Retransmissions (Port 179, BGP, IPv6) on Site-to-Site capture when using warm spare configuration

ksumann
Getting noticed

Retransmissions (Port 179, BGP, IPv6) on Site-to-Site capture when using warm spare configuration

Hello everyone,

 

can somebody confirm this?

If i do a packet capture on interface "Site-to-Site VPN" on a spoke, i have a lot of TCP retransmissions with packets using IPv6 and Port 179 (BGP) when the concentrator is configured in warm spare mode.

 

Those retransmissions doesn't exist when the concentrator is stand alone.

 

ksumann_0-1727452451961.png

 

vs

 

ksumann_1-1727452671388.png

 

9 Replies 9
RaphaelL
Kind of a big deal
Kind of a big deal

I don't know what MX version you are running but I was seeing the same behavior on MX 18.107.6 

 

I couldn't care less about ipv6 so I didn't bother opening a case.

ksumann
Getting noticed

I'm using 18.107.2 and i want to save the extra traffic those retransmission causes.

Do you currently use another version and the issue is gone?

RaphaelL
Kind of a big deal
Kind of a big deal

Went to a different architecture with HA/Warm spare. Like mentionned by ww , don't think this is supported yet in any version.

ww
Kind of a big deal
Kind of a big deal

I supose that is incoming traffic?

Because warm spares dont support ipv6 so they dont reply to any ipv6 traffic

 

RaphaelL
Kind of a big deal
Kind of a big deal

Yes that seems to be the case ! Good point

ksumann
Getting noticed

But isn't that the BGP traffic by the MX /AutoVPN itself? How does BGP even work then? In the same capture there are no IPv4 BGP packets.

RaphaelL
Kind of a big deal
Kind of a big deal

Do you have eBGP configured on your Hub ? if so , BGPv4 must be running

ksumann
Getting noticed

SDWAN -> Routing -> BGP is not enabled. Because of the firmware version / MX Hardware i'm not even able to enable it.

 

 

ksumann
Getting noticed

Does anyone know if this is fixed in a newer version?

Or is it safe so "disable" those packets with a firewall rule? Or is there another option to disable it?

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco account. If you don't yet have a Cisco account, you can sign up.
Labels