<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA Cluster Transparent Mode Dst MAC L2 Lookup Failed in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-cluster-transparent-mode-dst-mac-l2-lookup-failed/m-p/3734206#M1049630</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cluster Transparent Mode (2 units), only 1-2 flows to the same destination host are successful, all others fail.&lt;/P&gt;
&lt;P&gt;If I remove a unit from cluster (anyone), everything is OK.&lt;/P&gt;
&lt;P&gt;When I add a unit to the cluster, cluster is OK and healthy, but only 1-2 connections are OK.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Logs on firewall show a lot of connection with unknown destination:&lt;/P&gt;
&lt;P&gt;Oct 27 2018 19:45:03 DRC-FW3 : %ASA-6-302023: Teardown stub TCP connection for &lt;STRONG&gt;inside324&lt;/STRONG&gt;:10.44.32.201/80 to &lt;STRONG&gt;unknown&lt;/STRONG&gt;:172.22.4.230/50814 duration 0:00:00 forwarded bytes 0 Forwarding or redirect flow removed to create director or backup flow&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also from asp show command I have a lot of: "Destination MAC L2 Lookup Failed"&lt;/P&gt;
&lt;P&gt;What might be the problem with the cluster?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
    <pubDate>Fri, 21 Feb 2020 16:24:20 GMT</pubDate>
    <dc:creator>Eugen Bitca</dc:creator>
    <dc:date>2020-02-21T16:24:20Z</dc:date>
    <item>
      <title>ASA Cluster Transparent Mode Dst MAC L2 Lookup Failed</title>
      <link>https://community.cisco.com/t5/network-security/asa-cluster-transparent-mode-dst-mac-l2-lookup-failed/m-p/3734206#M1049630</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Cluster Transparent Mode (2 units), only 1-2 flows to the same destination host are successful, all others fail.&lt;/P&gt;
&lt;P&gt;If I remove a unit from cluster (anyone), everything is OK.&lt;/P&gt;
&lt;P&gt;When I add a unit to the cluster, cluster is OK and healthy, but only 1-2 connections are OK.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Logs on firewall show a lot of connection with unknown destination:&lt;/P&gt;
&lt;P&gt;Oct 27 2018 19:45:03 DRC-FW3 : %ASA-6-302023: Teardown stub TCP connection for &lt;STRONG&gt;inside324&lt;/STRONG&gt;:10.44.32.201/80 to &lt;STRONG&gt;unknown&lt;/STRONG&gt;:172.22.4.230/50814 duration 0:00:00 forwarded bytes 0 Forwarding or redirect flow removed to create director or backup flow&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also from asp show command I have a lot of: "Destination MAC L2 Lookup Failed"&lt;/P&gt;
&lt;P&gt;What might be the problem with the cluster?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 16:24:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cluster-transparent-mode-dst-mac-l2-lookup-failed/m-p/3734206#M1049630</guid>
      <dc:creator>Eugen Bitca</dc:creator>
      <dc:date>2020-02-21T16:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Cluster Transparent Mode Dst MAC L2 Lookup Failed</title>
      <link>https://community.cisco.com/t5/network-security/asa-cluster-transparent-mode-dst-mac-l2-lookup-failed/m-p/3734242#M1049644</link>
      <description>&lt;P&gt;if possible post both the ASA configuration and also output of below commands :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;what is the the models of both the units.&lt;/P&gt;
&lt;PRE&gt;&lt;STRONG class="cBold"&gt;show version&lt;BR /&gt;show arp-inspection&lt;BR /&gt;&lt;/STRONG&gt;&lt;STRONG class="cBold"&gt;show mac-address-table&lt;/STRONG&gt;&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;do you have any network topology ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 27 Oct 2018 21:43:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cluster-transparent-mode-dst-mac-l2-lookup-failed/m-p/3734242#M1049644</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2018-10-27T21:43:27Z</dc:date>
    </item>
    <item>
      <title>Re: ASA Cluster Transparent Mode Dst MAC L2 Lookup Failed</title>
      <link>https://community.cisco.com/t5/network-security/asa-cluster-transparent-mode-dst-mac-l2-lookup-failed/m-p/3734282#M1049667</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;DRC-FW3/DRCFW-3(config)# cluster exec show version | i Version&lt;BR /&gt;DRCFW-3(LOCAL):*******************************************************&lt;BR /&gt;Cisco Adaptive Security Appliance Software Version 9.8(3)14 &lt;BR /&gt;Firepower Extensible Operating System Version 2.2(2.107)&lt;BR /&gt;Device Manager Version 7.7(1)151&lt;BR /&gt;Baseboard Management Controller (revision 0x1) Firmware Version: 2.4&lt;BR /&gt;&lt;BR /&gt;DRCFW-4:**************************************************************&lt;BR /&gt;Cisco Adaptive Security Appliance Software Version 9.8(3)14 &lt;BR /&gt;Firepower Extensible Operating System Version 2.2(2.107)&lt;BR /&gt;Device Manager Version 7.7(1)151&lt;BR /&gt;Baseboard Management Controller (revision 0x1) Firmware Version: 2.4&lt;BR /&gt;DRC-FW3/DRCFW-3(config)#&lt;BR /&gt;&lt;BR /&gt;DRC-FW3/DRCFW-3(config)# sh arp-inspection &lt;BR /&gt;interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; arp-inspection&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; miss&lt;BR /&gt;----------------------------------------------------&lt;BR /&gt;mgmt&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; disabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&lt;BR /&gt;outside124&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; disabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&lt;BR /&gt;inside324&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; disabled&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -&lt;BR /&gt;&lt;BR /&gt;DRC-FW3/DRCFW-3(config)#&amp;nbsp; sh arp&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside124 10.44.32.2 188b.9da8.407f &amp;nbsp;&amp;nbsp; &amp;nbsp;207&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;//SVI on Core-S3&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; outside124 10.44.32.3 188b.9da8.3f7f &amp;nbsp;&amp;nbsp; &amp;nbsp;6080&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;//SVI on COre-S4&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; inside324 10.44.32.201 00c0.b7ff.0899 &amp;nbsp;&amp;nbsp; &amp;nbsp;515&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;//Testing Host&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; cluster 10.150.255.18 188b.9d1a.f650 &amp;nbsp;&amp;nbsp; &amp;nbsp;10838&lt;BR /&gt;&lt;BR /&gt;DRC-FW3/DRCFW-3(config)# show mac-address-table &lt;BR /&gt;interface&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; mac&amp;nbsp; address&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Age(min)&amp;nbsp;&amp;nbsp;&amp;nbsp; bridge-group&lt;BR /&gt;----------------------------------------------------------------------------------------------------&lt;BR /&gt;outside124&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 188b.9da8.3f7f&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 4&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;BR /&gt;outside124&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 188b.9da8.407f&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;BR /&gt;inside324&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 00c0.b7ff.0899&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dynamic&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 3&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&lt;BR /&gt;DRC-FW3/DRCFW-3(config)# &amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Sun, 28 Oct 2018 05:06:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-cluster-transparent-mode-dst-mac-l2-lookup-failed/m-p/3734282#M1049667</guid>
      <dc:creator>Eugen Bitca</dc:creator>
      <dc:date>2018-10-28T05:06:39Z</dc:date>
    </item>
  </channel>
</rss>

