Description

Some Google cloud connection profiles include default settings for UDP flood with a threshold between 1000 and 1500 pps.

This may result in packet loss over the VPN if the UDP4500 packet rate exceeds the threshold.

Symptoms

  • Packet loss over the VPN.
  • No high CPU on the VPN peers.
  • No explicits drops from flow on the clear traffic going into the tunnel.
  • Packet loss may be more severe during busier times or after an overall increase in traffic over the VPN.
  • PCAPs of the encrypted VPN traffic will show sections of missing ESP sequence numbers on one or both sides of the VPN.

Solution

Google cloud support will be able to confirm if the flood is being triggered, and they will be able to assists with creating a ticket for the IPs of the VPN endpoints to be added to the whitelist.

Modification History

2025-02-03 : Article Created