Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Cisco: NSP

Is there sticky ARP functionality on Private VLAN in NX-OS

 

 

Cisco nsp RSS feed   Index | Next | Previous | View Threaded


Matt.Stoward at team

Mar 21, 2012, 6:14 PM

Post #1 of 2 (409 views)
Permalink
Is there sticky ARP functionality on Private VLAN in NX-OS

Hi all,

When configuring PVLANs in IOS, the L3 SVIs automatically get sticky ARP turned on and to remove it is quite simple.

In NX-OS things are a little uncertain. It is implied that the behavior is the same but I don't think it actually is. On the Cisco site in http://docwiki.cisco.com/wiki/Cisco_Nexus_7000_Series_NX-OS_Troubleshooting_Guide_--_Troubleshooting_VLANs , and to quote: "Note: We recommend that you enable sticky Address Resolution Protocol (ARP) when you configure private VLANs. ARP entries learned on Layer 3 private VLAN interfaces, or SVIs, are sticky ARP entries. For security reasons, private VLAN port sticky ARP entries do not age out. "

This is the only reference I can find to sticky ARP anywhere (except for a couple of similar looking entries for this like the 1000V). Is this quite possibly an error in documentation? Having sticky ARPs in a big virtualized environment is going to break things for the sever guys and I want to ensure I head this off before it becomes a problem.

Regards,
Matt

_______________________________________________
cisco-nsp mailing list cisco-nsp [at] puck
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/


diosbejgli at gmail

Apr 2, 2012, 3:45 PM

Post #2 of 2 (354 views)
Permalink
Re: Is there sticky ARP functionality on Private VLAN in NX-OS [In reply to]

Hi Matt,

Sticky ARP is not available yet for Nexus series switches. There's an
internal enhancement request opened for supporting "ip sticky-arp" on
NX-OS but it's not yet implemented.

I've removed the incorrect note from the Cisco DocWiki, however note
that it's not the official Cisco Documentation.

Best regards,
Andras

On Thu, Mar 22, 2012 at 2:14 AM, Stoward, Matt
<Matt.Stoward [at] team> wrote:
> Hi all,
>
> When configuring PVLANs in IOS, the L3 SVIs automatically get sticky ARP turned on and to remove it is quite simple.
>
> In NX-OS things are a little uncertain. It is implied that the behavior is the same but I don't think it actually is. On the Cisco site in http://docwiki.cisco.com/wiki/Cisco_Nexus_7000_Series_NX-OS_Troubleshooting_Guide_--_Troubleshooting_VLANs , and to quote: "Note:  We recommend that you enable sticky Address Resolution Protocol (ARP) when you configure private VLANs. ARP entries learned on Layer 3 private VLAN interfaces, or SVIs, are sticky ARP entries. For security reasons, private VLAN port sticky ARP entries do not age out. "
>
> This is the only reference I can find to sticky ARP anywhere (except for a couple of similar looking entries for this like the 1000V). Is this quite possibly an error in documentation? Having sticky ARPs in a big virtualized environment is going to break things for the sever guys and I want to ensure I head this off before it becomes a problem.
>
> Regards,
> Matt
>
> _______________________________________________
> cisco-nsp mailing list  cisco-nsp [at] puck
> https://puck.nether.net/mailman/listinfo/cisco-nsp
> archive at http://puck.nether.net/pipermail/cisco-nsp/

_______________________________________________
cisco-nsp mailing list cisco-nsp [at] puck
https://puck.nether.net/mailman/listinfo/cisco-nsp
archive at http://puck.nether.net/pipermail/cisco-nsp/

Cisco nsp RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.