I had a remote site that was complaining of slowness in certain parts of the branch office during the latter part of the day. I started to dig into client statistics on the dashboard, and noticed that there was a group of about 10 systems that were transferring gigabytes of data within a very short period of time. It then would flood some of the uplinks of the switches they were attached to. The kicker that this traffic started once the site went to idle hours (after 6pm local time) and all were sending/receiving identical amounts of data. I ended up doing a packet capture on the switch ports of the hosts that were producing this traffic, and found that they were sending and receiving large amounts of IPv6 multicast traffic. After seeing they were HP desktops that were only generating this traffic, I went digging through the search engines for a possible answer. It turns out there was a known bug in certain driver versions of the onboard NIC of these machines. When the machines go idle, they end up being chatty with each other with IPv6 multicast traffic. The fix is to disable IPv6 or install a driver update. I sent out one of our help desk techs to assist on site with updating drivers on those specific desktop machines. Once that was completed, problem solved, have not seen that occurrence again. Moral of the story: Remote packet captures are your friend with Meraki.
... View more