Forum Discussion

Amresh008's avatar
Amresh008
Icon for Nimbostratus rankNimbostratus
Jun 13, 2017

Is Mac masquerade necessary ?

I have a pair of F5 7200v configured in single arm mode setup acting as Active/Standby. Both of them are connected to nexus 7k distribution switches and the latter are connected to each other via trunk port. Both the distribution switches have ARP entries for the VIPs on the F5 load balancer. "sh ip arp | in vip-ip" gives the same mac address for all the VIPs.

 

I do not see a reason why I should configure mac masquerade in this case! Please explain.

 

2 Replies

  • tbyerly_229301's avatar
    tbyerly_229301
    Historic F5 Account

    Generally you do not need it.

     

    "Ordinarily a failover to a new Active system will result in issuance of Gratuitous ARP broadcasts with the newly Active system’s MAC address supplied as L2 address for each L3 Failover Address (Virtual Addresses/VIPS, Floating Self-IP’s, NAT addresses)"

     

    Some devices ignore Gratuitous ARP's..

     

    So..MAC Masquerading solves these problems by using a common L2 address shared by BIG-IP devices for L3 traffic; no ARP entry is changed, only Switch’s MAC address/port forwarding table.

     

  • Depends

     

    IF the Nexus 7k is using F1 line cards, and IF the linecards are to remain default MAC update limits to < 100 / second, and IF you have more than 100 virtual + floating addresses, YES you very much need mac masquerading.

     

    You really don't want to ask me how I know this....

     

    //Jan