ZyWALL not sending gratuitous ARP on WAN for NAT addresses after failover

mkr
mkr Posts: 5  Freshman Member
Hello,

we have two ZyWALL 1100 with HA Pro in the datacenter. From the provider, we get two uplinks. We publish the servers over 1:1 NAT.

Example:
Gateway (ISP): 1.1.1.1/24
WAN IP (ZyWALL): 1.1.1.2/24
NAT IP: 1.1.1.10/24, 1.1.1.11/24, 1.1.1.12/24 and so on

The NAT IPs are only used on NAT rules and not configured as secondary IPs on WAN interface.

The problem is that on failover the secondary firewall does not send out GARP packets for the NAT IPs. Therefore the switch of the ISP does not know that he has to send packets to the port of the secondary firewall. This means that the servers are not reachable from the Internet until they initiate a connection on their own.

Is this a known problem? Is there a workaround? Should we configure the NAT IPs as IP Aliases of WAN?

Thank you for your help!

All Replies

  • mkr
    mkr Posts: 5  Freshman Member
    Hello again,

    I have to correct myself. It was wrong thinking: the switch does only store MAC and port in its ARP table, not the IP. So one GARP from the WAN interface will suffice.

    The problem seems to be that the firewall does not send one GARP after failover. Can this be confirmed?
  • Zyxel_Can
    Zyxel_Can Posts: 336  Zyxel Employee
    Hi @mkr,

    What is the type of your WAN IP?(DHCP/Static IP/PPPoE) ?
  • mkr
    mkr Posts: 5  Freshman Member

    The WAN type is static IP (Ethernet).
  • Zyxel_Can
    Zyxel_Can Posts: 336  Zyxel Employee

    Hi @mkr,

     

    Can you share some information with us;

     

    1-    Can you share your topology with us for HA setup?

    2-    Can you share your config file with me by private message?

    3-    Can you capture packets from WAN interface when you perform HA failover and send to me by private message?

    (Maintenance > Diagnostics > Packet Capture > Capture)

  • mkr
    mkr Posts: 5  Freshman Member

    thank you for your response. This is the topology:

    I will send you the configuration by private message. I'm not able to send you packet captures at the moment, but I will try to make it happen.
  • Zyxel_Can
    Zyxel_Can Posts: 336  Zyxel Employee
    Hi @mkr,

    I can see GARP requests with your configuration applied.

    Can you also provide me captured packets as well?

Security Highlight