[c-nsp] mac flap

Gert Doering gert at greenie.muc.de
Wed Mar 6 04:03:12 EST 2013


Hi,

On Tue, Mar 05, 2013 at 11:25:40PM -0500, harbor235 wrote:
> I hope someone has seen something like this:
> 
>  %SW_MATM-4-MACFLAP_NOTIF: Host 0000.0000.0000 in vlan 111 is flapping
> between port Fa0/15 and port Fa0/8
> 
> 
> Fa0/15 and F0/8 are server ports,the servers connected to the ports are
> sending Ethernet frames destined to the all zero's mac address.

The problem is not sending frames "to" something.  MAC learning works
on frames being sent *from* a given MAC address, so your servers are 
sending packets with a *source* MAC of 0000.0000.0000 - and that hints
at "something on the server is seriously broken", like "the ethernet card
lost it's preprogrammed MAC address" or "your vmware stack doing weird
stuff".

If the servers have otherwise working MAC addresses, this could be some
sort of funky keepalive protocol which should not be using zero source
MACs...

gert
-- 
USENET is *not* the non-clickable part of WWW!
                                                           //www.muc.de/~gert/
Gert Doering - Munich, Germany                             gert at greenie.muc.de
fax: +49-89-35655025                        gert at net.informatik.tu-muenchen.de
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 305 bytes
Desc: not available
URL: <https://puck.nether.net/pipermail/cisco-nsp/attachments/20130306/20e888c7/attachment.sig>


More information about the cisco-nsp mailing list