I want to expose you an issue i found using local-proxy-arp in a vpn remote access.
The difference between local proxy-arp and local-proxy-arp is that using normal proxy arp the router sets his mac-address to a REMOTE network IP address, while in local-proxy-arp the router sets its own mac-address to an IP address in his same subnet.
In my case i configured a router cisco 1720 as remote-access-vpn-server in the subnet 192.168.0.0/24, where the default gateway of this network is the 192.168.0.254.
The ra pool couldn't be out of the 192.168.0.0/24 subnet, because clients had configured IP .254 as default gateway and the installation of the vpn-server had to be transparent to normal operations.
If I had configured an external pool, the vpn wouldn't work, because clients would send the traffic to the default gateway and in turn would drop the traffic because he hadn't any route to vpn pool.
Setting a local remote access pool, clients mad arp requests to find IP addresses in the local network but nobody replied them because the vpn-server didn't know the real mac address of the pool's IP.
On cisco routers proxy arp is enabled by default, but 'local-proxy-arp' isn't.
When i enabled local-proxy-arp in interface config mode, clients in local network begun to reply to my pc connected through vpn.
However i noticed that 50% of icmp packets i sent was not received, precisely a packet was delivered and a packet not, alternately.
This was because the vpn-server didn't know the real mac-addresses of vpn clients, so creates arp request to every packet itself.
Solution has been to set static mac-addresses in the arp table of the cisco 1720 vpn-server so that he didn't need to produce arp requests to vpn clients connected and there is no more packet loss.
Hi, We are evaluating using CML for SD-WAN. I am pretty sure VIRL supports running vManage, vEdge, etc as there is a lab in DevNet with these components predefined in a VIRL simualtion.What are the steps to build these components on a new simulation?...
I have the responsibility to test used routers and switches my company will be receiving from other companies . We are are a recycling center and recieve a variety of different gear. I was wondering if someone could tell me a way to thoroughly bench test ...
I'm supposed to see the lxc routem under documentation in UWM but its not available. Neither is the node available on the CML Client.
Is my install broken?
How do I get the node to appear in the CML client as well as the documentation on the U...