cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
654
Views
5
Helpful
1
Replies

ASA 5585 - High number of cluster redirects

Hemant Sajwan
Level 1
Level 1

Hi,

 

We have two 5585s in cluster. We have been seeing very high number of cluster redirects under "show asp drop". They mainly increase only on one ASA. Around 10-20 redirects increase every second. Is it something to worry about? Does it mean traffic is not being forwarded to the right ASA most (or all) the time? Is it normal to have so many redirects every second? Here are some outputs taken every second:

 

XXXX# cluster exec show asp drop | incl redir
ASA1(LOCAL):**********************************************************
  Flow removed, packet sent to owner (cluster-redirect)                   210040


ASA2:*****************************************************************
  Flow removed, packet sent to owner (cluster-redirect)                 12343942

 


XXXX# cluster exec show asp drop | incl redir
ASA1(LOCAL):**********************************************************
  Flow removed, packet sent to owner (cluster-redirect)                   210040


ASA2:*****************************************************************
  Flow removed, packet sent to owner (cluster-redirect)                 12343948

 


XXXX# cluster exec show asp drop | incl redir
ASA1(LOCAL):**********************************************************
  Flow removed, packet sent to owner (cluster-redirect)                   210040


ASA2:*****************************************************************
  Flow removed, packet sent to owner (cluster-redirect)                 12343960

 


XXXX# cluster exec show asp drop | incl redir
ASA1(LOCAL):**********************************************************
  Flow removed, packet sent to owner (cluster-redirect)                   210040


ASA2:*****************************************************************
  Flow removed, packet sent to owner (cluster-redirect)                 12343966

 


XXXX# cluster exec show asp drop | incl redir
ASA1(LOCAL):**********************************************************
  Flow removed, packet sent to owner (cluster-redirect)                   210040


ASA2:*****************************************************************
  Flow removed, packet sent to owner (cluster-redirect)                 12343970

 


XXXX# cluster exec show asp drop | incl redir
ASA1(LOCAL):**********************************************************
  Flow removed, packet sent to owner (cluster-redirect)                   210040


ASA2:*****************************************************************
  Flow removed, packet sent to owner (cluster-redirect)                 12343978

 

1 Reply 1

Rishabh Seth
Level 7
Level 7

Hi Hemant,

 

The ASP drop counter signifies that the packet a unit received belongs to a session which is handled by another unit in the cluster. So the current unit which received the packet will forward it over CCL and would increment the counter for cluster-redirect in ASP drop output.

 

The ASA relies on the upstream and downstream switches for load balancing and would process the traffic as it receives from those devices. This counter is informational and should'nt  be treated as actual traffic drop.

 

Thanks,

R.Seth

 

Review Cisco Networking products for a $25 gift card