What happens when the return-mac limit is reached when using symmetric routing?

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

What happens when the return-mac limit is reached when using symmetric routing?

Does anybody know what happens if the limit is reached on the return-mac table? 

 

We have multiple ISPs and can host services on each if we use a PBF rule using symmetric return.  However, there is a limit and I can't find any information about what happens when the limit is reached.

 

The admin guide just says

To determine the next hop for symmetric returns, the firewall uses an Address Resolution Protocol
(ARP) table. The maximum number of entries that this ARP table supports is limited by the firewall
model and the value is not user configurable. To determine the limit for your model, use the CLI
command: show pbf return-mac all.

1 accepted solution

Accepted Solutions

Cyber Elite
Cyber Elite

Hi

 

Once the mac table is full no new mac addresses can be resolved until space becomes available for new entries. Any sessions needing a mac to get resolved for the symmetric-return would get dropped due to the inability to resolve the mac of the destination IP

 

 

hope this helps

Tom

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization

View solution in original post

1 REPLY 1

Cyber Elite
Cyber Elite

Hi

 

Once the mac table is full no new mac addresses can be resolved until space becomes available for new entries. Any sessions needing a mac to get resolved for the symmetric-return would get dropped due to the inability to resolve the mac of the destination IP

 

 

hope this helps

Tom

 

Tom Piens
PANgurus - Strata specialist; config reviews, policy optimization
  • 1 accepted solution
  • 2655 Views
  • 1 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!