NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

fredericallaert's avatar
Jun 08, 2020

ARP entry for gateway does not expire

We are using Barracuda firewalls in a cluster configurations. Whenever a failover of the cluster occurs, the ARP entry (incidentally also the default gateway for the switch) on the switch never expires, the switch retains the MAC address of the old unit while the rest of the network picks up on the new MAC of the failover unit. Any ideas why the switch would treat the gateway MAC differently, basically ignoring the ARP timeout (despite having set the ARP timeout to the minimum - 15 seconds)?

7 Replies

  • Retired_Member's avatar
    Retired_Member

    Hi fredericallaert 

     

    Welcome to Community!

     

    Could you please run command 'show arp' and collect the output information?

    In my side, it's work fine when I change ARP Age Time to 60s. You can see after about 60s, the ARP entry(111.1.1.2) is removed success.

     

    Below is my device output info:

     

    (M4300-48XF) #show arp

    Age Time (seconds)............................. 60
    Response Time (seconds)........................ 1
    Retries........................................ 4
    Cache Size..................................... 760
    Dynamic Renew Mode ............................ Disable
    Total Entry Count Current / Peak .............. 2 / 2
    Static Entry Count Configured / Active / Max .. 0 / 0 / 128

    IP Address MAC Address Interface Type Age
    --------------- ----------------- -------------- -------- -----------
    111.1.1.1 8C:3B:AD:6A:9D:0B vlan 1 Local n/a
    111.1.1.2 00:00:4A:52:02:2A vlan 1 Dynamic 0h 0m 17s

    (M4300-48XF) #

    (M4300-48XF) #show arp

    Age Time (seconds)............................. 60
    Response Time (seconds)........................ 1
    Retries........................................ 4
    Cache Size..................................... 760
    Dynamic Renew Mode ............................ Disable
    Total Entry Count Current / Peak .............. 2 / 2
    Static Entry Count Configured / Active / Max .. 0 / 0 / 128

    IP Address MAC Address Interface Type Age
    --------------- ----------------- -------------- -------- -----------
    111.1.1.1 8C:3B:AD:6A:9D:0B vlan 1 Local n/a
    111.1.1.2 00:00:4A:52:02:2A vlan 1 Dynamic 0h 0m 57s

    (M4300-48XF) #show arp

    Age Time (seconds)............................. 60
    Response Time (seconds)........................ 1
    Retries........................................ 4
    Cache Size..................................... 760
    Dynamic Renew Mode ............................ Disable
    Total Entry Count Current / Peak .............. 1 / 2
    Static Entry Count Configured / Active / Max .. 0 / 0 / 128

    IP Address MAC Address Interface Type Age
    --------------- ----------------- -------------- -------- -----------
    111.1.1.1 8C:3B:AD:6A:9D:0B vlan 1 Local n/a

    (M4300-48XF) #

     

    Hope it helps!

     

    Regards,

    Eric

     

     

    • fredericallaert's avatar
      fredericallaert
      Aspirant

      Hi Eric,

       

      Please find the output below. Nothing peculiar to see in the output, but what you can see is that the "Type" field of the IP-address 152.1 comes back as "gateway" in your output it's not BTW) because it's the default gateway address for the switch.

      When the firewall cluster fails over to the secondary unit this MAC address will not expire and keeps trying to reach out to this IP-address on the wrong MAC. Other devices in the network pick up the new MAC address after the 15s expiration, the switch doesn't

       

      IP Address MAC Address Interface Type Age
      --------------- ----------------- -------------- -------- -----------
      192.168.152.1 00:10:F3:86:C4:7C vlan 1 Gateway 0h 0m 3s
      192.168.152.2 00:10:F3:86:C4:7C vlan 1 Dynamic 0h 0m 0s
      192.168.152.3 00:10:F3:8B:A4:5F vlan 1 Dynamic 0h 0m 0s

      • Retired_Member's avatar
        Retired_Member

        fredericallaert 

         

        In your output, I see 152.1 and 152.2 use same MAC address, is it correct?

        What's the IP of  the firewall?

        What's the IP of the Switch?

        Could you please run command 'show mac-addr-table' and collect the output info?

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More