Grouping of NETWORK cards causing the ESXi to retransmit ethernet frames received.

I had an HP Proliant DL380 G5 ESXi 5.1.0 connected to a Cisco 3750 Switch stack.

All by performing a tcpdump on a host without a report, I discovered that he was under the bombardment with ethernet frames for the MAC address of a computer virtual located on a host across the data center. After a few brief troubleshooting, I discovered that I was able to stop those erroneous frames by disabling NETWORK adapters on my VMWare host group.

I believe that in my situation when ESXi is configured to use two network cards to all frames received on vmnic0 and retransmits them on vmnic1 and vice-vesa. I experienced these symptoms when ESXi is configured for failover with an active adapter and adapter mode standby and I also experienced the same symptoms in the following load balancing configuration.


Symptoms: some time after activating the load balancing, all frames Ethernet for the MAC address of a virtual computer on the affected host are broadcast on each switch port in the entire data center.

Steps to reproduce:
(1) implementation below configuration.
(2) unplug the ethernet cable connecting vmnic1 and switch1 port gi2/0/4
(3) run the host 1.1.1.1 EI - n - q tcpdump on any machine physics linux in the data center (don't even have to be connected directly to 1).
Confirm there is no packet seen with the IP address of 1.1.1.1 destination
(4) plug the cable between vmnic1 and switch1 gi2/0/4 port ethernet
(5) wait 60 to 120 seconds
(6) watch a burst of frames ethernet with the destination MAC address of the VM (which owns 1.1.1.1) in the output of tcpdump

Cisco Configuration:

hostname switch1
!
src-dst-ip port-channel load-balance

!

interface GigabitEthernet1/0/4

Description vmnic0.host0 (NIC 1)

switchport trunk encapsulation dot1q

switchport mode trunk

channel-group mode 4 on

spanning tree portfast trunk

end

!

interface GigabitEthernet2/0/4

Description vmnic1.host0 (NIC 2)

switchport trunk encapsulation dot1q

switchport mode trunk

channel-group mode 4 on

spanning tree portfast trunk

end

!

Interface Port-Channel 4

Host0 description

switchport trunk encapsulation dot1q

switchport mode trunk

spanning tree portfast trunk

end


Configuration of ESXi
vSwitch0

Grouping of NETWORK cards / Load Balancing: route based on IP Hash
Grouping of NETWORK cards / failover detection network: link status only
Grouping of NETWORK cards / notify switches: Yes
NIC Teaming / relief: Yes
Grouping of NETWORK cards / adapters active: vmnic0, vmnic1
NIC Teaming / standby adapters: nothingness
NIC adapters grouping / unused: nothingness
Security / Promiscious Mode: reject

Security / MAC address changes: accept
Security / forged passes: accept


#1 Virtual Machine port group
Network label: 'Public '.

VLAN: 27
Grouping of NETWORK cards: all unchecked (inherited)

#2 Virtual Machine port group
Network label: "trunk".
VLAN: 4095
Grouping of NETWORK cards: all unchecked (inherited)

VM kernel Port #1
Network label: 'management '.
VLAN: 2

Grouping of NETWORK cards: all unchecked (inherited)

VM #1

OS: Windows Server 2003
NIC 1 / adapter: Flexible
NIC 1 / network Label: 'Public '.

IP address: 1.1.1.1/24

I apologize for the delay in my response.

Unplug physically 2 cable NETWORK card on the host and configuration mirrored port on the switchport to 1 NETWORK adapter of the host, I have been able to confirm that the host VMWare issues guides on NIC1 with a destination MAC address of one of its own VM.

After carefully reviewing the captured data, I noticed that the destination frames wrong "02:bf:cb:50:a2:76" MAC address actually belonged to "Local Area Connection 1' one of my Windows 2003 Server WHAT VM installed on the suspected host.

Dig a little deeper, I discovered that this virtual NETWORK card is presented to the operating system as
Name: Local 1 network connection
"Type: VMware Accelerated AMD PCNet adapt."
MAC: 02-BF-CB-50-A2-76

But the configuration of the virtual machine in vCentre is
Name: Network adapter 1
Type: Flexible
MAC: 00: 0C: 29:fa:e8:83

Note the different MAC addresses.

