Solved

ARP Broadcast Storms with HP 1910 switches

Posted on 2014-11-19
6
892 Views
Last Modified: 2014-11-19
Hello,

We’ve started deploying HP 1910 8 port switches to isolated areas of our network, because they are reasonably priced. Our core devices are HP 28xx series switches and Cisco 29xx series switches.

We’ve noticed that the HP 1910 units aggressively broadcast ARP requests for everything in their ARP tables. We have about 30 of the 1910’s now, and they’re responsible for 90% of our internal network traffic—2,000-4,000 packets per second of nothing but ARP requests.

It does calm down every now and then—you might get 30 seconds while nothing is transmitting, then it starts up again. Watching an individual switch’s traffic, they seem to chatter every 2-3 minutes, which roughly matches the ARP ageing default. The problem is, for an ARP table with 100 entries, it might send 20k ARP requests!

Does anyone have any ideas on how to make these calm down, or at least make them act like our Cisco and 28xx series switches, that don’t have this kind of flooding issue?
0
Comment
Question by:MarktheNerd
  • 3
  • 3
6 Comments
 
LVL 26

Expert Comment

by:Predrag Jovic
ID: 40453039
That's not switch issue. That's network design problem.
a) you need to reduce number of hosts per VLAN
b) maybe there's a network loop
c) you need to set ports for host to portfast to reduce broadcast (this is optional and short term solution)
0
 

Author Comment

by:MarktheNerd
ID: 40453044
So even though only one specific switch model has the issue, it's a network design problem? Why wouldn't the other switches be displaying the same behavior, if it was a design issue?
0
 
LVL 26

Assisted Solution

by:Predrag Jovic
Predrag Jovic earned 500 total points
ID: 40453122
Switch by itself, without any reason don't produce such traffic (except broken ones - but broken is reason, isn't it?). If there is network loop that could explain that behavior. Or if ports for hosts are not in portfast mode.
First - network loop is self explanatory.
Second - every time someone turn on PC (if portfast is not issued to port) STP  start panicking  when receive TCN (topology change notification) - there's a change in network, and side effect of that is that switch reduces time for relearning MAC address in MAC address table from default 300 second to 15 seconds.
So, this can induct broadcast storms in larger network without any other design problem.
0
Better Security Awareness With Threat Intelligence

See how one of the leading financial services organizations uses Recorded Future as part of a holistic threat intelligence program to promote security awareness and proactively and efficiently identify threats.

 

Author Comment

by:MarktheNerd
ID: 40453300
I think the STP thing is probably on the right path. I haven't been able to figure out how to do portfast (Portfast is Cisco, this is HP, so I'm trying to find the equivalent), but if I disable STP on a given switch, the broadcasts stop immediately. I'll see if I can figure out the specific settings to keep it from happening now.
0
 
LVL 26

Accepted Solution

by:
Predrag Jovic earned 500 total points
ID: 40453313
HP paralel to portfast is edge-port, command is
Switch(config)#spanning-tree [portlist] edge-port
0
 

Author Comment

by:MarktheNerd
ID: 40453861
It's still being a bit odd, but at least we know the root cause now. Disabling STP is the Band-Aid we need until we can figure out the specific STP configuration we need. Thanks, Predrag!!!
0

Featured Post

Threat Intelligence Starter Resources

Integrating threat intelligence can be challenging, and not all companies are ready. These resources can help you build awareness and prepare for defense.

Join & Write a Comment

Quality of Service (QoS) options are nearly endless when it comes to networks today. This article is merely one example of how it can be handled in a hub-n-spoke design using a 3-tier configuration.
Configuring network clients can be a chore, especially if there are a large number of them or a lot of itinerant users.  DHCP dynamically manages this process, much to the relief of users and administrators alike!
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

706 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now