Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

Assimetric routed packet

Dear All,

I know that the asr-group command permit to a couple of interfaces (belonging to the same group) to re-route a return packet for a connection that

originated through its peer unit.

But the asr works also for the new connections?If a new connection arrive to the peer unit, the peer unit re-route the traffic to the active unit?

Best regards,

Igor.

1 REPLY
New Member

Re: Assimetric routed packet

This is for multi context, both firewall are at active status. NOT FOR active/standby mode

When running in Active/Active failover, a unit may receive a return packet for a connection that originated through its peer unit. Because the security appliance that receives the packet does not have any connection information for the packet, the packet is dropped. This most commonly occurs when the

two security appliances in an Active/Active failover pair are connected to different service providers and the outbound connection does not use a NAT address.

98
Views
0
Helpful
1
Replies