Solved

PIX 515e ARP collisions

Posted on 2004-10-06
7
13,975 Views
Last Modified: 2013-11-16
In my SYSLog I am seeing a lot of events:
%PIX-4-405001: Received ARP request collision from 10.36.81.2/000d.56b8.ed59 on interface inside
%PIX-4-405001: Received ARP request collision from 10.36.81.2/000d.56b8.ed57 on interface inside
%PIX-4-405001: Received ARP request collision from 10.36.81.2/000d.56b8.ed59 on interface inside
%PIX-4-405001: Received ARP request collision from 10.36.81.2/000d.56b8.ed57 on interface inside
%PIX-4-405001: Received ARP request collision from 10.36.81.2/000b.db92.1a1e on interface inside
%PIX-4-405001: Received ARP request collision from 10.36.81.2/000b.db92.1a1f on interface inside

--after looking at the packets I was able to determine that the MAC addresses are two servers using dual Nics (teamed for Load Balance). I have other servers with this same set up but I am not seeing events for those servers.

--According to Cisco: Explanation    The firewall received an ARP packet, and the MAC address in the packet differs from the ARP cache entry.
Recommended Action    This traffic might be legitimate, or it might indicate that an ARP poisoning attack is in progress. Check the source MAC address to determine where the packets are coming from and check to see if it belongs to a valid host.

Those MAC addresses are valid hosts. Is this a configuration issue or anything to be concerned with? Thanks in advance.

0
Comment
Question by:gl_3n2k3
  • 3
  • 3
7 Comments
 
LVL 79

Accepted Solution

by:
lrmoore earned 400 total points
ID: 12240493
What kind of switch are you connecting to?
If you have other server NIC teams configured the same, then I would investigate why this one is behaving differently. It could have a serious impact on the performance of that NIC team..


0
 

Author Comment

by:gl_3n2k3
ID: 12242241
The server (both of them) are plugged into Dell 5224. The other NIC teamed servers are plugged into the same  switch, DELL 5224. The Core switch is Cisco 3550. I am only see those two servers logging this event.

After hours I am going to change one of them to a single nic to see if the events stop.

NIC configuration is nothing out of the ordinary. Static IP, Static DNS, WINs, etc.
0
 
LVL 12

Expert Comment

by:mburdick
ID: 12243905
This is most likely caused by an incompatability between the NIC's and the switch that they are connected to in supporting the "teaming". If the Dell switch doesn't support PAgP, or doesn't support the same version as the software running the NIC's, you're going to have these kinds of issues. There may be little that you can do about it except change the switch they're connected to and possibly update your teaming software.
0
VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

 

Author Comment

by:gl_3n2k3
ID: 12249884
I was able to resolve this issue. I removed the team on one server and the events stopped logging. I compared the drivers between servers not logging the event to the ones that do and found some minor revision version differences.  I updated the drivers for the NICs and Control suite on the server stilll using NIC teaming and the events stop being logged. I also cleared the routing tables of all gateway entries because there appeared to be a bad entry. I  For those of you that may be interested.

Broadcom NetXreme updated drivers for both NICs from Microsoft 2.91.0.0 to Broadcom 7.80.0.0
BASP Virtual adapter updated from 6.0.1.0 to 6.0.9.0
Control Suite updated from 6.03 to 7.6.7

The logs did not indicate any ARP collisions after this.

Thanks for the responses!



0
 
LVL 79

Expert Comment

by:lrmoore
ID: 12250211
Good work!
How do you want to handle closing of this Question?
0
 

Author Comment

by:gl_3n2k3
ID: 12250755
I am giving you the points even though there wasnt an exact "fix" offered. I posted my fix in case someone else encounters a similar issue. Your comment to investigate the NICs lead to the eventually resolution. Thanks!!

I have another PIX log the is occuring with great frequency and was going to post it to see if any other's had experienced this (should I start a new post?). I havent started to troubleshoot it yet and may not even be an issue.

%PIX-2-106001: Inbound TCP connection denied from {external IP}/80 to 111.211.111.211/18355 flags PSH ACK  on interface outside 2004-10-05 15:44:59
%PIX-2-106001: Inbound TCP connection denied from {external IP}/80 to 111.211.111.211/18355 flags ACK  on interface outside

Per Cisco Error Event description:
Explanation   This is a connection-related message. This message occurs when an attempt to connect to an inside address is denied by your security policy. Possible TCP_flags values correspond to the flags in the TCP header that were present when the connection was denied. For example, a TCP packet arrived for which no connection state exists in the PIX Firewall, and it was dropped. The TCP_flags in this packet are FIN,ACK.

Action None required.

--- I dont think this is an issue but if its happening at great frequency then I may need to tweek some configurations.
0
 
LVL 79

Expert Comment

by:lrmoore
ID: 12252234
I don't think it's an issue. Whenever you open a web page and quickly click off to another link or something before the page fully loads, you'll see these type messages. You've closed the connection request to the initial page, but the graphics and things are still coming from the original request. They just get dropped...
0

Featured Post

Networking for the Cloud Era

Join Microsoft and Riverbed for a discussion and demonstration of enhancements to SteelConnect:
-One-click orchestration and cloud connectivity in Azure environments
-Tight integration of SD-WAN and WAN optimization capabilities
-Scalability and resiliency equal to a data center

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Monitor Internet Edge Router behind Firewall 2 22
NAT Public IP through a VPN 17 70
Cisco Aironet 1140: setting up basic SSID 12 35
ISP has issued 5 static IP addresses 4 28
Overview The Cisco PIX 501, PIX 506e, ASA 5505 and ASA 5510 (most if not all of this information will be relevant to the PIX 515e but I do not have a working configuration handy to verify the validity) are primarily used within small to medium busi…
I recently attended Cisco Live! in Las Vegas, a conference that boasted over 28,000 techies in attendance, and a week of hands-on learning hosted by a solid partner with which Concerto goes to market.  Every year, Cisco displays cutting-edge technol…
Both in life and business – not all partnerships are created equal. As the demand for cloud services increases, so do the number of self-proclaimed cloud partners. Asking the right questions up front in the partnership, will enable both parties …
Both in life and business – not all partnerships are created equal. Spend 30 short minutes with us to learn:   • Key questions to ask when considering a partnership to accelerate your business into the cloud • Pitfalls and mistakes other partners…

830 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question