...
ARP frames are getting dropped as runt by the NPU
The incoming encrypted frame containing the ARP frame as the payload is not padded to 64bytes and this is causing the pkt reaching the NPU post decryption to be less than 64 bytes (including FCS)
Configure static ARP and the traffic starts flowing
This problem is seen only when interop'ed with a Juniper box which is not padding the smaller ARP frames before encryption. We haven't seen this issue anytime otherwise with any other vendors or among our PIDs across the Cisco family.
Click on a version to see all relevant bugs
Cisco Integration
Learn more about where this data comes from
Bug Scrub Advisor
Streamline upgrades with automated vendor bug scrubs
BugZero Enterprise
Wish you caught this bug sooner? Get proactive today.