Digging a little further I discovered that Windows 2003 server has configured on "Local 1 network connection" network load balancing and NLB is the cause of the altered MAC address.

Rather than to investigate further I have just placed a load balancer linux before the server windows 2003 cluster and that you turn off NLB.

But I suspect that there is still a fundamental problem in the Virtual Switch VMware with how he learns the MAC addresses of the virtual machine is using flexible vNIC. In particular, with a virtual machine that uses a form to override the MAC address such as that used by NLB.

Tags: VMware

Similar Questions

  • Grouping of NETWORK cards reverse the policy

    When I apply a profile esxi 5.0 to 5.1 host, I got the following configuration message. any ideas?

    Hello

    This is mentioned in the 5.1 version of vSphere notes:

    Compliance policy network outages continue to host profiles created from applied guests 5.1 ESXi ESXi 4.1 or ESXi 4.0 hosts
    After you apply a profile created from an ESXi 4.1 or ESXi 4.0 host host to a 5.1, the failures of compliance profile next host ESXi host could continue:

    For the network policy for the Group [NAME of GROUP of PORT] port spec.policy.nicTeaming.failureCriteria property does not match
    For the network policy for the Group [NAME of GROUP of PORT] port spec.policy.nicTeaming.reversePolicy property does not match


    Network settings above are not supported on ESXi 5.1 hosts and are configured is more when you apply a host profile with these settings.

    Solution: Two options are available:

    • After applying host initially created from an ESXi 4.1 host to a host profile ESXi 5.1, create a new profile of the host from the host ESXi 5.1 and which attach to this 5.1 ESXi host and other affected 5.1 ESXi hosts.
    • Change the policy of grouping of NETWORK adapters in the profile of the host to the option user must explicitly choose political instead of the strategy of grouping NIC specified.

    Now I know IVotre profiles are at the origin of 5.0 but the thought to mention it anyway

  • Grouping of network cards on the PowerEdge R320 and R720 servers

    Hello

    I have several R320 servers with quad port NIC broadcom. I would like to configure the collection of NETWORK adapters on the Server 2008 R2, but I couldn't find a download on the website of Dell application, could someone ' a please point me in the right direction.

    I also have a Dell server with Vmware Esxi 5.1 R720, is it possible to configure NETWORK cards on this grouping?

    Thank you

    Dan

    Guys,

    Is the possible consolidation of NETWORK cards? I would have thought that it is something that would be fairly simple with the right driver.

  • iDRAC 7 express, grouping of network cards

    Hello

    I can't access iDRAC when the grouping of NETWORK cards is configured. Is it according to the design guidelines? There is no work around for this?

    #idrac7express #NICteaming  

    Hello.

    Yes, it's normal. IDRAC Express does NOT use a NETWORK card dedicated for remote access, but rather use a LAN on motherboard (LOM) as a shared port. Now, once you have Teaming on the LOM ports, then the iDRAC Express cannot share all the ports with the team. The solution is to upgrade to iDRAC Enterprise that uses another port dedicated team card NETWORK for management traffic. See page 4 of the link: downloads.dell.com/.../integrated-dell-remote-access-cntrllr-7-v1.30.30_Setup%20Guide_en-us.pdf;. l = en & cs = 555 & s = biz

  • Grouping of NETWORK cards

    Hello

    I am new to virtualization and have a basic question about the collection of NETWORK adapters. I have a host with a NETWORK card with 2 ports (vmnic0 and vmnic1). I have a network cable connected to vmnic0 and vmnic1 is open without any network connection to the outside world. Can I use grouping of NETWORK cards in this case? Or both network adapters must be connected to the network for NIC teaming to work?

    You can certainly configure everything as if the two vmnic was active. However, with a single uplink connected to a physical switch, it may not make much sense.

    André

  • vSphere replication - grouping of NETWORK cards

    We have a large virtual machine (60 to VMDK) we need to replicate to a second host.  We are currently receiving about 100 MB/s and it seems we're reached the limit of 1 GB.  I want to increase the bandwidth available for this large replication work by aggregating traffic through several nic is it possible?  If so, how?

    I tried the following approach, thinking that these operations can be based on the same transfer mechanism, but it has not made a difference.

    http://KB.VMware.com/selfservice/microsites/search.do?language=en_US & cmd = displayKC & addresses...

