cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
495
Views
3
Helpful
7
Replies

ECMP behaviour on FMC managed FTD 7.2.4

atsukane
Level 1
Level 1

Hi All,,

We've just enabled ECMP with two 1Gbps AWS direct connect links over the weekend.

The ECMP zone is created in the global routing table, we didn't use VRF, and added equal cost static routes destined to AWS networks in the global routing table. Both interfaces belong to the same security zone.

I would have thought that the traffic will be load balanced and we'd see similar level of utilisation, however, it would appear from the netflow stats that one interface is more heavily used that the other. Any ideas?

atsukane_0-1706527303065.png

 

Many thanks,

 

 

2 Accepted Solutions

Accepted Solutions

tvotna
Spotlight
Spotlight

The difference is dramatic, but let me ask: is it a production with lots of random connections or you're testing the setup by generating some traffic? The thing is: the firewall distributes connections over ECMP links by 6-tuple hash (the hash takes ingress interface into consideration), and not packets, so utilization might be unequal because of this.

 

View solution in original post

Thanks.

I've checked and the AWS-1 always have the asterisk 

 

View solution in original post

7 Replies 7

tvotna
Spotlight
Spotlight

The difference is dramatic, but let me ask: is it a production with lots of random connections or you're testing the setup by generating some traffic? The thing is: the firewall distributes connections over ECMP links by 6-tuple hash (the hash takes ingress interface into consideration), and not packets, so utilization might be unequal because of this.

 

the load balance not per-packet but per destination IP and L4 destination Port (if source IP and L4 port is same)
from cisco doc.

Screenshot (96).png

atsukane
Level 1
Level 1

thank you both. oddly, as the day went by, it seems to be handling similar amount of traffic now.

We'll keep on monitoring and see how this goes. 

atsukane
Level 1
Level 1

we've monitored throughout yesterday and this morning and now the ECMP seems to be doing what it supposed to do.

 

atsukane_2-1706610041299.png

 

(@tvotna this is for a production with lots of random connections.)

Only thing is that we have an "*" asterisk on one of the routes, this is not just for this network in the screenshot but for all other routes, which make us think one is preferred over the other despite the equal metric.

atsukane_0-1706609744798.png

 

no friend 
the "*" meaning that this route will use for next packet 
now use different destination and check * is it appear with same route or not
MHM

Thanks.

I've checked and the AWS-1 always have the asterisk 

 

atsukane
Level 1
Level 1

Just reporting back after monitoring the behaviour for a week and it would appear it sorted itself out.

atsukane_3-1706877991044.png

atsukane_1-1706877890218.png

atsukane_0-1706878145063.png

 

 

Review Cisco Networking for a $25 gift card