Duplicate IP Address Detection for IP Mobility
Configure duplicate IP address detection settings to detect duplicate IP addresses, generate syslog messages, and specify how the device will respond when a duplicate IP address is detected.
IP mobility refers to endpoints, such as virtual machines, containers, and physical hosts, retaining their IP addresses while being moved within an EVPN-VXLAN data center. PE devices advertise their locally learned MAC-IP bindings using EVPN Type 2 MAC/IP advertisement route messages. When an endpoint moves from one PE device to another, the new PE device advertises a MAC-IP route for the same IP address with a higher sequence number. This allows remote PE devices to identify the most current location of the endpoint. As endpoints move within the EVPN-VXLAN network, multiple MAC/IP advertisement routes for the same IP address can exist in the control plane. EVPN IP mobility uses sequence numbers and route precedence rules to identify the active advertisement and ensure that traffic is forwarded to the endpoint's current location.
PE devices in the network use the following precedence order in selecting which IP address source to advertise:
IP address of the local IRB (most preferred).
Locally pinned IP address.
Remotely pinned IP address.
Learned local IP address with a static MAC address.
Learned remote IP address with a static MAC address.
IP address with the highest sequence number.
IP address with the latest timestamp.
Network misconfigurations can lead to unstable endpoint movements, which cause route instability and excessive MAC/IP advertisement route messages. In some scenarios, you may also wish to exclude specific IP addresses from duplicate IP address detection.
Duplicate IP address detection supports valid IP moves by providing you with the mechanism to manage the following:
- Detect duplicate IP addresses and generate syslog messages.
- Use EVPN Type 2 route sequence numbers to determine the preferred MAC-IP route to use when multiple MAC/IP advertisement routes exist for the same IP address.
-
Either suppress or continue to forward traffic associated with a duplicate IP address.
- Exclude selected IP addresses from duplicate IP address detection.
This feature is supported for both IPv4 and IPv6 underlay networks.
Limitations
-
In CRB deployments where
proxy-macip-advertisementis enabled, Junos does not apply duplicate IP address detection to IP addresses that are not locally learned on the spine device. Because the MAC/IP advertisement route messages generated on behalf of leaf devices for the endpoints do not have sequence numbers, whenproxy-macip-advertisementis enabled. So, duplicate IP address detection cannot be applied to those IP addresses. -
When
no-sequence-numbersis enabled formac-mobility, MAC/IP advertisement route messages are sent without sequence numbers. Duplicate IP Address Detection will then default to using timestamps.
Benefits of Using Duplicate IP Address Detection for IP Mobility
-
Detects unstable endpoint movement.
-
Prevents excessive MAC/IP advertisement route messages that can be caused by continuous IP movement.
-
Protects against forwarding instability caused by duplicate IP usage.
-
Supports configurable operational responses (block or no-ip-suppression) based on your deployment policy.
-
Provides improved operational visibility through mobility tracking and duplicate IP syslogs.
-
Supports automatic or manual recovery mechanisms when duplicate conditions are resolved.
Configure Duplicate IP Address Detection for IP Mobility
Duplicate IP address detection helps you to manage the IP mobility in an EVPN-VXLAN
network. Duplicate IP address detection uses the same detection window and detection
threshold configuration settings that are used for duplicate MAC address detection. An IP
address is identified as a duplicate IP address when the number of IP mobility events
associated with that IP address exceeds the configured detection threshold within the
detection window. The duplicate status of the IP address is stored in the EVPN control
plane. When the IP address is identified as a duplicate IP in the control plane, the device
generates a syslog message and carries out the configured
duplicate-ip-detection action.
- Configure Duplicate IP Address Detection
- Exclude IP Addresses from Duplicate IP Address Detection
- Clear Duplicate IP Addresses
Configure Duplicate IP Address Detection
To configure duplicate IP address detection, include the following
duplicate-ip-detection options at the global [edit protocols
evpn] hierarchy level.
-
action—Specify one of the following actions:-
block—The device generates a syslog message for the duplicate IP address. It stops responding to ARP/ND requests for that IP address and will drop traffic bound for that IP address. -
no-ip-suppression— The device generates a syslog message for the duplicate IP address. It continues to advertise the MAC-IP routes, responds to ARP/ND requests and will forward traffic destined for the IP address.
-
-
use-timestamp—The device does not use sequence numbers in the MAC/IP advertisement route messages. Instead, it uses the most recent timestamp to determine the best source selection when a duplicate IP address is detected. -
exclude-policy—The device uses the policy to exclude IP addresses from duplicate IP address detection.
