Solved

Bad arp entry help

Posted on 2014-09-09
8
273 Views
Last Modified: 2014-09-15
Hello EE,

One server "storage" gets a bad arp entry in the local arp cache for all users on the network and therefore users cannot connect . Once I delete the arp entry locally on a client pc for "storage" , then receive the correct ip to mac entry it works . The "bad mac" entry for storage  appears to be the cisco pix, I cleared the arp cache there as it did have a bad entry for "storage" . The pix arp cache is correct, however, users still receive a bad arp entry for "storage" , again, it is the cisco pix mac address. So again , have to use arp -d and the storage ip to get it to work again .

Any ideas?
0
Comment
Question by:davesnb
  • 4
  • 3
8 Comments
 
LVL 32

Expert Comment

by:harbor235
ID: 40314388
Do they share the same IP address? By bad you mean its not the mac of the storage device but the MAC of the PIX.

harbor235 ;}
0
 

Author Comment

by:davesnb
ID: 40314408
There is no ip conflicts on the network . There is an incorrect arp entry that occurs locally on al client pcs , the mac address is the mac address which is  the pix , when it should be the mac address of storage box. This results in users unable to connect to storage box.
0
 
LVL 32

Accepted Solution

by:
harbor235 earned 500 total points
ID: 40314566
So I assume the default gateway is the PIX? in that case your arp tables should have an entry for the PIX. That being said
is the default GW IP associated with the bad entry?

Can you post your arp table (arp -a) and the result of "netstat -rn" for UNIX or route print on windows


harbor235 ;}
0
 
LVL 32

Expert Comment

by:harbor235
ID: 40314580
The other possibility is malicious code being executed by some system on your network to redirect traffic. I would put a sniffer on the network and locate the source of the bad arp entries if my other questions are not applicable.


harbor235 ;}
0
How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

 
LVL 79

Expert Comment

by:lrmoore
ID: 40320815
Disable proxyarp in the pix inside interface
0
 

Author Comment

by:davesnb
ID: 40321033
Ok will try those suggestions thanks
0
 

Author Comment

by:davesnb
ID: 40323207
By unteaming the nics on the "storage" box and using the good nic as per the arp table when connections were successful , this seems to have resolved the issue.
0
 

Author Closing Comment

by:davesnb
ID: 40323210
Arp table was useful in tracking down the  problematic nic card .
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Suggested Solutions

The Need In an Active Directory enviroment, the PDC emulator provide time synchronization for the domain. This is important since Active Directory uses Kerberos for authentication.  By default, if the time difference between systems is off by more …
Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now