One of our customers have a 4240 IPS on which there is one inline pair and 2 promiscuous interfaces.
The inline pair is used between an internet router and a switch on which is connected a pair of ASAs.
The problem happens when we connect the inline pair, sudeenly and after a random period of time ranging from 2 to 4 hours, and although the upload trafic on the internet router is limited by the ISP to 500 Kbps, we see bursts of 6 Mbps and disconnection for the internet link
I have tried to set the virtual sensor inline-TCP-evasion-protection-mode to asymmetric instead of the default set to strict, I think this has solved the problem untill now( first day of monitoring) but I need to know how it resolved it??????
What does the asymmetric mode exactly do? ( Please provide additional information than the original documentation whihc is not very informative)
And how could it solve the problem in my case?
btw I'm using multiple virtual sensors for each of the inline pair and the rest of the two promiscuous interfaces