Exclude IP Addresses from Duplicate IP Address Detection
In some cases, you might want to exclude specific IP addresses from duplicate IP address detection. Examples of IP addresses that might be commonly excluded are anycast IP addresses, shared service IP addresses, static infrastructure IP addresses, or other IP addresses that are expected to move frequently.
Excluded IP addresses are not evaluated for duplicate IP address detection and the device does not take any action or generate syslog messages for those addresses.
The following is a sample policy and configuration for excluding IP addresses 10.10.10.5/32 and 192.168.100.0/24.
policy-options {
prefix-list EXCLUDED-IP {
10.10.10.5/32;
192.168.100.0/24;
}
policy-statement EXCLUDE-DUP-IP {
term 1 {
from {
prefix-list EXCLUDED-IP;
}
then accept;
}
}
}
protocols {
evpn {
duplicate-ip-detection {
exclude-policy EXCLUDE-DUP-IP;
}
}
}
For more information about configuring prefix lists in policies, see Understanding Prefix Lists for Use in Routing Policy Match Conditions.
Clear Duplicate IP Addresses
Junos OS does not automatically clear identified duplicate IP addresses. The duplicate IP addresses remain in the suppressed state when the automatic recovery timer is not configured or when you do not manually clear the duplicate IP addresses. Clearing the duplicate IP addresses allows the device to resume normal MAC/IP advertisement route messages.
To set an autorecovery timer for clearing EVPN duplicate IP addresses, configure
auto-recovery-time in the [edit routing-instances
routing-instance-name protocols duplicate-mac-detection] hierarchy level. The
automatic recovery timer defines how long an IP address remains in a duplicate IP state.
At the end of this timer, the PE device starts advertising the IP address when there are
no conflicting MAC-IP address bindings detected.
detection-window and detection-threshold settings are
configured as part of the duplicate-mac-detection. Both settings apply to
both duplicate MAC address and duplicate IP address detections.For more information duplicate MAC address detection settings, see Changing Duplicate MAC Address Detection Settings.
To manually clear the suppression of duplicate IP addresses, use the clear evpn
duplicate-ip-suppression command. The PE device starts advertising the IP
address if no conflicting MAC-IP address bindings were detected.
Viewing Duplicate IP Address Information
Use the following commands to check the status of duplicate IP addresses:
show evpn globalsshow evpn database extensiveshow evpn instance <instance> mac-ipv4-trackingshow evpn instance <instance> mac-ipv6-tracking
The following sample output from the show evpn globals command displays
the status of duplicate IP address detection.
user@switch> show evpn globals
Router-ID: 10.255.255.1
Ipv6-Primary-Addr: ::
Ipv6 Underlay: N
Underlay-Change: N
Init-Complete Timestamp: Aug 6 11:41:17.448 2026
L2ALD-Conn: Up
L2ALD-Down Timestamp: Aug 6 14:45:38.367 2026
L2ALD-Up Timestamp: Aug 6 14:45:53.646 2026
IBGP-peer Count: 2
MCSN-Blocked: N
GMP Client-ID: 2
SMET-NH-Limit: 10000
RVTEP-Mode: Per-Instance
RVTEP-AR-Mgid: 65535
duplicate-ip-detection
Status: Enable
Use-Timestamp: Disable
Action: IP-Suppression
The following sample output displays the status of MAC-IP bindings.
user@switch> show evpn instance mac-ipv4-tracking
Instance: User_mvs1
Tracker-ip: 192.168.1.254
Status: Active
Mac: 00:01:01:00:00:fe/irb.100
Tracker-ip: 192.168.2.105
Status: Duplicate Detected
Mac: 00:00:01:01:02:01/11.0.2.1
Mac: 00:00:01:01:03:01/et-0/0/1:0.0
Mobility history
Mobility event time Type Source Seq num MAC
Aug 24 20:14:24.402452 Local et-0/0/1:0.0 1 00:00:01:01:03:01
Aug 24 20:14:25.561496 Remote 11.0.2.1 2 00:00:01:01:02:01
Aug 24 20:14:26.032787 Local et-0/0/1:0.0 3 00:00:01:01:03:01
Aug 24 20:14:27.173663 Remote 11.0.2.1 4 00:00:01:01:02:01
Aug 24 20:14:27.671772 Local et-0/0/1:0.0 5 00:00:01:01:03:01
Tracker-ip: 172.16.1.254
Status: Active
Mac: 00:01:01:10:00:fe/irb.110
Tracker-ip: 172.16.2.254
Status: Active
Mac: 00:01:01:50:00:fe/irb.145