Go Back   Velocity Reviews > Newsgroups > Cisco
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read


Reply

Cisco - Ghost MAC address Part II

 
Thread Tools Search this Thread
Old 07-17-2006, 07:14 PM   #1
John Oliver
 
Posts: n/a
Default Ghost MAC address Part II

I have three Cisco 2970s... 2970_1 has a trunk to 2970_2 vi Gi0/24 on
both, and a trunk to 2970_3 on Gi0/4 (Gi0/2 on 2970_3)

I'm seeing lots of ARP broadcasts for an IP I do not use from a MAC
address that isn't one of mine. I'm trying to hunt down where that
address is with no luck:

2970_1 can't decide if it's on Gi0/24 or Gi0/4:

2970_1#sh mac-address-table address 000c.764e.04c8
Mac Address Table
-------------------------------------------

Vlan Mac Address Type Ports
---- ----------- -------- -----
3 000c.764e.04c8 DYNAMIC Gi0/24
Total Mac Addresses for this criterion: 1
2970_1#sh mac-address-table address 000c.764e.04c8
Mac Address Table
-------------------------------------------

Vlan Mac Address Type Ports
---- ----------- -------- -----
3 000c.764e.04c8 DYNAMIC Gi0/4
Total Mac Addresses for this criterion: 1
2970_1#sh mac-address-table address 000c.764e.04c8
Mac Address Table
-------------------------------------------

Vlan Mac Address Type Ports
---- ----------- -------- -----
3 000c.764e.04c8 DYNAMIC Gi0/24
Total Mac Addresses for this criterion: 1

As mentioned above, Gi0/4 is a trunk to 2970_3 and Gi0/24 is a trunk to
2970_2



2970_2 thinks it might be on Gi0/3, Gi0/7, or Gi0/24:

2970_2#sh mac-address-table address 000c.764e.04c8
Mac Address Table
-------------------------------------------

Vlan Mac Address Type Ports
---- ----------- -------- -----
3 000c.764e.04c8 DYNAMIC Gi0/3
Total Mac Addresses for this criterion: 1
2970_2#sh mac-address-table address 000c.764e.04c8
Mac Address Table
-------------------------------------------

Vlan Mac Address Type Ports
---- ----------- -------- -----
3 000c.764e.04c8 DYNAMIC Gi0/24
Total Mac Addresses for this criterion: 1
2970_2#sh mac-address-table address 000c.764e.04c8
Mac Address Table
-------------------------------------------

Vlan Mac Address Type Ports
---- ----------- -------- -----
3 000c.764e.04c8 DYNAMIC Gi0/7
Total Mac Addresses for this criterion: 1

Gi0/24 is a trunk to 2970_1, Gi0/3 is down with nothing connected to it,
and Gi0/7 is a web server with one connected interface that does *not*
have a hardware address of 000c.764e.04c8


2970_3 can't tell if it's on Gi0/2, Gi0/3, or Gi0/4:

2970_3#sh mac-address-table address 000c.764e.04c8
Mac Address Table
-------------------------------------------

Vlan Mac Address Type Ports
---- ----------- -------- -----
3 000c.764e.04c8 DYNAMIC Gi0/2
Total Mac Addresses for this criterion: 1
2970_3#sh mac-address-table address 000c.764e.04c8
Mac Address Table
-------------------------------------------

Vlan Mac Address Type Ports
---- ----------- -------- -----
3 000c.764e.04c8 DYNAMIC Gi0/3
Total Mac Addresses for this criterion: 1
2970_3#sh mac-address-table address 000c.764e.04c8
Mac Address Table
-------------------------------------------

Vlan Mac Address Type Ports
---- ----------- -------- -----
3 000c.764e.04c8 DYNAMIC Gi0/4
Total Mac Addresses for this criterion: 1

Gi0/2 is a trunk to 2970_1, and Gi0/3 and Gi0/4 are connected to two
name servers, neither of which have a hardware address of 000c.764e.04c8


WHAT THE HELL IS GOING ON??? How can a hardware address be dancing
around like that, especially when it doesn't freaking exist? If I keep
doing sh mac-address-table address 000c.764e.04c8 over and over again,
the answers randomly dance between the various values I've shown above.


