Answer the question
In order to leave comments, you need to log in
Does a storm appear periodically in the VLAN where IP telephony is used?
A storm appears in the VLAN segment.
1) There is an asterisk server with a static ip address that looks in VLAN
2) All phones are also in VLAN 4
3) D-Link switches
4) A lot of ARP requests
appear at different times 5) UDP requests for registration with sides of phones towards the server, which are not processed by the asterik server.
At the same time, before switching to VLAN, everything worked fine.
It is possible that such packets were processed by the Firewall (dropped packets).
Tried to disable ARP requests on the server side. ifconfig eth0 -arp, after that it loaded from the file where the IP addresses of the phones and the MAC address are registered - as a result, all the phones "disconnected" - returned everything back.
Registered in iptables limit 60/minutes the number of udp requests on port 5060 - did not help.
Removed several phones from the VLAN and connected to asterisk - they work without problems.
Softphones also work without problems.
Some phones are in rupture with computers - when the network in the VLAN "falls" (storm) - computers also "buggy".
What could be the problem.
Some changes:
1) Set up the 2nd asterisk and link it to the 1st one.
2) In the 2nd asterisk threw most of the phones and removed the VLAN.
3) There are 5 phones left in the 1st asterisk - there are no problems.
4) There are 20 phones in the 2nd asterisk - lags continue.
5) Checking for loops did not give any results - everything is fine.
6) The MAC address table on the main switch is updated normally - no problems are visible either. All phones are visible and IP addresses correspond to the table of MAC addresses and ports.
7) Checking the configuration of phones also did not give anything.
Outcome:
Backup did not give a solution to the problem.
So far, the only thing that has not yet been checked comes to mind:
- Remove the phone autoconfiguration settings via tftp - not an obvious solution - but this is the only thing that changed just at the moment when the problems started.
Solution:
1) DHCP server was configured
2) DNS server just in case
3) Disabled on Keep Alive IP phones
4) Asterisk settings were reset
As a result: The
storm stopped.
Answer the question
In order to leave comments, you need to log in
4) At different times there are many ARP requestsAre the requests coming from the same device or different ones? What is the approximate intensity? Do these traffic spikes at random or recurring times?
At the same time, before switching to VLAN, everything worked fine.Before transition to VLAN is how? How was the network organized? One L2 domain for all devices? What changes were made during the "transition to VLAN"?
Tried to disable ARP requests on the server side. ifconfig eth0 -arp, after that it loaded from the file where the IP addresses of the phones and the MAC address are registered - as a result, all the phones "disconnected" - returned everything back.Do your phones have manually assigned IP addresses or do they receive them automatically?
A storm appears in the VLAN segment.What is the traffic intensity? Besides ARP requests and UDP packets, are there other significant traffic components?
I went to work and found something interesting:It is logical that the phone generates ARP responses in response to an ARP request that the server sends because, for example, an entry in the arp table is out of date.
1. During the "storm" - on the Asterisk server - checking with the
arp -a command
- it cannot "bind" some* IP phones and MAC addresses
2. At the same time, just udp requests on port 5060 go from these phones.
3. I.e. at some point in time, the server cannot understand where the phone is located, the phone tries to send a request to the server - and the server cannot answer it, because doesn't know where he is. The result is Storm.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question