Reset Search



udp traffic flooded due to unresolved arp after removed device

« Go Back


Titleudp traffic flooded due to unresolved arp after removed device
  • the following errors reported in the syslog:
<167>Mar 30 17:23:06 x.x.x.x  RtrArpProc[3]ARP/ND entry removed.  IP Address: x.x.x.x Type: Dynamic State Incomplete

<167>Mar 30 17:23:07 RtrArpProc[3]Sending ARP packet: ff:ff:ff:ff:ff:ff - 00:1f:45:9e:73:41 - 81006012 - Op: 1 - Sender: x.x.x.x  00:1f:45:9e:73:41 - Target: x.x.x.x 00:00:00:00:00:00
  • High CPU - Switch Packet Processing task
  • S-Series
  • K-Series
  • N-Series
  • All Firmware
  • ARP
devices sending constant UDP traffic to collector server that is not responding - .constant arping as doesnt have the mac address
investigate the ip addresses reported in the syslog errors to find out why the arps are being sent for device that is unlearned constantly. 
In one case a device was still sending syslog UDP to a collector server that had been decommissioned.
Additional notes



Was this article helpful?



Please tell us how we can make this article more useful.

Characters Remaining: 255