Cisco Switches with IPDT Cause Duplicate IPs

Problem:

Allen-Bradley Ethernet module faulting with the following scrolling message:

Module #1:

1756-ENBT/A

[IP Address]

Message:

Duplicate IP

84b51768b631

PLC connected to a Cisco 3850

Cause

IOS Bug on Cisco switches (e.g. IE300, C3850, C3650) See https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuj04986

 

Solution:

Run these two commands to completely disable the ip device tracking function on the affected Cisco switches that have this IOS bug

Hostname (configif)#nmsp attach suppress

Hostname (configif)#no ip device tracking max

Or

follow the workarounds below depending on your firmware version

Full Cisco Article

568750 False Duplicate IP detection on Ethernet modules when used with Cisco switches

Problem

When Rockwell Automation EtherNet/IP modules are connected to a subnet containing Cisco switches with "IP device tracking" (IPDT) enabled, the modules may go into a duplicate IP address state after a restart/reset.

Environment

Any layer two networks that contain both Rockwell Automation EtherNet/IP modules and Cisco switches running IPDT.

IPDT is much more likely to be implemented on Cisco switches as of August, 2013 because of a behavior change which enables this command if any feature which requires it is enabled.

This behavior change also removes the ability to turn off IPDT without first turning off any features which require IPDT. The Stratix line of switches will not have “IP device tracking” enabled by default until a permanent solution is in place.

Cause

The IPDT feature sends probe ARP packets with a source IP address of 0.0.0.0., the source MAC ID of the switch, and the target IP and MAC ID for the device being probed to check that it is still connected and responsive.

When a device becomes disconnected, and then is reconnected within the configurable IPDT timeout period, probe ARP packets may be received by a Logix Ethernet module at the same time as it is in its Address Conflict Detection mechanism. If this happens, the EtherNet/IP module will immediately go into a duplicate IP state, and stop communicating.

IPDT when activated on a Cisco switch will try to probe for every IP connected on the subnet, regardless of whether it is connected to that switch or not.

Testing has shown that this affects the majority of Ethernet modules sold by Rockwell Automation.

Solution

Cisco is continually updating the latest workarounds. Here is a link to Cisco’s technote: http://www.cisco.com/c/en/us/support/docs/ip/address-resolution-protocol-arp/118630-technote-ipdt-00.html Workaround

Several workarounds to this issue exist. They all make suggestions using Cisco IOS command line interface commands.

Workaround 1

Architect manufacturing zone subnets such that:

1. IPDT is explicitly disabled on every trunk port with the following command:

Hostname (configif)# ip device tracking maximum 0

2. IPDT probe delay is manually configured on any access port connected to a Rockwell Automation Ethernet module with the following command:

Hostname (config)# ip device tracking probe delay 10

Workaround 2

If the switch in question has an administration IP (SVI) configured on the subnet/VLAN in question the Cisco CLI command: Hostname (config)# ip device tracking probe usesvi

will insert the administration IP into the source IP in the IPDT packet. This packet will not impact Address Conflict Detection operation.

Workaround 3

Disable IPDT on any Cisco switch ports with IPDT enabled that subsequently connect to a Rockwell Automation Ethernet module with the following command:

Hostname (configif)# ip device tracking maximum 0

 

Workaround 4

Run both the tracking probe auto-source command and the tracking probe auto-source fallback on all switches with this feature turned on.

See https://www.cisco.com/c/en/us/support/docs/ip/address-resolution-protocol-arp/118630-technote-ipdt-00.html

Additional Links

IPDT Overview - https://www.cisco.com/c/en/us/support/docs/ip/address-resolution-protocol-arp/118630-technote-ipdt-00.html

Cisco Community Discussion - https://supportforums.cisco.com/discussion/12563251/cisco-switch-upgrade-leads-allen-bradley-plc-duplicate-ip-address-errors

Honeywell Community Discussion - https://dashboard.intelligrated.com/knowledgebase/PrintArticle.aspx?article=59affed0-03ec-4c12-a40c-2a14f43fc5d3

Where To Buy: Find a Distributor Near Me

 

For support contact us at techsupport@panduit.com