Jump to content

Recommended Posts

Posted

So at home I have recently bought a pair of ASA 5505's.

 

I have a strange issue that if I am using an internal Layer3 switch for IntervLan routing I get drops of packets to the ASA and I'm thinking this is ARP related.

 

To back up this issue if I check the ARP table of the ASA where the internal Layer 3 switch is connected I imediatley see the MAC address change in the table, one MAC address works the other does not. I have tried 2 different switches, one a EdgeSwitch Lite24 and the other is a HPE 1920. I've also tried using a vYOS instance in a VM and I get the same issue but I did not check ARP tables.

 

 

I have the ASA's in a HA group but even with only one powered on I still get this issue. Being ASA 5505's I can not get stateful HA but as I've only got one switched on during testing.

 

Anyone got any ideas :confused:

Posted

So I sort of fixed the issue by setting a static mac ARP entry on the ASA firewall for the IP address.

 

Long term it does not give me the resiliency in HA I'd like which my virtual firewalls did.

Posted
Can't speak for ASA, but in their switches the MAC table timeout is five minutes and the ARP table timeout if four hours. I ran into some issues with asymmetric routing and changing the ARP timeout to being sooner than the MAC solved it - in my case I set it to four minutes.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...