    The KB points it is grouping of network cards that will help when you lost the active NIC then stand by will pass your tgraffic.

    Now coming to your scenario, you need to configure the user profile of the NIOC here you have to devote all the speed of the network to this replication job card. You cannot aggregate multiple Nic for reaching the combined capacity. We have a concept called LAG and LACP. but it will also give the speed that is independent to the different traffic

  • Adding a second NETWORK card on the server HP Proliant ML 350 G5

    I have a new HP Proliant with a guest of Windows 2008.  HP came with two network cards on the MB.  I need double-home this box on both networks, at least for a while, and this server will be the only road between subnets.  It's just a stand-alone installation inset.

    I looked in the settings of the BIOS on the HP and it's a little confusing, but I'm sure that the second network card is active (it lights up when it is plugged).  When I try to add a NETWORK adapter to the configuration of the host, it is as if the second NETWORK card is not present.

    My question is what is the best way to add this second NETWORK adapter and how do I do that?

    I'll need access to the host of the VI Client on both networks - at least for a while.

    Any help would be greatly appreciated.

    If you go to configuration-card network in the vSphere client is the 2nd NETWORK card that there are listed?  If ESXi is able to recognize the NETWORK adapter (or other people that you add) they should appear in this list without any config changes and be ready for use.

    What kind of networks are you fill?   If one is considered not secure you could be better not add a management on this network port and prefer to have access via a VPN VM or a secure hosted VM / dual.

    Dave

    VMware communities user moderator

    Now available - vSphere Quick Start Guide

    You have a system or a PCI with VMDirectPath?  Submit your specifications to Officieux VMDirectPath HCL.

  • Configuration of VLAN with grouping of NETWORK cards.

    I have a Dell Poweredge server here at work with 2 NIC cards on it.  I have the ESXi hypervisor installed and created virtual machines. I want to use two network cards that the lables vmnic0 and vmnic1 VMware.  I would like to share the same subnet.  See the attached screenshot.  vmnic0 works very well and it is connected to vswitch0.  My management network uses this same vmnic0.  I guess I have to turn on VLAN somehow.  Do I need to do to the ESXi Server Console?  Goal is to be able to put a box until the server ESXi Dell itself and connect a crossover cable and have an IP address to be able to get leased to it in the same subnet, connected on the vmnic1. Thank you

    The problem here is that there is a requirement of 3rd communication. The esx server you are converting to must be contacted as well.  If you connect your machine of transformation of the physical machine, you can convert local files, which should be no problem.  But, you don't want to keep these files locally on the server of conversion, you are trying to convert it to ESX, correct?  It's the difference between your previous method and your current attempt.

    -KjB

    VMware vExpert

  • Compaq Presario V6000: exclamation point next to the network card in the BIOS Setup

    Hello

    Recently, I find the wifi on my laptop does not work with projected light orange. I tried hard to stop my laptop, remove the battery and then restart the same thing with resetting the wifi button but of no use. Also with F10 if I enter the configuration for starting it I find exclamation close the my network card with the message that the ability to start will be disabled if the device with the exclamation mark.

    Please let know us, as I did also update my network drivers.

    Concerning

    Arvind

    Hi @Arvind_1990 ,

    Welcome to the HP Forums!

    It's a great place to find answers and suggestions!

    You have the best experience in the HP forum, I would like to draw your attention to the Guide of the HP Forums Learn how Post and more

    Compaq Pressario V6000 series laptop, what your exact model?

    How can I find my model number or product number?

    I understand - you have a problem with your wireless network. You tried to update the drivers, but there was no change.

    Did you of recent changes made to your Internet provider or router?

    If you go into Device Manager there is an error on the network card?  If yes what is it?

    Here is a link to HP - troubleshooting your wireless network computers and Internet (Windows 7)

    Have your tried running MS Fix It for help with this difficulty?

    Good luck!

  • Diagnostics network ping to the remote host, but has not received a response

    I'm trying to figure out if there is a problem with just my laptop not wanting to connect to a local free WiFi, so any help is appreciated. He worked two days ago only to stop abruptly last night.

    Windows Network Diagnostics comes back with the error message "Can not contact www.microsoft.com (65.55.12.249)" and "diagnostic network ping to the remote host, but has not received a response.

