- Bronze, 100 points or more
We have 2 ASA5520 firewalls setup as Active/Failover running in single router mode.
IOS is version 8.0(4)
Doing a capture we continue to see one firewall talking to the other (as expected) but the communiction is via IP Protocol 105 (which appears to be SCPS - link and details below).
Here is the output as seen on the firewall cli
1: 13:27:51.355923 802.1Q vlan#10 P0 10.4.1.1 > 10.4.1.2: ip-proto-105, length 44
2: 13:27:52.311232 802.1Q vlan#10 P0 10.4.1.2 > 10.4.1.1: ip-proto-105, length 44
3: 13:27:56.356350 802.1Q vlan#10 P0 10.4.1.1 > 10.4.1.2: ip-proto-105, length 44
4: 13:27:57.311278 802.1Q vlan#10 P0 10.4.1.2 > 10.4.1.1: ip-proto-105, length 44
Are we reading this incorrectly?
Is this a bug that has been reported and fixed in a more recient version?
Here is the google search result and explanation:
SCPS is a protocol suite designed allow communication over challenging environments. Originally developed jointly by NASA and DoD’s USSPACECOM to meet their various needs and requirements. These protocols have been found to be applicable in meeting the needs of the satellite and wireless communities.
Is this a failover pair?
The active and standby ﬁrewalls determine a failure by sending hello messages to each other at
regular intervals (every 15 seconds by default). These messages are sent over the failover cable
(if present) or the LAN-based failover interface to detect failures of an entire ﬁrewall. The hellos are
also sent on all interfaces conﬁgured for failover so that the ﬁrewall peer can determine the health of
each interface. These messages are sent as short packets using IP protocol 105.