NR5111 - Router blackholes packets if client ignores ICMP redirects

Options

Dear Zyxel community,

I have hit something where I wanted to confirm if it is intended behavior or a bug.

The whole network is behind one of the ports of the router. On that network there is also an IP address that acts as an gateway to a remote location via VPN.

Using this setup works fine with clients that respect ICMP redirects or when adding a static route to a clients config.

When the client ignores ICMP redirects the setup does not work. Packet capture shows reoccurring TCP retransmissions and ICMP redirects. It ends with the client giving up (TCP reset).

Let me know if this is intended or not. If not is there is any chance of a fix being published?

Kind regards

All Replies

  • Bob_C
    Bob_C image  Master Member
    5 Answers First Comment Friend Collector Seventh Anniversary
    Options

    Hi caymenislands777,

    Could you please clarify how the devices are physically or logically connected?

    Specifically, do the clients connect directly to the NR5111 along with the VPN gateway (Topology A), or do the clients connect through the VPN gateway before reaching the NR5111 (Topology B)?

    (Topology A)
    Clients ------ NR5111 ))(( Operator's network
    VPN Gateway -- (both on the same local network)

    (Topology B)
    Clients -- VPN Gateway -- NR5111 ))(( Operator's network

    I ask because based on your initial description, it sounds like Topology B; however, the symptoms you described (such as relying on ICMP redirects and TCP retransmissions) strongly point to Topology A.

    Clearing this up will help us identify why the routing is behaving this way. Thanks!

    Regards,

    Bob

  • caymenislands777
    caymenislands777 image  Freshman Member
    First Comment
    Options

    Hi Bob,

    it is topology A. Both the clients (that try to connect to a remote location) and the VPN gateway (Wireguard LXC container) are locally connected to the NR5111.

    Kind regards

Consumer Product Help Center