Thursday, November 9, 2017

Question about ICMP loss

At the college I work for I am responsible for my department's firewalls, but we rely on campus to manage the core routers.
We were switched to a new campus router a year ago, and it drops 5% pings directed to it every 6 minutes. This loss happens on all pings to the same device at the same time regardless of what system is pinging it. This loss causes our routers to think their upstream gateway is down, we have since disabled the ping check. Even their central monitoring system is showing that this is their highest loss system. We are experiencing unusual outages too, where traffic does not get passed and the firewalls freak out.

I asked if the system was at capacity or configured differently, or if they could remove throttling, but their response was:

PingLossBDF is a newer model of hardware than the majority of our BDFs. It's treats ICMP with less priority. We are at 1% CPU, have zero errors on the links, and are extremely nowhere near reaching capacity. My recommendation would be to ping your own equipment.

Am I being unreasonable, or should I just expect that their own monitoring system should high loss and just deal with the frequent outages.



No comments:

Post a Comment