Wireless Access

last person joined: 16 hours ago 

Access network design for branch, remote, outdoor, and campus locations with HPE Aruba Networking access points and mobility controllers.
Expand all | Collapse all

VRRP source mac address. Physical or Virtual?

This thread has been viewed 6 times
  • 1.  VRRP source mac address. Physical or Virtual?

    Posted Jan 24, 2017 05:18 PM

    For traffic coming from the VIP of a Master Redundancy VRRP, what should the source mac address be?  My understanding is that it should be sourced from the VRRP virtual mac address and the VRRP virtual IP address.

     

    But when i take a packet capture, that's not what i see.  Traffic from the VRRP IP address is sourced via the physical mac address.

    Aruba_VRRP.JPG

     

    So either my understanding of VRRP is incorrect, or the Aruba controller is not responding sourced from the correct mac address.  I do see it sending VRRP packets sourced from the VRRP virtual mac, but not packets destined towards APs.

     

    Thoughts?



  • 2.  RE: VRRP source mac address. Physical or Virtual?

    EMPLOYEE
    Posted Jan 24, 2017 05:32 PM
    The controller does not initiate any traffic from its VRRP. VRRP is only used for receiving traffic.


  • 3.  RE: VRRP source mac address. Physical or Virtual?

    Posted Jan 24, 2017 06:16 PM

    So traffic from the controller to the AP should not be sourced via the VRRP address?  That doesn't seem right.



  • 4.  RE: VRRP source mac address. Physical or Virtual?

    EMPLOYEE
    Posted Jan 24, 2017 08:32 PM

    It is not.  It comes from the controller's controller-ip.  VRRP is a standard protocol for incoming traffic, not outgoing traffic.



  • 5.  RE: VRRP source mac address. Physical or Virtual?

    Posted Jan 24, 2017 09:19 PM

    Listen, VRRP is not a receive only protocol. If that was the case, all TCP transactions to the VIP would fail.  As you can see in the screenshot, they very well do work as this is a packet FROM the VRRP IP Address.

     

    If what you are saying regarding AP communication is correct, then there would be 2 seperate GRE tunnels to the controller.  One from the AP to the VIP, and one from the controllers mgmt IP to the AP.  Which is also not the case.  See the following:

     

    Aruba-GRE-Termination.jpeg

    Amazing that the firwall shows that the controller does indeed build a GRE tunnel from the VIP to the AP.

     

    So now back to my original question, why are packets SENT from the VIP IP address not sent via the VRRP virtual mac?  Doesn't this lead to issues where we have to do unicast flooding since we aren't learning the mac address on that port? (also behavior described in the RFC).



  • 6.  RE: VRRP source mac address. Physical or Virtual?

    Posted Jan 24, 2017 09:40 PM