The Journey of a Network Engineer

May 30 2011   4:35AM GMT

GRE Tunnel ARP entry never times out! – part 2



Posted by: Sulaiman Syed
Tags:
6500
AP
ARP
Cisco
GRE
mn
SUP720
Tunnel
wireless
WLSM

I have been trying to figure out why the APR entries don’t timeout as they should do naturally from the tunnels. As it seems, the natural time of 4hr is not being applied here. For some uknown reason yet. We have opened up a TAC case with Cisco. Roger Nobel (CCIE WIreless#23679) is really helpful and efficient.

So, in our troubleshooting so far, we tested how the MN is associated with AP, is the association with AP remains after MN is disconnected, does the SUP720 maintains a record for this MN. what we found so far is the following.

After the MN is disconnected from AP. The AP will clear the association in less than 1 min. and in another 5 mins this association will be cleared from the SUP720 as well. it can be seen from the following commands

WLAN-CORE-1#show mobility mn ip 10.13.115.150
MN Mac Address  MN IP Address  AP IP Address  Wireless Network-ID  Flags
————–  ————-  ————-  ——————-  —–
b407.f9ea.a941  10.13.115.150  10.254.14.172  8                      F

Flags: D=Dynamic network ID, F=Fresh, G=Grace Period

WLAN-CORE-1#show mobility mn ip 10.13.115.150
MN with ip 10.13.115.150 is not found in database

Now naturally, the ARP entry should stay for 4 hrs (default Cisco). but in our case it says forever! we have ARP entries as old as 10 days without adding any configurations. The command does not even show any timer for timeout as it shows in other physical interfaces.

WLAN-CORE-1#show int gig 5/1
GigabitEthernet5/1 is up, line protocol is up (connected)
Hardware is C6k 1000Mb 802.3, address is 0011.5cb4.c2a4 (bia 0011.5cb4.c2a4)
MTU 1500 bytes, BW 1000000 Kbit, DLY 10 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation ARPA, loopback not set
Keepalive set (10 sec)
Full-duplex, 1000Mb/s, media type is T
input flow-control is off, output flow-control is off
Clock mode is auto
ARP type: ARPA, ARP Timeout 04:00:00

here is how the tunnel interface looks like

WLAN-CORE-1#show int tunnel 1
Tunnel1 is up, line protocol is up
Hardware is Tunnel
Description:
Internet address is X.X.X.253/20
MTU 1514 bytes, BW 1000000 Kbit, DLY 500000 usec,
reliability 255/255, txload 1/255, rxload 1/255
Encapsulation TUNNEL, loopback not set
Keepalive not set
Tunnel source X.X.X.1 (Loopback1), fastswitch TTL 255
Tunnel protocol/transport multi-GRE/IP, key disabled, sequencing disabled
Checksumming of packets disabled, fast tunneling enabled
Last input 00:00:00, output 00:00:01, output hang never
Last clearing of “show interface” counters never
Input queue: 0/75/125/37 (size/max/drops/flushes); Total output drops: 0
Queueing strategy: fifo
Output queue: 0/0 (size/max)
5 minute input rate 318000 bits/sec, 226 packets/sec
5 minute output rate 3458000 bits/sec, 355 packets/sec
L2 Switched: ucast: 0 pkt, 0 bytes – mcast: 0 pkt, 0 bytes
L3 in Switched: ucast: 0 pkt, 0 bytes – mcast: 0 pkt, 0 bytes mcast
L3 out Switched: ucast: 0 pkt, 0 bytes mcast: 2989660 pkt, 922842977 bytes
249194378 packets input, 54362827775 bytes, 0 no buffer
Received 1308901 broadcasts (71327 IP multicasts)
0 runts, 0 giants, 18 throttles
0 input errors, 0 CRC, 0 frame, 0 overrun, 0 ignored, 0 abort
327413145 packets output, 259801658657 bytes, 0 underruns
0 output errors, 0 collisions, 0 interface resets
0 output buffer failures, 0 output buffers swapped out

I would wait for Mr. Roger to come back and see what possible thing is causing this.


 Comment on this Post

 
There was an error processing your information. Please try again later.
Thanks. We'll let you know when a new response is added.
Send me notifications when other members comment.

REGISTER or login:

Forgot Password?
By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Forgot Password

No problem! Submit your e-mail address below. We'll send you an e-mail containing your password.

Your password has been sent to: