Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Thecoder
Collaborator

when we added new pbr rules,The gateway did not answer 10 minutes

hello

when we added new pbr rules,The gateway did not answer ssh,web interface for 10 minutes. and vpn users droped and can not reconnect 10 minutes. but imternals client can connect to the internet and the gateway gives arp reply.

version informaiton: R80.10 take 112

we tried at take 103 and took same results

thanks

2 Replies
Timothy_Hall
Champion Champion
Champion

There have been SecureXL issues with PBR and dynamically-updating routes in the past, although PBR is fully supported with SecureXL in R80.10 by default as stated here: sk109741: Packets are not routed correctly when PBR is configured and SecureXL is enabled.  It is possible that while configuring PBR an incomplete configuration started impacting traffic and confused SecureXL.  Try this:

fwaccel off   (If your firewall has more than 8 cores schedule an outage window before doing this)

(add PBR routes & test)

fwaccel on

--
Second Edition of my "Max Power" Firewall Book
Now Available at http://www.maxpowerfirewalls.com

Gateway Performance Optimization R81.20 Course
now available at maxpowerfirewalls.com
Thecoder
Collaborator

we didnt use securexl.when i opened securexl, problem was solved. thanks Tim

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events