Coming soon - Get a detailed view of why an account is flagged as spam!
view details

This post has been de-listed

It is no longer included in search results and normal feeds (front page, hot posts, subreddit posts, etc). It remains visible only via the author's post history.

1
ICMP over vpn dropping
Post Body

I am working on a VPN issue with AWS using openwan. Our Palo is configured right but this is what I get back from their side. Has anyone ever seen a similar issue with Palo? I do not believe this is a Palo issue.

We noticed that when using N subnets, (N-1)/N of the traffic are dropped. 

For example, when I try a single subnet (either 10.6.67.157/32 or 10.15.57.0/24), no traffic drop at all. When I try two subnets together, I noticed 50% of the ping got no reply. 

When I try three subnets (10.6.67.157/32, 10.15.57.0/25, 10.15.57.128/25), I noticed more than 50% less than 100% drops. 

My solution is using a single big subnet, 10.6.0.0/12, which contains both 10.6.67.157/32 and 10.15.57.0/24, and the network becomes stable, i.e. no more packet drops. 

Note that 10.6.0.0/12 is a super big subnet. We avoid IP conflicts by doing routing for 10.6.67.157/32 and 10.15.57.0/24 only, instead of routing the whole 10.6.0.0/12.

Author
Account Strength
80%
Account Age
10 years
Verified Email
Yes
Verified Flair
No
Total Karma
338
Link Karma
226
Comment Karma
99
Profile updated: 21 hours ago
Posts updated: 1 week ago

Subreddit

Post Details

We try to extract some basic information from the post title. This is not always successful or accurate, please use your best judgement and compare these values to the post title and body for confirmation.
Posted
3 years ago