Is ARP done at the boot code level?
Since updating to the to 4.39 I'm see a spike in my BQM (ping to me every 1000ms) I did a test with my USG40 that got updated to 4.39 but I'm wondering if ARP is controlled in boot code that got updated? I switched back to 4.38 but thinking the boot code stays the same doing that and the firmware runs on top of the boot code? This never happened before and my ISP has a ARP flood limit which looks like the USG is now doing.
Here is a Wireshark showing the problem that happens randomly (many hours to happen) to cause a ping spike where the ping reply gets stuck in the buffer waiting for ARP.

Accepted Solution
-
Its seems it was caused by a switch and ARP was not forwarding correctly.0
All Replies
-
Wondering If my switch is to blame for this as a packet capture on the USG40 vs a upstream switch packet capture don't match in fact going be the USG40 capture its trying to get the gateway MAC and still forwarding ping replies.
So I rebooted the switch that I think is causing the issue and see how it goes
USG40

upstream switch

0 -
Its seems it was caused by a switch and ARP was not forwarding correctly.0
Categories
- All Categories
- 439 Beta Program
- 2.8K Nebula
- 205 Nebula Ideas
- 127 Nebula Status and Incidents
- 6.4K Security
- 522 USG FLEX H Series
- 330 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.3K Wireless
- 49 Wireless Ideas
- 6.9K Consumer Product
- 290 Service & License
- 462 News and Release
- 90 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.5K FAQ
- 34 Documents
- 86 About Community
- 98 Security Highlight
Guru Member