--
* John Oliver http://www.john-oliver.net/ *
  Reply With Quote
Old 07-17-2006, 09:28 PM   #2
Merv
 
Posts: n/a
Default Re: Ghost MAC address Part II


1. What is the version of software running on each of the three 2970?

2. Is VLAN 3 the only VLAN ( beside 1 ) configured on the three 2970's?

3. What operating system are used on the name servers and the web
server

4. Have you capture any of the ARP requests/replies? If so what is the
source IP address?


This might be caused by one of the ARP virus programs

  Reply With Quote
Old 07-17-2006, 11:37 PM   #3
John Oliver
 
Posts: n/a
Default Re: Ghost MAC address Part II

On 17 Jul 2006 14:28:27 -0700, Merv wrote:
>
> 1. What is the version of software running on each of the three 2970?


2970_1#sh version
Cisco IOS Software, C2970 Software (C2970-LANBASE-M), Version
12.2(25)SEB4, RELEASE SOFTWARE (fc1)

2970_2#sh version
Cisco IOS Software, C2970 Software (C2970-LANBASE-M), Version
12.2(25)SEB4, RELEASE SOFTWARE (fc1)

2970_3#sh version
Cisco IOS Software, C2970 Software (C2970-LANBASE-M), Version
12.2(25)SEB4, RELEASE SOFTWARE (fc1)

> 2. Is VLAN 3 the only VLAN ( beside 1 ) configured on the three 2970's?


2970_1#sh vlan

VLAN Name Status Ports
---- -------------------------------- ---------
-------------------------------
1 default active Gi0/1, Gi0/3, Gi0/5,
Gi0/8
Gi0/10, Gi0/11, Gi0/13,
Gi0/14
Gi0/15, Gi0/16, Gi0/17,
Gi0/18
Gi0/19, Gi0/20, Gi0/21,
Gi0/22
Gi0/23
2 Outside active
3 DMZ active Gi0/2, Gi0/6, Gi0/7,
Gi0/9
Gi0/12
4 Secure active
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup

VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1
Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------
------
1 enet 100001 1500 - - - - - 0
0
2 enet 100002 1500 - - - - - 0
0
3 enet 100003 1500 - - - - - 0
0
4 enet 100004 1500 - - - - - 0
0
1002 fddi 101002 1500 - - - - - 0
0
1003 tr 101003 1500 - - - - - 0
0
1004 fdnet 101004 1500 - - - ieee - 0
0
1005 trnet 101005 1500 - - - ibm - 0
0

Remote SPAN VLANs
------------------------------------------------------------------------------


Primary Secondary Type Ports
------- --------- -----------------
------------------------------------------

2970_2#sh vlan

VLAN Name Status Ports
---- -------------------------------- ---------
-------------------------------
1 default active Gi0/1, Gi0/6, Gi0/8,
Gi0/9
Gi0/10, Gi0/12, Gi0/19,
Gi0/20
Gi0/21
2 Outside active
3 DMZ active Gi0/3, Gi0/4, Gi0/5,
Gi0/7
Gi0/11, Gi0/13, Gi0/14,
Gi0/15
Gi0/16, Gi0/17, Gi0/18,
Gi0/22
Gi0/23
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup

VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1
Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------
------
1 enet 100001 1500 - - - - - 0
0
2 enet 100002 1500 - - - - - 0
0
3 enet 100003 1500 - - - - - 0
0
1002 fddi 101002 1500 - - - - - 0
0
1003 tr 101003 1500 - - - - - 0
0
1004 fdnet 101004 1500 - - - ieee - 0
0
1005 trnet 101005 1500 - - - ibm - 0
0

Remote SPAN VLANs
------------------------------------------------------------------------------


Primary Secondary Type Ports
------- --------- -----------------
------------------------------------------

2970_3#sh vlan

VLAN Name Status Ports
---- -------------------------------- ---------
-------------------------------
1 default active
3 VLAN0003 active Gi0/1, Gi0/3, Gi0/4,
Gi0/5
Gi0/6, Gi0/7, Gi0/8,
Gi0/9
Gi0/10, Gi0/11, Gi0/12,
Gi0/13
Gi0/14, Gi0/15, Gi0/16,
Gi0/17
Gi0/18, Gi0/19, Gi0/20,
Gi0/21
Gi0/22, Gi0/23, Gi0/24
1002 fddi-default act/unsup
1003 token-ring-default act/unsup
1004 fddinet-default act/unsup
1005 trnet-default act/unsup

