We tried to run BGP through our WG, with our provider's peer on the external side and our peer on the Trusted port. The BGP session came right up, but traffic did not flow smoothly; there would be a 20- to 30-second stall, then it would flow, then another stall, etc. This was visible with ping, traceroute, and websurfing. We rolled back to static routes and the problem went away--but not entirely.
When pinging from a router directly connected to the Trusted interface to either the WG's Trusted interface or a router directly connected to the External interface, we get delays in a consistent pattern: 100 packets get through, 1 is dropped, 100 get through, 1 is dropped, etc.
Pinging from the WG's External interface to the router directly connected to it goes without any loss, even flood-pinging.
The WG is very lightly loaded (CPU utilization ~3%, 10 Mbps peak traffic).
My hunch is that the router interface and WG Trusted interface are suffering from a speed mismatch. The router has a GigE int, the WG a FastE, and both are set to auto speed, auto duplex.
Anyone have a better theory?
When pinging from a router directly connected to the Trusted interface to either the WG's Trusted interface or a router directly connected to the External interface, we get delays in a consistent pattern: 100 packets get through, 1 is dropped, 100 get through, 1 is dropped, etc.
Pinging from the WG's External interface to the router directly connected to it goes without any loss, even flood-pinging.
The WG is very lightly loaded (CPU utilization ~3%, 10 Mbps peak traffic).
My hunch is that the router interface and WG Trusted interface are suffering from a speed mismatch. The router has a GigE int, the WG a FastE, and both are set to auto speed, auto duplex.
Anyone have a better theory?