09-16-2015 04:52 AM - edited 03-11-2019 11:36 PM
Hi,
We have two 5585s in cluster. We have been seeing very high number of cluster redirects under "show asp drop". They mainly increase only on one ASA. Around 10-20 redirects increase every second. Is it something to worry about? Does it mean traffic is not being forwarded to the right ASA most (or all) the time? Is it normal to have so many redirects every second? Here are some outputs taken every second:
XXXX# cluster exec show asp drop | incl redir
ASA1(LOCAL):**********************************************************
Flow removed, packet sent to owner (cluster-redirect) 210040
ASA2:*****************************************************************
Flow removed, packet sent to owner (cluster-redirect) 12343942
XXXX# cluster exec show asp drop | incl redir
ASA1(LOCAL):**********************************************************
Flow removed, packet sent to owner (cluster-redirect) 210040
ASA2:*****************************************************************
Flow removed, packet sent to owner (cluster-redirect) 12343948
XXXX# cluster exec show asp drop | incl redir
ASA1(LOCAL):**********************************************************
Flow removed, packet sent to owner (cluster-redirect) 210040
ASA2:*****************************************************************
Flow removed, packet sent to owner (cluster-redirect) 12343960
XXXX# cluster exec show asp drop | incl redir
ASA1(LOCAL):**********************************************************
Flow removed, packet sent to owner (cluster-redirect) 210040
ASA2:*****************************************************************
Flow removed, packet sent to owner (cluster-redirect) 12343966
XXXX# cluster exec show asp drop | incl redir
ASA1(LOCAL):**********************************************************
Flow removed, packet sent to owner (cluster-redirect) 210040
ASA2:*****************************************************************
Flow removed, packet sent to owner (cluster-redirect) 12343970
XXXX# cluster exec show asp drop | incl redir
ASA1(LOCAL):**********************************************************
Flow removed, packet sent to owner (cluster-redirect) 210040
ASA2:*****************************************************************
Flow removed, packet sent to owner (cluster-redirect) 12343978
09-16-2015 11:32 PM
Hi Hemant,
The ASP drop counter signifies that the packet a unit received belongs to a session which is handled by another unit in the cluster. So the current unit which received the packet will forward it over CCL and would increment the counter for cluster-redirect in ASP drop output.
The ASA relies on the upstream and downstream switches for load balancing and would process the traffic as it receives from those devices. This counter is informational and should'nt be treated as actual traffic drop.
Thanks,
R.Seth
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide