Re: [OpenIndiana-discuss] arp response tuning for IP Source Guard

2017-01-24 Thread James Carlson via openindiana-discuss
On 01/24/17 14:45, Tim Mooney wrote: > While testing and debugging, we also discovered that some of the > list speculation from earlier in the thread turned out to be correct: > we could pacify the Cisco switch if I set the following two ARP-related > tunables: > > sudo ndd -set /dev/arp arp_d

Re: [OpenIndiana-discuss] arp response tuning for IP Source Guard

2017-01-24 Thread Tim Mooney
In regard to: Re: [OpenIndiana-discuss] arp response tuning for IP Source...: All- Here's some more information on this thread I started related to Cisco's IP Source Guard feature (with ARP probes) and intermittent packet loss from OI. Our network engineers opened a case with Cisco, and Cisco e

Re: [OpenIndiana-discuss] arp response tuning for IP Source Guard

2017-01-06 Thread Tim Mooney
for IPv6. That's with the IP Source Guard enabled. Thanks, Tim -Oorspronkelijk bericht- Van: Tim Mooney [mailto:tim.moo...@ndsu.edu] Verzonden: vrijdag 6 januari 2017 0:50 Aan: openindiana-discuss@openindiana.org Onderwerp: Re: [OpenIndiana-discuss] arp response tuning for IP S

Re: [OpenIndiana-discuss] arp response tuning for IP Source Guard

2017-01-06 Thread Tim Mooney
In regard to: Re: [OpenIndiana-discuss] arp response tuning for IP Source...: Have you run any tcpdump / anything to check what exactly happens? I tried 'sudo tcpdump arp', but whenever I run tcpdump, all I get is: tcpdump: unknown data link type 524288 Our network engineers indicate

Re: [OpenIndiana-discuss] arp response tuning for IP Source Guard

2017-01-06 Thread James Carlson via openindiana-discuss
On 01/05/17 18:49, Tim Mooney wrote: > In regard to: Re: [OpenIndiana-discuss] arp response tuning for IP > Source...: >> It would be great to see the syslog messages and (if possible) a packet >> trace showing what's going on. In general, if the system itself is >> directly responsible for these

Re: [OpenIndiana-discuss] arp response tuning for IP Source Guard

2017-01-06 Thread James Carlson via openindiana-discuss
On 01/06/17 08:17, Doug Hughes wrote: > It seems to me that you might be hitting up against "arp_defend_rate" > which by default says that the maximum arps it should be expecting in > one hour is 100. It's he's sending 3 per minute, that's already 180. I > could be wrong. I'd probably try setting t

Re: [OpenIndiana-discuss] arp response tuning for IP Source Guard

2017-01-06 Thread PÁSZTOR György
Hi, "Tim Mooney" írta 2017-01-05 14:37-kor: > > I'm running hipster, updated a few days ago, illumos-b106467 > > Our network engineers recently enabled Cisco's IP Source Guard on the > subnet my workstation is on. The IP Source Guard overview is here: > > > http://www.cisco.com/c/en/us

Re: [OpenIndiana-discuss] arp response tuning for IP Source Guard

2017-01-06 Thread Doug Hughes
h) -Oorspronkelijk bericht- Van: Tim Mooney [mailto:tim.moo...@ndsu.edu] Verzonden: vrijdag 6 januari 2017 0:50 Aan: openindiana-discuss@openindiana.org Onderwerp: Re: [OpenIndiana-discuss] arp response tuning for IP Source Guard In regard to: Re: [OpenIndiana-discuss] arp response tuni

Re: [OpenIndiana-discuss] arp response tuning for IP Source Guard

2017-01-05 Thread the outsider
response tuning for IP Source Guard In regard to: Re: [OpenIndiana-discuss] arp response tuning for IP Source...: > On 01/05/17 15:37, Tim Mooney wrote: >> When that was enabled for the subnet I'm on, my hipster workstation >> and the hipster VirtualBox VM I have both started

Re: [OpenIndiana-discuss] arp response tuning for IP Source Guard

2017-01-05 Thread Tim Mooney
In regard to: Re: [OpenIndiana-discuss] arp response tuning for IP Source...: On 01/05/17 15:37, Tim Mooney wrote: When that was enabled for the subnet I'm on, my hipster workstation and the hipster VirtualBox VM I have both started experiencing packet loss. Talking with the network engineers,

Re: [OpenIndiana-discuss] arp response tuning for IP Source Guard

2017-01-05 Thread James Carlson via openindiana-discuss
On 01/05/17 15:37, Tim Mooney wrote: > When that was enabled for the subnet I'm on, my hipster workstation and > the hipster VirtualBox VM I have both started experiencing packet loss. > Talking with the network engineers, the Cisco switch is sending batches > of 3 ARP probes periodically, and both

[OpenIndiana-discuss] arp response tuning for IP Source Guard

2017-01-05 Thread Tim Mooney
All- I'm running hipster, updated a few days ago, illumos-b106467 Our network engineers recently enabled Cisco's IP Source Guard on the subnet my workstation is on. The IP Source Guard overview is here: http://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst6500/ios/12-2SY/configu