I've posted this once but doesn't seem to have made it....
We have put a new dual firewall system in and were having approx 50% packet loss..
The switches were vlaned and it seems the carp fake macs were upsetting it. Eventually I found the following post
http://forums11.itrc.hp.com/service/...readId=1033811
and to quote
I believe this is happening because the firewalls probably share the same virtual mac-address for their HA functionality.
The 2500 series only have a single mac-address table, whereas the newer products such as the 2600's have a mac-address table per VLAN.
There's some information about this in the VLAN chapter of the management and configuration guide... you can also find it here:
http://www.hp.com/rnd/support/faqs/2...htm#question27
Once I remove the virtual LAN carpip the problem goes away!
So I suppose my question a couple of posts up was ' does a switch need to be layer 3 to go with this, or is it just a problem with the ageing 2524, which is a managed layer2