Use last know ARP check for Connectivity Check

PeterUK
PeterUK Posts: 1,150  Guru Member
edited November 2021 in Security Ideas

When Connectivity Check is enabled it send a ARP which it does not need too if the USG has done a ARP check before. When you have many routing rules with a 5 sec check period this can cause a ARP flood which some ISP rate limit to 2-3 ARP a sec causing a drop in connection. The ARP check only then needs to be done if ping check fails.

Also if many routing rules with Connectivity Check use the same IP for a check this can then be checked once for all routing rules instead of pinging the target many times.


1 votes

Active · Last Updated