Is ARP done at the boot code level?

PeterUK
PeterUK Posts: 2,651  Guru Member
First Anniversary 10 Comments Friend Collector First Answer
edited April 2021 in Security

Since updating to the to 4.39 I'm see a spike in my BQM (ping to me every 1000ms) I did a test with my USG40 that got updated to 4.39 but I'm wondering if ARP is controlled in boot code that got updated? I switched back to 4.38 but thinking the boot code stays the same doing that and the firmware runs on top of the boot code? This never happened before and my ISP has a ARP flood limit which looks like the USG is now doing.

Here is a Wireshark showing the problem that happens randomly (many hours to happen) to cause a ping spike where the ping reply gets stuck in the buffer waiting for ARP.


Accepted Solution

  • PeterUK
    PeterUK Posts: 2,651  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓
    Its seems it was caused by a switch and ARP was not forwarding correctly.

All Replies

  • PeterUK
    PeterUK Posts: 2,651  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    edited September 2020

    Wondering If my switch is to blame for this as a packet capture on the USG40 vs a upstream switch packet capture don't match in fact going be the USG40 capture its trying to get the gateway MAC and still forwarding ping replies.

    So I rebooted the switch that I think is causing the issue and see how it goes

    USG40


    upstream switch



  • PeterUK
    PeterUK Posts: 2,651  Guru Member
    First Anniversary 10 Comments Friend Collector First Answer
    Answer ✓
    Its seems it was caused by a switch and ARP was not forwarding correctly.

Security Highlight