Network Management

last person joined: yesterday 

Keep an informative eye on your network with HPE Aruba Networking network management solutions
Expand all | Collapse all

increased in traffic from DMZ Controller to remote controllers over GRE Tunnel

This thread has been viewed 3 times
  • 1.  increased in traffic from DMZ Controller to remote controllers over GRE Tunnel

    Posted Feb 16, 2017 06:01 PM

    We have a large network of controllers connected via corporate network using telstra services.

    We also have a controller in the DMZ for internet access of untrusted devices.

    the remote controllers each have a GRE tunnel back to the DMZ controller for the untrusted users, eg guest or ipad/phone internet access.

    We had an interent service provider failure at 6am, a(propably unrelated?), but at 9:30 am there was a huge increase in traffic from the DMZ controller out to the remote controllers via their respective GRE tunnels.

    This resulted in some of the smaller bandwidth sites being conjested.

    Is there any reason why conversation from DMZ Controller to remote controller shoud suddenly spike for 1-2 hrs, then stop.



  • 2.  RE: increased in traffic from DMZ Controller to remote controllers over GRE Tunnel

    EMPLOYEE
    Posted Feb 16, 2017 06:31 PM
    If any of those RAP sites have wired traffic, make sure that the VLAN has bcmc-optimization enabled so that it does not forward wired broadcasts to every site.


  • 3.  RE: increased in traffic from DMZ Controller to remote controllers over GRE Tunnel

    Posted Feb 16, 2017 08:24 PM

    The remote sites all have a local controller.

    It is teh traffic on the GRE tunnel from DMZ controller to the remote Contoller that spiked



  • 4.  RE: increased in traffic from DMZ Controller to remote controllers over GRE Tunnel

    EMPLOYEE
    Posted Feb 16, 2017 08:43 PM
    It is tough to understand what could be going on without knowing everything about your topology...


  • 5.  RE: increased in traffic from DMZ Controller to remote controllers over GRE Tunnel

    Posted Feb 16, 2017 08:48 PM

    Theory - 

    DMZ controller, connects to the internet for "untrusted user" who come in via GRE tunnels from multiple site local controllers using a corporate network.

    BCMC optimization is not checked for the IP/Vlans that go over the tunnel.

    If the internet connection were to go down for extended period, would this cause broadcast traffic back to all controllers over those VLANs and therefore over the tunnels, back to local servers at sites?

     

    Any suggestions/comments appreciated.

     

    Also, what impact would it have if I checked this box now.?

    Would it impact the connectivity/network?



  • 6.  RE: increased in traffic from DMZ Controller to remote controllers over GRE Tunnel

    EMPLOYEE
    Posted Feb 16, 2017 09:16 PM

    I honestly do not know about your network, so I cannot comment on what a single option will or will not do to it.