by the switch.

If this does not answer your question please provide some specifics on how the SPAN is configured, how the VLAN is configured, how the trunking is configured, and the source/destination addresses and protocol port numbers of some packets in the capture that you did not expect.

HTH

Rick

New Member

Re: Routing on 6509

I attached the sho ports and sho span...

I am seeing tcp traffic that is not bound for port 12... going to port 12...

New Member

Re: Routing on 6509

Interesting... I had the admin do a snoop from the server on port 10/12 and he see's only the broadcast and server traffic... so the p-cap is 'wrong' ?!?!?!

Hall of Fame Super Silver

Re: Routing on 6509

Marty

I looked at the log file that you posted and do not see anything out of the ordinary.

It is indeed interesting that snoop on the server port sees only the correct traffic.

I do not know if you want to go further with this, but if you do it might be interesting to see the output of show cam dynamic 256. I am particularly wondering if there might be some MAC address still associated with the span port.

I think that the other possibility to consider is that there may be some unicast flooding going on. One way to investigate this would be to do a fresh capture, look for unexpected packets, find the destination MAC address of the unexpected packet, and look in the cam of the switch to see if it is there. If the destination MAC is not in the cam then I would expect it to be flooded to all ports.

HTH

Rick

New Member

Re: Routing on 6509

the 256 vlan has a firewall with the .4 network behind it... the majority of traffic I see is stuff coming from that firewall.. from the .4 network... there is absolutely no return traffic !!!

So it's all one way... I'm checking some of the stuff you had asked about... it's curiousity at this point...

98
Views
0
Helpful
5
Replies
CreatePlease to create content