ISP connecting going to Switch

AnkitSharma1
Here to help

ISP connecting going to Switch

Since we got one handoff from ISP, Connection is going to switch and then distributing to firewall 1 and 2 however what are these IP's i am seeing when i clicked on switch port which is connected to ISP connection.

 

AnkitSharma1_0-1710901931100.png

 

7 Replies 7
BlakeRichardson
Kind of a big deal
Kind of a big deal

Given they are all showing the same MAC I'd say the switch is reporting on devices upstream. Is the a screenshot of the port that is connected to the ISP or one of your downstream firewalls? 

 

Also I wouldn't recommend connecting a switch directly to an ISP like this. 

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
AnkitSharma1
Here to help

AnkitSharma1_0-1710903016997.png

 

AnkitSharma1
Here to help

Same thing with another ISP on switch 2

K2_Josh
Building a reputation

In case it helps, it looks like 00:00:5E is VRRP.

 

https://stackoverflow.com/questions/14710389/reserved-mac-addresses-some-are-assigned-anyway

 

So I'm wondering if the port configuration on 46-48 of the MS isn't setup properly and potentially leaking through the MS to the MX LAN ports. I would setup a separate VLAN that is not configured on the MX, and ideally not not part of the trunk ports to the MX.

KarstenI
Kind of a big deal
Kind of a big deal

What firewall is it? Looks like a Proxy-ARP misconfiguration.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
AnkitSharma1
Here to help

We are using MX84

KarstenI
Kind of a big deal
Kind of a big deal

Hmm, what else has an IP on this VLAN? Do a packet capture on the ISP port and look for ARP packets.

If you found this post helpful, please give it Kudos. If my answer solves your problem, please click Accept as Solution so others can benefit from it.
Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels