<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi,From the command reference in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685969#M192050</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;From the command reference:-&lt;/P&gt;&lt;P&gt;"By default, the ASA does not replicate HTTP session information when Stateful Failover is enabled. Because HTTP sessions are typically short-lived, and because HTTP clients typically retry failed connection attempts, not replicating HTTP sessions increases system performance without causing serious data or connection loss. The &lt;B class="cCN_CmdName"&gt; failover replication http&lt;/B&gt; command enables the stateful replication of HTTP sessions in a Stateful Failover environment, but could have a negative affect on system performance."&lt;/P&gt;&lt;P&gt;Refer:-&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/A-H/cmdref1/f1.html#pgfId-2014541&lt;/P&gt;&lt;P&gt;Also . HTTP inspection would not have any effect on the stateful connection replication on the failover.&lt;/P&gt;&lt;P&gt;I hope this answers your query. If you have any other query , please let me know.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
    <pubDate>Sat, 02 May 2015 03:43:06 GMT</pubDate>
    <dc:creator>Vibhor Amrodia</dc:creator>
    <dc:date>2015-05-02T03:43:06Z</dc:date>
    <item>
      <title>ASA HTTP connection replication question</title>
      <link>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685968#M192049</link>
      <description>&lt;P&gt;I'm assessing the potential service impact of failing over from one ASA to another with HTTP replication disabled.&lt;/P&gt;&lt;P&gt;There is some concern that HTTP flows may be broken or disrupted when we failover&lt;/P&gt;&lt;P&gt;Surely HTTP is just an application running over TCP and the connection table is replicated by default in a stateful failover pair so I'm struggling to see how HTTP would be affected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is HTTP replication only relevant if you have HTTP inspection enabled and all that inspection info can be replicated?&lt;/P&gt;&lt;P&gt;Cheers, Dom&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:52:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685968#M192049</guid>
      <dc:creator>d-fillmore</dc:creator>
      <dc:date>2019-03-12T05:52:24Z</dc:date>
    </item>
    <item>
      <title>Hi,From the command reference</title>
      <link>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685969#M192050</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;From the command reference:-&lt;/P&gt;&lt;P&gt;"By default, the ASA does not replicate HTTP session information when Stateful Failover is enabled. Because HTTP sessions are typically short-lived, and because HTTP clients typically retry failed connection attempts, not replicating HTTP sessions increases system performance without causing serious data or connection loss. The &lt;B class="cCN_CmdName"&gt; failover replication http&lt;/B&gt; command enables the stateful replication of HTTP sessions in a Stateful Failover environment, but could have a negative affect on system performance."&lt;/P&gt;&lt;P&gt;Refer:-&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/A-H/cmdref1/f1.html#pgfId-2014541&lt;/P&gt;&lt;P&gt;Also . HTTP inspection would not have any effect on the stateful connection replication on the failover.&lt;/P&gt;&lt;P&gt;I hope this answers your query. If you have any other query , please let me know.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Sat, 02 May 2015 03:43:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685969#M192050</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-02T03:43:06Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor, Thanks for taking</title>
      <link>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685970#M192051</link>
      <description>&lt;P&gt;Hi Vibhor, Thanks for taking the time to respond, but this doesn't answer my question.&lt;/P&gt;&lt;P&gt;I always read as much of the documentation available&amp;nbsp;as possible before posting.&lt;/P&gt;&lt;P&gt;Cheers, Dom&lt;/P&gt;</description>
      <pubDate>Sat, 02 May 2015 07:36:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685970#M192051</guid>
      <dc:creator>d-fillmore</dc:creator>
      <dc:date>2015-05-02T07:36:37Z</dc:date>
    </item>
    <item>
      <title>Hi,Okay. Let me answer this</title>
      <link>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685971#M192052</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Okay. Let me answer this as per the query.&lt;/P&gt;&lt;P&gt;HTTP connections are not replicated to the Standby unit on Stateful Failover without the "failover http replication" command enabled.&lt;/P&gt;&lt;P&gt;HTTP inspection is irrelevant to the connection being replicated or not on the HA pair.&lt;/P&gt;&lt;P&gt;Let me know if any other queries.&lt;/P&gt;&lt;P&gt;Thanks ad Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 May 2015 03:36:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685971#M192052</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-03T03:36:43Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor,Are the HTTP</title>
