On 01/12/05, Christopher Vance <[EMAIL PROTECTED]> wrote: > On Thu, Dec 01, 2005 at 08:08:27AM +0000, tony sarendal wrote: > >> Which managed switch brands behave right with carp, allowing traffic from > >> carp source addresses on multiple ports without duplicate suppression? > > > >"duplicate suppression", makes the lack of per-vlan mac-address tables > >sound like a feature. > > > >Get switches with per-vlan mac-address tables, even old cisco 3500 has this. > > Both firewalls are on all vlans, and I want both firewalls to be able > use the same source MAC address (a separate address per vlan, but > shared by both firewalls) and see each other's carp multicasts. > > Even with per-vlan tables, I need CARP source addresses to be an > exception (although Cisco will think they are V*RP). >
I use carp, hsrp, routers with same mac-address on all vlan interfaces, cases where the same mac-address goes different ways in the network depending on which vlan it is on. Even on old 3500 it works. /Tony -- Tony Sarendal - [EMAIL PROTECTED] IP/Unix -= The scorpion replied, "I couldn't help it, it's my nature" =-