Solved

Windows 2003 ARP cache contains default gateway MAC for all IP's

Posted on 2013-01-30
8
1,452 Views
Last Modified: 2013-02-20
Windows 2003 server with assigned static IP and default GW is unable to route directly to other servers on the exact same subnet / IP range. All Tracert results always use the Default GW as the 1st hop then the destination on the 2nd when the expected behavior should be a direct find on the 1st.

The ARP cache contains entries for all IP's but the corresponding MAC is always the MAC for the default GW

The contents of the ARP cache updates dynamically - no static entries

As you can see from the screen show ARP -a show no entry for 10.2.171.10
the tracert performed directly after finds 10.2.171.10 on the very first hop
immediately after the tracert ARP-a shows the entry in the ARP table but with the GW MAC
The next tracert then goes via the GW and not like the previous trace which went directly on the 1st hop

I've tried a static route in the routing table - this doesn't help
I've also disabled dynamic update of ARP - not quite sure if that work
I've also tried entering a manual entry in the ARP table with the IP / MAC but this causes the Trace route to fail

The servers are all on the same address subnet plugged into a switch which acts as the GW (10.2.171.254)
As all servers are on the same broadcast network surely they should be reached on the 1st hop.
Not sure why the ARP entries contain the MAC of the GW

Any idea on how i can resolve this so all traffic would go directly to the specific IP / MAC rather than via the GW?

MAC of the default GW in this case ends in d8
You would notice in the screen grab that 10.2.171.40 has a MAC entry which isn't the gateway. I have no idea why this is - I've confirmed that the TCP/IP config on this windows server is exactly the same as the other servers.
ARP.PNG
0
Comment
Question by:Eric
  • 4
  • 2
  • 2
8 Comments
 
LVL 20

Expert Comment

by:agonza07
Comment Utility
send a screenshot of "ipconfig /all" from that server.
0
 

Author Comment

by:Eric
Comment Utility
Thanks, please find attached - ipconfig
IPCONFG.PNG
0
 
LVL 20

Expert Comment

by:agonza07
Comment Utility
That is weird.

What kind of switch are you using.

Also, please verify the subnet masks of your other servers, just to make sure they are on the same subnet.

Finally, can you ping the other servers when you manually put in an arp entry?
0
 
LVL 10

Expert Comment

by:mat1458
Comment Utility
Your default gateway issues some weird kind of proxy arp. You should either disable this function in the gateway if you can live without it or go into the bug list of the device to find out why it proxies local arp requests. What brand/type of device is your default gateway?
0
Find Ransomware Secrets With All-Source Analysis

Ransomware has become a major concern for organizations; its prevalence has grown due to past successes achieved by threat actors. While each ransomware variant is different, we’ve seen some common tactics and trends used among the authors of the malware.

 

Author Comment

by:Eric
Comment Utility
Hi agonza07,  The switches are Dell 6224 with VLAN routing, the switch stack is the default GW for all the VLANS, although that should not affect things as the route I need is within a single VLAN.  I have verified all subnets masks are the same.  Ping doesn't work if I add static arp to the servers.
0
 
LVL 10

Accepted Solution

by:
mat1458 earned 495 total points
Comment Utility
Can you do a "show ip interface vlan x" for the specific VLAN and post the output? Especially interesting would be the setting of ip local proxy-arp. I see that there is such a feature in your Dell switch, however apart from monitoring traffic I do not yet see a reason to use it. In the manual I have not found any explanation on how to switch it on or off but I'd try a "no ip proxy-arp local" on the VLAN interface.
0
 

Author Comment

by:Eric
Comment Utility
Hi

This is the out put from show ip

Routing Interface Status....................... Up
Primary IP Address............................. 10.2.171.254/255.255.255.0
Routing Mode................................... Enable
Administrative Mode............................ Enable
Forward Net Directed Broadcasts................ Disable
Proxy ARP...................................... Enable
Local Proxy ARP................................ Enable
Active State................................... Active
MAC Address.................................... 0023.AEC4.D9D8
Encapsulation Type............................. Ethernet
IP MTU......................................... 1500
Bandwidth...................................... 10000 kbps
Destination Unreachables....................... Enabled
ICMP Redirects................................. Enabled

ip local proxy-arp is now off and tracert produces the same result with the extra entry of the switch.
0
 

Author Closing Comment

by:Eric
Comment Utility
Thank you to all who helped with this, the answer was in the local proxy-arp, turning it off didn't have an immediate effect hence the response but later the cache must have cleared and all is working correctly now - again thanks for the help.
0

Featured Post

Highfive Gives IT Their Time Back

Highfive is so simple that setting up every meeting room takes just minutes and every employee will be able to start or join a call from any room with ease. Never be called into a meeting just to get it started again. This is how video conferencing should work!

Join & Write a Comment

Learn about cloud computing and its benefits for small business owners.
Let’s list some of the technologies that enable smooth teleworking. 
Here's a very brief overview of the methods PRTG Network Monitor (https://www.paessler.com/prtg) offers for monitoring bandwidth, to help you decide which methods you´d like to investigate in more detail.  The methods are covered in more detail in o…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now