An ARP storm causes a high volume of ARP packets to get punted to the CPU. DDoS protection kicks in to protect the RE. However, when ARP DDoS violations are ongoing, legitimate ARP packets can be dropped. If an ARP entry ages out during this time, the device may not be able to refresh the ARP entry. Protocols dependent on the ARP resolution of the next hop such as BFD/BGP will go down as a result.
"DDOS_PROTOCOL_VIOLATION_SET: Warning: Host-bound traffic for protocol/exception ARP: aggregate exceeded its allowed bandwidth" messages in the logs. BFD/BGP and other control plane protocols might flap.
DDoS violations are a symptom of a problem in the environment. Identify the source of the DDoS violations and apply a firewall filter to drop these packets.