pratya_52230
May 09, 2011Nimbostratus
LTM/LC: ARP not update, after failover firewall
I have bigIP(LTM/LC) in front of checkpoint HA firewall(active/standby)
I did try pinging from my PC located in internal network through checkpoint+F5 to external router.
It seems fine at the first period of continuous ping, but when I tried failover checkpoint firewall by unplug one lan interface on active firewall (node A) to, to force failover to standby-firewall (nodeB),
I found that my ping result was timeout.
I use tcpdump on internal vlan on f5 and found that icmp-request was sent from FW-nodeB (0090.fb31.0947)to F5 correctly, but icmp-reply packet was sent to MAC address of FW-node A(0090.fb31.0917) which is wrong.
I also verified dynamic arp on bigip, and found that dynamic arp on bigip was correct and updated quickly. I tried another ping from another PC from same internal network, ping result is 100% success.
I do not understand why arp on bigip already update, but some process on bigip still remember the invalid mac-address. Anyone have found this problem like me, please kindly help.
note. my PC is 172.18.64.101
- I use SNAT with origin address configured to handle this outbound traffic.
- I config route 172.18.0.0 to VIP of checkpoint firewall as gateway.