    The only repair option it evokes is ' reset NIC 'wireless network connection ' '.

    I can always connect to WiFi using my iPhone, and even a connected laptop computer work Companion. Yet once, if this can be fixed on my end, any help would be appreciated.

    Hello BrenJones,

    Thanks for posting back. DNS servers are controlled by your ISP. I communicate with your Internet service provider and confirm that you have the good DNS for your network.

    Hope this helps J

    Adam
    Microsoft Answers Support Engineer
    Visit our Microsoft answers feedback Forum and let us know what you think

  • 4 network cards on the question of the ESXi

    Hello

    DL380 G7 4 integrated.

    Please suggest NIC config and transfer of intellectual property. Is THAT DHCP are possible for virtual machines?

    THX.

    You offer 2 NICs for the management. Should I have the IP static 2 concerning best practices in this situation? I had planned a.

    No, just an IP address.  You can also place the second NIC in the standby mode, so that it is available only if the first fails.

    And other physical 2 network cards must be static. As I mentioned VMs will use only STATIC.

    I separate the VM network outside vSwitch0 and create a new vSwitch just for the network of the VM.  Entrust these two network cards and that's it.  There will be no IP addresses for the vSwitch for the network of the VM.  Just give IP addresses to your virtual machines.

  • VMware device with 2 network cards claiming the same IP address with two MAC addresses

    Hello.

    I see messages intermittent my gateway network two MAC addresses associated with a virtual machine running on a 5.5 ESXi host for the same IP address.

    The virtual machine is a MiTel 3300 controller for a VOIP system. the system is configured with two IP addresses, one on the local network and another with a public IP address in the DMZ. In the network configuration of the 3300, I assigned the address LAN IP at 00: 0C: 29:30:B2:B2 and the DMZ IP at 00: 0C: 29:30:B2:BC (Mac for network devices presented by the ESXi host virtual machine).

    On the host, I configured a vSwitch with exclusive access to two physical network adapters on the host machine. The vSwitch is configured with two machine virtual port groups, LAN and DMZ, with access to the physical network interface cards. Tab grouping of groups vSwitch port NIC, I replaced the order of failover of the switch to activate an active NETWORK card only for the Group of LAN ports and the other card NETWORK only for the DMZ port group. (I don't know how the content of the column of networks is determined. Neither is correct for the traffic on the physical switch. If these are configurable, please advise and I'll change the settings). The relevant parameters of vSwitch, groups of ports and VM are distinguished below.

    On the virtual machine itself, through the VMWare host, I assigned 00: 0C: 29:30:B2:B2 for the Group of LAN ports and 00: 0C: 29:30:B2:BC to the DMZ group port (best I can tell, anyway, since the MAC address field annoyingly obscures the last two digits of the MAC address - break if I invert the mapping) (, but all seems OK).

    The goal here is to make sure that MACs of ports vSwitch the 3300 is listening and sending always correspond to the physical ports that are VLAN Tag by the physical switch to ensure the routing. Generally speaking, it seems that what is happening but, intermittently, we cross one-way calls that suggests a problem of routing between us and our SIP trunk provider; coinciding with these incidents, I get an email along the lines of "the security in the network device has detected a conflict of IP address with two or more devices. The period of INVESTIGATION "DMZ. DMZ. DMZ. DMZ' is claimed by the following clients with MAC addresses: ' 00: 0C: 29:30:B2:B2' ' 00: 0C: 29:30:B2:BC'. »

    I did something in the configuration that would lead to this kind of collision intermittent? Have a hacked together a way to do something that could be accomplished in a way that is simpler and more reliable?

    Thanks for any idea that you can offer.

    Kind regards

    J.

    I probably don't fully understand your configuration, but it seems that you are not interested in using the collection of NETWORK adapters in the virtual switch of the VM MiTel 3300.

    If it is correct, why not create two virtual switches, each with a group of port (LAN and DMZ) unique and with a separate connection of (vmnic2 and vmnic1)?

    In general, collection of NETWORK adapters may be used to share traffic between uplinks and ensure that if one of the uplinks connect fails, a virtual machine still has access to the network.

  • virtual network card to the physical network mapping and default loadbalancing

    What Virtual Machine virtual network card is map physical NIC.

