[j-nsp] ARP Table Timer vs. MAC Table Timer on Juniper

Gert Doering gert at greenie.muc.de
Mon Dec 11 11:32:49 EST 2017


Hi,

On Mon, Dec 11, 2017 at 05:27:11PM +0100, Karl Gerhard wrote:
> This seems to be a rather stupid default to me since expired MAC table entries (in conjuction with still existing ARP table entries) will cause Unknown Unicast packets to be flooded. We've been bitten by this because we did VRRP between two routers and two switches and traffic flow was asymmetric so one switch forgot the MAC addresses and flooded Unknown Unicasts.

Yeah, same thing on Cisco (different values, but same thing, MAC timers
way lower than ARP timers).

We work around this by ensuring hosts broadcast something every minute
(on unix boxes, running rwhod).

gert
-- 
now what should I write here...

Gert Doering - Munich, Germany                             gert at greenie.muc.de
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 630 bytes
Desc: not available
URL: <https://puck.nether.net/pipermail/juniper-nsp/attachments/20171211/5a14da04/attachment.sig>


More information about the juniper-nsp mailing list