Re: Gratuitous ARP

From: Colin Farley (Colin.Farley_at_ecarecenters.com)
Date: 09/19/05

  • Next message: Dan Mack: "Re: any ideas when 5.5 will be out"
    To: matt@fruitsalad.org
    Date: Mon, 19 Sep 2005 14:08:22 -0500
    
    

       Hi Matt,

       Thanks for your reply. = The model of the Cisco router is 2811. Do
       you think that lowering the= timeout to 5 seconds would be ok? I have
       seen that Cisco does not recommen= d a timeout below 30 seconds but
       after reading your reply and seeing as the= re are only a couple dozen
       hosts on this subnet I would think that thi= s would be fine. Please
       confirm. Thanks again.

       
       Colin

       -----owner-freebsd-stable@freebsd= .org wrote: -----

         To: freebsd-stable@freebsd.org
         From: Matt Douhan <matt@fru= itsalad.org>
         Sent by: owner-freebsd-stable@freebsd.org
         Date: 09/19= /2005 01:54PM
         cc: Colin Farley <Colin.Farley@ecarecenters.com>
         = Subject: Re: Gratuitous ARP
         On Monday 19 September 2005 19:31, Colin = Farley wrote:
    > 1.&nbs=p; Set the arp cache timeou= t of the cisco router
         very low so
    > that outages a=re = minimal. I would rather not do this as
         it will
    > p= roblably stress th=e router too much. Unfortunately I
         know little> about cisco devices so=I really cant figure this
         one = out, does anyone
    > think that this is a bad th=ing? &n= bsp;Can you tell a
         cisco device not to
    > cache arp entri= es on just the=internal interface? The
         subnet
    > = currently consists of about 25 hosts =so this may not be
         so bad after
         = > all?
         Depending on your Cisco router model you will= not have any issues
         whatsoever
         lowering the timeout to really low, in = the region of a few
         seconds.
         even an old 25xx device would be to han= dle that without problems.
    >
    > 2. Ru= n an ANT task to =clear the cache on the cisco
         device, this
    > = ; task can become part of the UCARP=scripts. This may be a
         go= od
    > solution but security is a concern.
         This wou= ld be very very bad, cause no matter how you do it the
         security
         concern= would be severe.
         --
         Matt Douhan
         www.fruitsalad.org
         (remem= ber, amateurs built the Ark, professionals built the
         Titanic)
         ___ ______________________ 5F__= ___________________
         freebsd-stable= @freebsd.org mailing list
         [1]http://lists.freebsd.org/mailman/li= stinfo/freebsd-stable
         To unsubscribe, send any mail to "freebsd-stab le-unsubscribe@freebsd.org"
         
       
    References

       1. 3D"http://lists.freebsd.org/mailman/li_______________________________________________
    freebsd-stable@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-stable
    To unsubscribe, send any mail to "freebsd-stable-unsubscribe@freebsd.org"


  • Next message: Dan Mack: "Re: any ideas when 5.5 will be out"

    Relevant Pages

    • Re: problem with vlan + arp
      ... the default mac-address timeout on the switches are different. ... into this problem before and I consider this to be a bug (but Cisco ... Cisco recommends setting the arp-cache timeout on each VLAN to ...
      (comp.dcom.sys.cisco)
    • Re: Help: inappropriate OLEDB timeout:
      ... >> Matt C. writes: ... MDAC hotfix described in kb article 832483, ... I get the premature 30 second timeout. ... there is no premature timeout and the process completes normally. ...
      (microsoft.public.data.oledb)
    • Re: Help: inappropriate OLEDB timeout:
      ... Matt C. writes: ... > MDAC hotfix described in kb article 832483, ... The default timeout of 30 seconds is evil. ... Erland Sommarskog, SQL Server MVP, esquel@xxxxxxxxxxxxx ...
      (microsoft.public.data.oledb)
    • Re: On some Please listen to my demo type ish...
      ... Timeout. ... Matt ... Me: "fat laces" ... Prev by Date: ...
      (rec.music.hip-hop)
    • ? How to set FTP session time limits ?
      ... Are you talking about general session time or timeout? ... my knowledge there is no way to limit session lengths. ... But timeout is a different story. ... Matt ...
      (microsoft.public.inetserver.iis.security)