[c-nsp] Useful HSRP feature additions WAS: Rate limiting questions

Dale Shaw dale.shaw+cisco-nsp at gmail.com
Sat Oct 27 18:41:14 EDT 2007


Hi all,

On 10/28/07, Christopher E. Brown <chris.brown at acsalaska.net> wrote:
> 5 min later, the MAC entry times out, but the ARP entries are there for
> another 4hr 55min...  Now we have our layer2 network with no target for
> that MAC and flooding everywhere.

(3hr 55min?)

I was tempted to start a new thread re: this, but since it's on topic
and people-who-know are reading, I decided not to..

There is conflicting advice about the 'correct' fix in this scenario.
The options appear to be:

1. reduce ARP aging timer on a per-interface basis from (4hr) default
to something less than the default MAC aging timer (5 minutes)

2. increase MAC aging timer globally or on a per-VLAN basis from
(5min) default to something equal-to or less-than the default ARP
aging timer (4 hours)

Even Cisco's web site has separate documents that provide conflicting
advice. A search of the list archives reveals differing views. A
recent post in this (or the related) thread suggests low ARP aging
timers are bad things.

Is there an authoritative guide 'out there', or can someone provide a
solution and back it up with the rationale? Perhaps there are pros and
cons to both approaches, but I haven't been able to find these
documented anywhere.

cheers,
Dale


More information about the cisco-nsp mailing list