VLAN Type SAID MTU Parent RingNo BridgeNo Stp BrdgMode Trans1
Trans2
---- ----- ---------- ----- ------ ------ -------- ---- -------- ------
------
1 enet 100001 1500 - - - - - 0
0
3 enet 100003 1500 - - - - - 0
0
1002 fddi 101002 1500 - - - - - 0
0
1003 tr 101003 1500 - - - - - 0
0
1004 fdnet 101004 1500 - - - ieee - 0
0
1005 trnet 101005 1500 - - - ibm - 0
0

Remote SPAN VLANs
------------------------------------------------------------------------------


Primary Secondary Type Ports
------- --------- -----------------
------------------------------------------

> 3. What operating system are used on the name servers and the web
> server


All Linux.

> 4. Have you capture any of the ARP requests/replies? If so what is the
> source IP address?


16:36:52.525936 00:0c:76:4e:04:c8 > Broadcast, ethertype ARP (0x0806),
length 60: arp who-has 172.16.100.103 (Broadcast) tell 172.16.100.103

--
* John Oliver http://www.john-oliver.net/ *
  Reply With Quote
Old 07-18-2006, 10:59 AM   #4
Merv
 
Posts: n/a
Default Re: Ghost MAC address Part II

If the offending device is continuously ARPing, then I would suggest
setup a monitoring port connected to a PC running Ethereal.

Since the MAC address only show up on the trunk port of 2970_1, it
would seem that the offending device is probably not connected to that
switch.

So start with 2970_2, set up a monitoring port and one by one monitor
the traffic from each port ( one port at a time). Hopefully this way
you can find the device that is generating the ARP request for
172.16.100.103. The decode posted looks like a device sending a
gratuitous ARP. If not found on 2970_2 repeat process on 2970_3.

  Reply With Quote
Old 07-18-2006, 03:29 PM   #5
Make
 
Posts: n/a
Default Re: Ghost MAC address Part II

The Ethereal network protocol analyzer has changed its name to Wireshark.
http://www.wireshark.org/

> If the offending device is continuously ARPing, then I would suggest
> setup a monitoring port connected to a PC running Ethereal.



  Reply With Quote
Old 07-18-2006, 11:50 PM   #6
anybody43@hotmail.com
 
Posts: n/a
Default Re: Ghost MAC address Part II


Make wrote:
> The Ethereal network protocol analyzer has changed its name to Wireshark.
> http://www.wireshark.org/
>
> > If the offending device is continuously ARPing, then I would suggest
> > setup a monitoring port connected to a PC running Ethereal.


Strangely enough there is no mention of this change on
www.ethereal.com.

Why might that be? "Shark" seems to be the critical part here.
Would (on the) Make please go away, is my first reaction.

  Reply With Quote
Old 07-20-2006, 05:51 PM   #7
Make
 
Posts: n/a
Default Re: Ghost MAC address Part II

> Strangely enough there is no mention of this change on
> www.ethereal.com.


Try link http://www.ethereal.com/download.html ja select Windows SourceForge
and you get
http://sourceforge.net/project/showf...p?group_id=255
and there it is said:
Wireshark (formerly Ethereal) is a network protocol analyzer for Unix and
Windows.


  Reply With Quote
Old 07-20-2006, 10:10 PM   #8
Merv
 
Posts: n/a
Default Re: Ghost MAC address Part II


any change of sticking the the OP's issue ???

  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Computer Security aldrich.chappel.com.use@gmail.com A+ Certification 0 11-27-2007 01:11 AM
Classic Original Broadcasts Trading List - Updated ( w/o/c ) porkys1982@sbcglobal.net DVD Video 0 12-05-2005 02:38 AM
Classic Original Broadcasts Trading List - Updated ( w/o/c ) porkys1982@sbcglobal.net DVD Video 0 11-19-2005 03:46 PM
Original Airings : The A-Team , M*A*S*H , Taxi , Barney Miller , WKRP porkys1982@sbcglobal.net DVD Video 0 08-15-2005 02:09 AM
How to make a bootable Ghost CD with Norton Ghost 2003 van A+ Certification 2 10-14-2003 07:53 PM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47