IOS-XE 17.15.4 clients with 00:00:00:00:00:00 mac address

denstov
Comes here often

IOS-XE 17.15.4 clients with 00:00:00:00:00:00 mac address

Hello,

We are testing Cloud Managed IOS-XE 17.15.4 and upgraded one of the templates and networks to this release. I am seeing hundreds of clients with mac address of 00:00:00:00:00:00 with different public ips and all mapped to interface 1 vlan1.  Interface 1 on the switch its an uplink to MX-67 appliance. Looks like those ips are connections that internal network clients connected to. Is anyone who tested this IOS-XE release seeing the same information under Network-Wide >  Clients? Never seen this type of clients with CS firmware.

Thank you

7 Replies 7
compunetJimmy
Here to help

I'm seeing the same exact issue.

 

I'm seeing it associate what appear to be destination IP addresses as clients too. 

 

compunetJimmy_0-1756304068880.png

 

denstov
Comes here often

I did not see anything in the release notes related to this.  I opened a support case. 

alemabrahao
Kind of a big deal
Kind of a big deal

Perhaps this is relevant information.

 


Note: 
Only the MX Security Appliance has the option to use Unique Client Identifier or track clients by IP. All other Cisco Meraki devices will only distinguish clients based on MAC addresses.

Note: The following ports don't support Client Tracking features on MS390 & C9300/L/X-M.

1. Ports with supported max speeds 25G, 40G, 100G.

2. Link Aggregation ports

 

 

Client-Tracking Options - Cisco Meraki Documentation

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
compunetJimmy
Here to help

Good information to share. Weird that no client tracking is supported on C9300s when DHCP snooping is enabled and that would be a valid source of client information.

 

This issue, the large quantity of 00::00 MAC addresses, appears to have come after the upgrade but I can't be 100% for sure. 

 

I'm also looking at this and turning off client sampling on all interfaces, which I left on initially because of being a mixed Catalyst-MS environment, but maybe this is just polluting the dashboard:
https://documentation.meraki.com/MS/Monitoring_and_Reporting/MS_Client_Sampling_on_Uplink_Configurat...

 

My gripe with this issue: if Meraki doesn't support client tracking on Catalyst switching, why are they reporting client information in the dashboard using Catalyst switching telemetry? If the information can't be accurate and the dashboard reports bad data, the dashboard is just lowering the SNR and making the work of investigating clients way more difficult than it should be. *

Edit-Changed the focus of this paragraph to platform itself and not the people building it. 

Ryan_Miles
Meraki Employee All-Star Meraki Employee All-Star
Meraki Employee All-Star

@denstov  We've seen some cases of this in the past. If you haven't already I would open a Support case and have them see if this matches the previous cases or if this is something different.

denstov
Comes here often

Hi Ryan,

I opened a support case.  I follow up with an update once I hear back.

Thank you

jbright
A model citizen

I have a C9300L-48UXG-4X switch running 17.15.4 and the client MAC addresses are showing correctly in the dashboard. The switch is static routing and it is connected to an MX85, which is running SDWAN 19.1.10 and using UCI for client tracking.

Get notified when there are additional replies to this discussion.