Re: [f-nsp] Layer 2 packet forwarded in hardware(PP)

Eldon Koyle <[email protected]> Thu, 13 Sep 2018 08:23:06 -0600
Newsgroups gmane.network.nsp.foundry
Message-ID <CAKJRP3RcccvkioyKr7tO5f=+fbwjWcu_TR0ZNPZzKV_J8Bw7jg@mail.gmail.com>
Have you tried running dm pstat?  It can sometimes help identify the type
of traffic causing issues.  First run is a throwaway, it shows counts since
the previous run.

I think dynamic arp inspection can still run without any L3 configured.  It
is also possible that you have some kind of hardware entry that is
flip-flopping (duplicate MAC, some kind of multicast, etc.) or a lot of
broadcast/unknown unicast traffic.  Also, multicast is treated like
broadcast if you don't enable igmp snooping, which will eat CPU.

It would take an insane amount of ARP traffic to generate that much load on
the lp cpu, so that may be a red herring.

-- 
Eldon




On Thu, Sep 13, 2018, 05:58 Franz Georg Köhler <[email protected]> wrote:

> On Mo, Sep 10, 2018 at 08:22:19 -0600, Eldon Koyle <
> [email protected]> wrote:
> > You can enable cpu-protection on the vlan IIRC, I don't remember all the
> > caveats; definitely look at the manual before enabling.
>
> Also with CPU protection enabled on the VLAN I see packets hitting the
> CPU with "reason: Layer 2 packet forwarded in hardware(PP)".
>
> Therefore, I still wonder what does that mean exactly: Why is the packet
> hitting CPU if it is being forwarded in hardware?
>
>
>
> _______________________________________________
> foundry-nsp mailing list
> [email protected]
> http://puck.nether.net/mailman/listinfo/foundry-nsp
>

_______________________________________________
foundry-nsp mailing list
[email protected]
http://puck.nether.net/mailman/listinfo/foundry-nsp