If you have that situation, can you check if 'show mac-address' shows the MAC address that is listed for 1.2.3.5?
What I can imagine is that if the switch has an arp entry but no port in the the mac-address table, that it doesn't know where to send the packet. In that case it should either send it to all ports in the VLANs, or it should do an ARP first and then send it to the right destination (but it knows the mac already).
And yes, the thought that this may be related to dynamic arp protection or other protection features sounds reasonable. However, unless you can't quickly test by disabling arp protection and see if that resolves the issue, I would open a support case for this to have it be investigated because this sounds like something really undesirable which needs to be addressed.
------------------------------
Herman Robers
------------------------
If you have urgent issues, always contact your Aruba partner, distributor, or Aruba TAC Support. Check
https://www.arubanetworks.com/support-services/contact-support/ for how to contact Aruba TAC. Any opinions expressed here are solely my own and not necessarily that of Hewlett Packard Enterprise or Aruba Networks.
In case your problem is solved, please invest the time to post a follow-up with the information on how you solved it. Others can benefit from that.
------------------------------
Original Message:
Sent: Dec 14, 2022 04:49 AM
From: Finn Baumg�rtner
Subject: No Switchport at ARP Entries
Hey Airheads,
in the past month I have some trouble with our 5406Rzl2 switches.
Sometimes the arp entry does not contain a port int the arp table. Her an example:
IP Address MAC Address Type Port
--------------- ----------------- ------- ----
1.2.3.4 123456-abcdef dynamic Mesh
1.2.3.5 654321-abcdef dynamic
1.2.3.6 567890-fedcba dynamic A3
When I start a ping to 1.2.3.5 the request gets a timeoute even if I set the timeout to 10 seconds.
After this ping the switchport for is 1.2.3.5 is displayed in the arp table and the ping and other requests which get switched over this switch works. No matter if its a ping or a sftp request, the first try will get a timeout. The second try works perfecly fine.
I had this issue on some hosts not just this (example) one. I saw this on all our 5406Rzl2 switches. There are four deviced cross connected via mesh.
Could this be a case with the dynamic arp protection?
thanks!
Best regards
Finn