Hi Guys!
The firewall loses the first packet when I use the backup link to test ping to 8.8.8.8 or 1.1.1.1. We analyzed the logs and found that the first packet loss is associated with an ARP request for the destination IPs. Is this a natural behavior of Sophos or is it a BUG?
Note. When we switch the link to operate as active, it does not send ARP requests to the destinations and does not lose the first ICMP packet.
Logs:
Hi,
Thank you for reaching out to Sophos Community.
Have you tried to use any how-to videos, documentation, Sophos Assistant, or KBA to try to check the issue?
This is normal, as the first ping usually does its ARP function.
You may check the following link for reference:
www.pathsolutions.com/.../PathSolutions-Why-Does-the-First-Ping-Usually-Fail.pdf
Erick Jan
Global Community Engineer, Support & Services
Are you a Sophos Partner? | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question, please use the 'Verify Answer' button.
The award-winning home for Sophos Support videos! - Visit Sophos Techvids
But the ARP request only occurs for destinations within the same broadcast domain, in this case the destination is on the internet. Nevertheless, following this, after the first ARP population, the next ping attempt would not experience packet loss. What raises my doubt is that this only happens on the link configured as backup. If I change it to the primary link, it no longer loses the first packet, and I don't see the ARP request in the tcpdump. Based on this, what do you think might be happening?
Thank you for your support
Hi Lukas,
As the issue is only happening in the backup link.
I would recommend considering checking the logs/errors and comparing the settings between the primary and backup links.
Also, check its configurations and the backup link stability and further analyze the network traffic.
You may also check the following KB
Sophos Firewall: ISP Gateway Fluctuation
Erick Jan
Global Community Engineer, Support & Services
Are you a Sophos Partner? | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question, please use the 'Verify Answer' button.
The award-winning home for Sophos Support videos! - Visit Sophos Techvids
Hi Lukas Venuti As far as I know, manually setting up the Gateway with the backup type, will remove the default route from the XG routing table for that Interface Gateway.
When you are generating the PING with binding an Interface, there are no matching routes for that IP on that interface, and due to that, it will blindly trigger an ARP request for any IP that is not it's own.
When the Link is active, the default route is there on that same Interface via the next hope with gateway IP, and due to that reason PING requests to any outside IP, the XG routing table knows how to reach that IP via which next hope.
Regards,
Vishal Ranpariya
Technical Account Manager | Global Customer Experience
Sophos Support Videos | Knowledge Base | @SophosSupport | Sign up for SMS Alerts |
If a post solves your question, use the 'Verify Answer' link.