Operational Defect Database

BugZero found this defect 2575 days ago.

WatchGuard Technologies | kA10H000000g3TvSAI

ECMP is not supported for a mixture of static and dynamic routes

Last update date:

5/2/2017

Affected products:

Firebox M200

Firebox M300

Firebox M270

Firebox M370

Firebox M470

Firebox M570

Firebox M670

Firebox M290

Firebox M390

Firebox M400

Firebox M500

Firebox M440

Affected releases:

All

Fireware

11.x

11.1.x

11.10.x

11.10

11.10.1

11.10.2

11.10.3

11.10.4

11.10.5

11.10.6

Fixed releases:

All

Description:

Issue

If you have both static and dynamic routes in your OSPF configuration, and you specify the same metric and distance values for the routes, a conflict occurs. If the link for the default static route fails, the dynamic route activates. However, if the link recovers, the default static route is not added back to the route table. This is because the static and dynamic routes have the same distance and metric values. The Firebox does not support ECMP for a mixture of static and dynamic routes. The Firebox supports: ECMP for dynamic routesECMP for static default routes

Workaround/Solution

If you have both static and dynamic routes, you must specify different metric and distance values for the routes to avoid a conflict. You can only change the metric for dynamic routes, or for static routes that are not default routes. You cannot change the metric for default static routes added for external interfaces. For example, the default static route for an active external interface has a metric of 5. To avoid a conflict, you can assign a metric of 6 to the dynamic route. This list shows the typical metric values for the static default route on an external interface: 5 — Active external interface20 — Unselected active external interface (not involved in Multi-WAN)30 — Modem interface50 — Wireless interface100 — Inactive external interface10/11/12/ (1st/2nd/3rd) — External interfaces in failover mode

Additional Resources / Links

Share:

BugZero® Risk Score

What's this?

Coming soon

Status

Open

Learn More

Search:

...