Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

SOLVED: ARP Broadcasts are leaving subnet - Switch port violations - please help

ARP Broadcasts are leaving subnet - switch port violations - please help

Hi,

I am running the UTM9 virtual appliance in a datacenter.  The problem I have on this specific installation is that I got threathend by the hosting company (Hetzner/Germany) that they are going to shut down my server (ESXi 6.5) because they have multiple and permanet switchport violations on the switchport where my machine is attached.

I am only allowed to connect to that switchport using MAC-adresses that I get assigned from Hetzner. So I bind these MAC’s to the network cards in Esxi, and this works so far.

BUT, and here the problem stays:
all the MAC-addresses of the internal Vmware guests (behind the UTM9) in a private 192.168.0.0/24 network are seen at the switchport.
This means ARP broadcasts are leaving the internal network (192.168.0.0/24 on interface eth1).
Normally ARP broadcasts are stopped here and don’t pass any subnets.

Eth0 is my public IP on the UTM, now when I do a „tcpdump -i eth0 | grep ARP“ I see many many broadcasts like these:

14:30:02.990873 ARP, Request who-has 192.168.0.238 tell 192.168.0.11, length 46
14:30:02.990875 ARP, Request who-has 192.168.0.149 tell 192.168.0.11, length 46
14:30:03.006995 ARP, Request who-has 192.168.0.147 tell 192.168.0.11, length 46
14:30:03.022297 ARP, Request who-has 192.168.0.237 tell 192.168.0.11, length 46
14:30:03.022822 ARP, Request who-has 192.168.0.236 tell 192.168.0.11, length 46
14:30:03.022824 ARP, Request who-has 192.168.0.235 tell 192.168.0.11, length 46
14:30:03.404799 ARP, Request who-has 192.168.0.55 tell utm.hz6.xx.net, length 46
14:30:03.432743 ARP, Request who-has 192.168.0.39 tell utm.hz6.xx.net, length 46
14:30:03.490079 ARP, Request who-has 192.168.0.180 tell 192.168.0.11, length 46
14:30:03.948653 ARP, Request who-has 192.168.0.63 tell utm.hz6.xx.net, length 46
14:30:03.989290 ARP, Request who-has 192.168.0.149 tell 192.168.0.11, length 46
14:30:03.989379 ARP, Request who-has 192.168.0.147 tell 192.168.0.11, length 46
14:30:03.989380 ARP, Request who-has 192.168.0.237 tell 192.168.0.11, length 46
14:30:03.989380 ARP, Request who-has 192.168.0.236 tell 192.168.0.11, length 46

So all these requests reach  the switchport also and create the swithport violations there.

This is a really critical situation, as the hosting company will shut down my server soon if I don’t stop spoofing that port with not allowed MAC-addresses (MAC’s that are coming from my internal machines behind the UTM).

I have opened a ticket with Sophos 3 days ago, today finally I got a call from India, who I hardly was able to understand.
All he did was saying „> They are all the arp request generating which can be controlled from the switch end.“ Totally bs.

Any advice?

The strange thing ist hat I have the complete same setup running on other servers there as well, and there no ARP broadcasts from internals are seen on the public interface at the UTM, so not reaching any unallowed ARP traffic on the public switchport in the datacenter.

Thanks for helping me to fix this and find the cause of this behaviour.



This thread was automatically locked due to age.
Parents
  • Salut Guenther,

    This just feels like an ESXi issue, but I have a question - have you assigned an appropriate MAC address for the UTM's eth1 on the 'Hardware' tab?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Salut Guenther,

    This just feels like an ESXi issue, but I have a question - have you assigned an appropriate MAC address for the UTM's eth1 on the 'Hardware' tab?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children
No Data