      <link>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685972#M192053</link>
      <description>&lt;P&gt;Hi Vibhor,&lt;/P&gt;&lt;P&gt;Are the HTTP connections we're talking about connections to the ASA, or through the ASA?&lt;/P&gt;&lt;P&gt;HTTP is a layer 7 Protocol. If the TCP connection table is replicated between ASAs then I would expect HTTP to function uninterrupted though a pair of ASAs if you failed them over from one to the other, much like an SSH session, which would stay up.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you see what I'm getting at? If you replicate TCP connections between both devices, anything that runs on top of TCP should subsequently be replicated&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers, Dom&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 03 May 2015 09:03:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685972#M192053</guid>
      <dc:creator>d-fillmore</dc:creator>
      <dc:date>2015-05-03T09:03:33Z</dc:date>
    </item>
    <item>
      <title>Hi,I am referring to the</title>
      <link>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685973#M192054</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am referring to the Connections through the ASA device.&lt;/P&gt;&lt;P&gt;You need to understand that when we are talking about about HTTP connection it talks about the HTTP service which works on port 80.&lt;/P&gt;&lt;P&gt;So , all the port 80 connections will not be replicated to the Standby Unit until and unless this command is enabled on the ASA device.&lt;/P&gt;&lt;P&gt;Check this Statement from the same link:-&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;"To enable HTTP (port 80) connection replication"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/asa/asa-command-reference/A-H/cmdref1/f1.html#pgfId-2014541&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Sun, 03 May 2015 10:55:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685973#M192054</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-03T10:55:49Z</dc:date>
    </item>
    <item>
      <title>Ah OK. So by default, all TCP</title>
      <link>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685974#M192055</link>
      <description>&lt;P&gt;Ah OK.&amp;nbsp;So by default, all TCP connections &lt;EM&gt;except&lt;/EM&gt; on port 80 are replicated and you need to explicitly enable replication of port 80 by using HTTP replication?&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 07:02:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685974#M192055</guid>
      <dc:creator>d-fillmore</dc:creator>
      <dc:date>2015-05-04T07:02:39Z</dc:date>
    </item>
    <item>
      <title>Hi,Yes , you are correct</title>
      <link>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685975#M192056</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Yes , you are correct.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 07:07:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685975#M192056</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-04T07:07:43Z</dc:date>
    </item>
    <item>
      <title>Thanks :) </title>
      <link>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685976#M192057</link>
      <description>&lt;P&gt;Thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 04 May 2015 07:15:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685976#M192057</guid>
      <dc:creator>d-fillmore</dc:creator>
      <dc:date>2015-05-04T07:15:48Z</dc:date>
    </item>
    <item>
      <title>Hi Vibhor, Do you know what</title>
      <link>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685977#M192058</link>
      <description>&lt;P&gt;Hi Vibhor, Do you know what the performance&amp;nbsp;impact is of enabling HTTP replication?&lt;/P&gt;&lt;P&gt;eg Is it an increase in the load on the processor to synchronise lots of small flows?&lt;/P&gt;&lt;P&gt;I'm trying to get a feel for what is an acceptable number of HTTP&amp;nbsp;flows for a given ASA&amp;nbsp;(eg 5580-20) to consider turning HTTP replication on&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers, Dom&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2015 08:48:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685977#M192058</guid>
      <dc:creator>d-fillmore</dc:creator>
      <dc:date>2015-05-05T08:48:43Z</dc:date>
    </item>
    <item>
      <title>Hi,I don't think the HTTP</title>
      <link>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685978#M192059</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I don't think the HTTP replication would have any problems with the load on the ASA device.&lt;/P&gt;&lt;P&gt;It can certainly increase the load on the Stateful link for the failover.&lt;/P&gt;&lt;P&gt;In normal scenario , we don't see many issues with this being enabled.&lt;/P&gt;&lt;P&gt;Thanks and Regards,&lt;/P&gt;&lt;P&gt;Vibhor Amrodia&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 May 2015 09:37:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-http-connection-replication-question/m-p/2685978#M192059</guid>
      <dc:creator>Vibhor Amrodia</dc:creator>
      <dc:date>2015-05-05T09:37:12Z</dc:date>
    </item>
  </channel>
</rss>