    For example.

    lets assume Vswitch1 on host1 esx dedicated for the network of the virtual machine (port group) and it has 6 cards network linked to it (vmnic1, vmnic2, vmnic0, vmnic3)

    Load policy (default) Balancing - from the originating virtual port (it balances only outbound traffic through all the nic assigned to vswitch1 right?)

    ESXi host1 <-Vswitch1 (the VM network) <---(vmnic 0-vmnic 3)

    Lets assume that esxi hosting 6 virtual machines and each virtual machine has two network cards configured.  Through some documents, come out of that when the virtual machine is running, it gets connected to the ports of availabe on virtual swicth. say, I turn on the virtual machine in the order VM1, VM2... VM6.

    Vmname virtual adapter port on virtual switch1 Mapping of the physical network adapter                        

    VM1 eth0, eth1 1.2 which mappeed of the physical NIC to eth0, eth1?

    VM2            eth0,eth1                              3,4                                      ?

    VM3            eth0,eth1                              5,6                                      ?

    VM4            eth0,eth1                              7,8                                      ?

    VM5            eth0,eth1                              9,10                                    ?

    VM6            eth0,eth1                              11,12                                  ?

    Since we use load balancing based on the virtual port, can two virtual map of the same virtual machine are mapped to the two physical NETWORK card I want say eth0 VM1 is mapped to the (physical nic) VMNIC0, VM1 eth1 get connected VMNIC1 (physical nic).

    It would be great if you could explain how the virtual network adapters are mapped to the physical NIC Y at - it a command or a script to the list NIC(of all vms hosted on esxi) virtual NETWORK adapter mappings physical in detail.

    .

    sansaran wrote:

    Is there a way to know what virtual NIC to connect to which physical NIC

    With the virtual NETWORK adapter, you hear the virtual card inside the VM? If if and when you use several VMNIC like you, there is no visibility in vCenter (usually vSwitches, we see with Distributed vSwitches).

    However, you can use the command-line ESXTOP tool in the view 'n', for the connection between the virtual machines and the outgoing vmnic.

  • Failed to create FT logging with grouping of NETWORK cards

    I use vSphere vCenter 5.1 and 5.1.

    I create a port group of kernel VM on a new vSwitch, assign two NICs used on my ESX Server and logging FT. I have then add a second port VM kernel group to the two network cards and also assign FT logging. When I do this FT Logging the first port of kernel VM group is disabled. If I then manually enable FT gones then a second by logging on the first group of ports of kernel VM mode off.

    The same thing happens when I create 2 vSwitches, assign 1 NIC to each of them and assign the FT logging.

    I wanted to create my FT Logging predisposees in this way to match what I've done with vMotion and VM Network.

    I do something wrong or you can have a group of ports per server for recording of FT? Please notify.

    Thank you

    Multi-NIC VMotion is a new feature in vSphere 5.0. Multi-NIC FT has not yet been introduced. You mentioned trade Multi-NIC VM, but it is not possible either. While you can have two interchanges to connect to the same VLAN they must have unique names and a VM NIC may connect only to a unique name.

    What advantage do you hope to achieve with Multi - NIC FT? If the goal is more throughput 10G is the only option currently. If the lens is better traffic load balancing so that you could watch LACP on the vDS.

  • Tests... Grouping of NETWORK cards - based IP Hash

    Hello!

    I am configuring the NETWORK cards on my vSwitch grouping feature. I configured several ports in two physical switches (two HP Procurve 2810) (HP 2810 switches obtained haven´t etherchannel) LACP mode available. Right now, everything is Ok.

    So my question is: How can I test if the IP hash function works well, it is, connecting the same virtual machine with the help of several physical NIC according to computers ask server information?

    I thought about using "sniffer" or something like that. More ideas?

    PS: I tried to configure the collection of NETWORK adapters - Hash IP without configuration LACP in my physical switch and I noticed haven´t alarms or internal errors. May I take it that it works well?

    Thanks for all!

    With ESXTOP command you can see network load on each physical network adapter. Press N to see details on the network.

    I'm not familiar with the switches HP, but (like Cisco), it should be possible to see the counters on LACP or detailed statistics on your switch.

    If you do not use load balancing on your physical switch, all incoming traffic from the network of your virtual machine can come on one single network card.

Maybe you are looking for