Reset Search
 

 

Article

udp traffic flooded due to unresolved arp after removed device

« Go Back

Information

 
Titleudp traffic flooded due to unresolved arp after removed device
Symptoms
  • the following errors reported in the syslog:
 
<167>Mar 30 17:23:06 x.x.x.x  RtrArpProc[3]ARP/ND entry removed.  IP Address: x.x.x.x Type: Dynamic State Incomplete

<167>Mar 30 17:23:07 10.8.10.102 RtrArpProc[3]Sending ARP packet: ff:ff:ff:ff:ff:ff - 00:1f:45:9e:73:41 - 81006012 - Op: 1 - Sender: x.x.x.x  00:1f:45:9e:73:41 - Target: x.x.x.x 00:00:00:00:00:00
  • High CPU - Switch Packet Processing task
Environment
  • S-Series
  • K-Series
  • N-Series
  • All Firmware
  • ARP
Cause
devices sending constant UDP traffic to collector server that is not responding - .constant arping as doesnt have the mac address
Resolution
investigate the ip addresses reported in the syslog errors to find out why the arps are being sent for device that is unlearned constantly. 
In one case a device was still sending syslog UDP to a collector server that had been decommissioned.
Additional notes

Feedback

 

Was this article helpful?


   

Feedback

Please tell us how we can make this article more useful.

Characters Remaining: 255