What is this LLC broadcast fram?


The customer saw high CPU condition on switch side after upgrading from R3.6.2 to R5.2.1 of SZ and found LLC broadcast frame from SZ caused it.


Customer Environment

Catalyst4948E SZ-100 R5.2.1.0 515

Root Cause

After R5.0, DP will sent L2UF frame when UE roamed or disconnected from DP. This change was maed for IP phone roaming scenario. IP phone supports power save mode and phone will be silence more than 900 seconds and it depends on customer's setup. DP learns UE connect to DP by traffic. Once IP phone fails over from DP1 to DP2 and power save mode is enable, DP2 can't know UE connect to itself. Today core side IP phone calls another phone which just fails over to DP2, but DP2 just drops the call because DP2 doesn't know it. Instead DP1 will pass the call to old AP if idle less than 180 seconds. The solution will let AP send L2UF to DP2 to declare UE roaming to DP2. DP2 add it to host table and bridge L2UF. If DP1 and DP2 in the same subnet, DP1 will remove UE data in host table.

Troubleshooting Steps

The customer is seeing high CPU condition on the switch that 3-node cluster SZ connected to.
The customer also found the following syslog on the switch.

%SW_MATM-4-MACFLAP_NOTIF: Host 0013.9200.0000 in vlan 1180 is flapping between port Gi2/0/24 and port Gi1/0/24
The customer captured packets and found the following LLC frames were sent from all SZ nodes.

Source MAC address was 00:13:92:00:00:00 and it came from different switch port that connected to differnt DPs, so it caused MAC address flapping on the switch.

User-added image


This is not be disabled in SZ, so workaround is to configure static MAC table on Cisco Switch.
No packet will be forwarded to 00:13:92:00:00:00, so it does not have any impact for the system.

