[XS1930-12HP] CARP MAC gets falsely marked as static
I have set up two Virtual IPs using CARP on two separate OPNsense Firewalls:
WAN was assigned the MAC 00:00:5e:00:01:01 and LAN was assigned the MAC 00:00:5e:00:01:02
Firewall 1 is connected to Port 10 on the Switch and Firewall 2 is connected to Port 9.
For whatever reason, only the WAN VIP works properly and has it's MAC registered as Dynamic on the Switch. The LAN MAC wrongfully gets marked as "Type" Static.
Because of this, the OPNsense High Availability is broken. When the CARP MAC switches form one Firewall to the other, the Port on which the Switch forwards the traffic won't change and is stuck on Static. It will only work again if I restart the Switch.
Firmware V4.80(ABQF.4)
All Replies
-
Hi @Fabian_S
We have experienced a similar issue on VMware vMotion and this issue is fixed by changing arp-learning mode. Could you help to change the arp-learning mode to ARP-request? Path: Menu > NETWORKING > ARP Setup > ARP Learning.
If the issue still exist after changing, please let me know.
Zyxel Melen0 -
Thanks for getting back to me!
I changed the setting about a week ago but unfortunately, the issue persists. I don't know why Changing an ARP setting would affect the MAC Table anyway? The Port stayed on "Dynamic" for some time but now it's stuck on "Static" again.
Currently, my nearly 700€ switch is unusable because it disturbs my firewall cluster…
0 -
Hi @Fabian_S
May I confirm that you have changed the ARP Learning mode to ARP request option, but the issue still exists?
If so, please let us know and allow us to replicate in our lab first.
Zyxel Melen0 -
Yep, I changed the ARP Learning mode, saved the config and restarted the switch. The after the reboot, the port was set to Dynamic but changed to Static after a while.
But just now I checked again and it changed back to Dynamic? (yesterday it was on Static)I run OPNsense (where the VIP is configured) on proxmox, with the LAN vmbr0 Linux bridge assigned as Interface
OPNsense Virtual IPs:
OPNsense Interface assignments:
the LAN Interface is bound to the vmbr0 bridge on the proxmox VM:
Please note, that only the VIP 10.0.0.250 has this problem, the WAN VIP 172.16.1.6 doesn't. The WAN Interface is a proxmox SDN VLAN VNet in the VLAN 1000 (where as the 10.0.0.250 VIP is in the access VLAN 1 so that all clients can use it as gateway).Port VLANs:
0 -
Just checked and today it's on Static again…
0 -
And today it's back to Dynamic…
This is a critical bug which currently renders the switch useless. I can't fathom how the Port type can switch to Static in the first place, the documentation clearly states that it should also be Static if a MAC Forwarding rule was created manually.
0
Categories
- All Categories
- 442 Beta Program
- 2.9K Nebula
- 220 Nebula Ideas
- 128 Nebula Status and Incidents
- 6.5K Security
- 606 USG FLEX H Series
- 344 Security Ideas
- 1.7K Switch
- 84 Switch Ideas
- 1.4K Wireless
- 52 Wireless Ideas
- 7K Consumer Product
- 299 Service & License
- 482 News and Release
- 92 Security Advisories
- 31 Education Center
- 10 [Campaign] Zyxel Network Detective
- 4.8K FAQ
- 34 Documents
- 87 About Community
- 105 Security Highlight
Freshman Member


Zyxel Employee







