Hello all,
I've been tasked to setup up FWLB with CSS 11503's as shown below. The issue is that intranet workstations use VPN client software when connecting to certain sites through the Internet and other times they use http or https (for connection to different sites). Because no flow is setup for ipsec and ECMP uses per packet routing for non TCP/UDP traffic, I'm concerned that load balancing through the firewalls will occur on a per packet basis. If that is true, stateful inspection in the firewalls will block asymmetrical traffic flows.
Is my understanding correct? And, if so, is there a way to configure the CSS units to deal with this?
Thanks in advance.
(sorry for the dots in the drawing but the spaces kept getting deleted)
. -------------
.| Internet |
. -------------
..........|
. -------------------
.| CSS-outside |
. -------------------
.............|
.----------------------
........|...............|
.---------......--------
.| FW1 |.....| FW2 |
.---------......--------
.......|................|
.----------------------
............|
..-----------------
.| CSS-inside |
..-----------------
............|
..------------
.| Intranet |
..------------