Asymmetric Routing - Palo Edge Firewall Active/Passive to Nexus Core

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Palo Alto Networks Approved
Palo Alto Networks Approved
Community Expert Verified
Community Expert Verified

Asymmetric Routing - Palo Edge Firewall Active/Passive to Nexus Core

L0 Member

We have (2) equal cost L3 links from our Nexus core switches to an upstream Palo edge firewall HA pair, active/passive. On the firewall, this is an aggregation ethernet with layer 3 subinterfaces defined.  There is an SVI on each Nexus switch for routing with a layer 2 port-channel to a breakout switch in between the firewall and core, and we are using OSPF.  We suspect there may be some asymmetric routing issues where we see flows such as TCP non-syn in global counters incrementing on the firewall, and due to some application throughput issues.  We want to influence path selection so that the primary L3 link is always used. I have attached a high-level diagram of the topology.  

 

We are planning to adjust cost on the Palo by changing the OSPF metric to a higher metric on the secondary link, and also adjusting the cost on the Nexus switch SVI for the secondary link to a higher cost.  Currently, we do not have ECMP enabled.  Has anyone experienced a similar issue and resolve it by adjusting the OSPF metric, or by enabling ECMP?

3 REPLIES 3

L3 Networker

Hello,

We had the same problem once. I'm not sure we are in the same situation here but i m pretty sure the solution you said will be ok.

Shortly : indeed u have to change the ospf cost.

We put an OSPF cost higher on the nexus backup link and a higher metric on our ospf links on the palo alto connected to this nexus. All of this was related to the nexus doing a hashing thing... We had some asymetric packets and some others not.

 

Hope it helps !

 

L3 Networker

For the ecmp answer : i don't know at all. I m currently working on migrating these links for ebgp links with ECMP but one sentence scared me : https://docs.paloaltonetworks.com/ngfw/networking/ecmp

'ECMP is supported on all Palo Alto Networks® firewall models, also with hardware forwarding support on the PA-7000 Series, PA-5200 Series, and PA-3200 Series. VM-Series firewalls support ECMP through software only. Performance is affected for sessions that cannot be hardware offloaded. '

Cyber Elite

Hello,

I agree with changing the cost metric. I use high numbers for the metric like 10000. That way the algorhythm will always chose the path I want.

OtakarKlier_0-1769197243306.png

 

Regards,

  • 1986 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!