Forum Discussion
Floating IP responds from wrong VLAN/trunk
I have a routing issue I can't seem to figure out the cause of.
I have two trunks defined, T1 on 1.1 and 1.2, and T2 on 1.3 and 1.4.
Both trunks are connected to the same switch (on the same VLAN on the switch).
I have two VLANs tied to the respective trunks, V1 on T1 and V2 on T2.
I have two traffic groups, TG1 and TG2, with masquerade MACs.
I have two routing domains, 0 and 255.
I have local self IPs defined on the respective VLANs, say 10.0.0.3 on V1 and 10.0.255.3%255 on V2.
I have floating self IPs, such as 10.0.0.2 on V1 and TG1, and 10.0.255.2%255 on V2 and TG2.
When I ping 10.0.0.3 and 10.0.255.3 I get proper responses. No problems there.
When I ping 10.0.0.2 I proper responses.
When I ARP 10.0.255.2, it resolves to the MAC of TG2 and the switch it's connected to routes that MAC to T2.
However, when I ping 10.0.255.2 only the first response comes back - but it comes back from T1 and with the MAC of TG1. When the second (and further) ping is sent, it's consequently (due to MAC learning) sent to T1 - which is not accepting it.
Why is the ping response sent back from T1 when the request was sent to T2? Why is the floating IP in V2, TG2 and routing domain 255 not responding from the same interface as it receives the ICMP package on?
2 Replies
- LarsKristensson
Altocumulus
I made a small mistake in the original post. The correct version should be: "but it comes back from T1 and with the MAC of TG2."
Otherwise there would be no problem, just asymmetric routing.
- Shyy
Cirrus
is this a new config? has it worked before?
I suggest if possible to try and shut the port on T1 to see that routing actually works without T1 in the loop.
If it doesn't work something isn't configured right, if it does work might be just a simple routing issue(Should double check the routing table).
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com