- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
11-29-2021 08:34 AM
Hello
We have an active/passive cluster (PA-820) which we use for IPSec tunnels (with 30 different partners).
One of the partners insisted on having a redundant connection using two IPSec tunnels with different peers. So we came up with the idea of enabling ECMP. Based on the routing table, this looks fine (same destination network listed twice, marked with an "e" in the list).
Unfortunately the CPU of the management plane went up (from ~30% to ~99%) after ECMP was enabled. Event the management plane on the passive node is at ~70%.
PAN-OS: 9.1.7
Is this a common behaviour of using ECMP (on tunnel interfaces)?
11-29-2021 06:32 PM
I've never enabled ECMP on such a small platform, but it's not uncommon to see a rise in management utilization after its enabled. Can I ask why you enabled ECMP for this scenario however? I don't see how it really gains you anything in the situation that you've described. You could have utilized tunnel monitoring or static route path monitoring and wouldn't have needed to touch ECMP.
11-29-2021 06:32 PM
I've never enabled ECMP on such a small platform, but it's not uncommon to see a rise in management utilization after its enabled. Can I ask why you enabled ECMP for this scenario however? I don't see how it really gains you anything in the situation that you've described. You could have utilized tunnel monitoring or static route path monitoring and wouldn't have needed to touch ECMP.
12-06-2021 12:46 AM
Thanks for the hint regarding tunnel monitoring vs. ECMP. We picked the latter since it sounds very simply (enable the feature, no need to setup monitors per tunnel, ...).
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!