cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1355
Views
0
Helpful
1
Replies

ASA cluster

ahmede1
Frequent Visitor
Frequent Visitor

Good day,

 

We have ASA cluster, routing is symmetrical, so whatever traffic leaves through the master F/W it returns through the same firewall, same with the slave.. According to my limited understanding to how cluster works (I'm network guy not a security guy), we shouldn't see any user traffic on the CCL link, however we still see some traffic on the links.. Can someone to please explain why?

 

Thank you in advance

1 Reply 1

Marius Gunnerud
VIP Alumni
VIP Alumni

If traffic happens to arrive on one of the slaves (or master for that matter) where another firewall is the flow owner, that traffic is forwarded to the flow owner for further processing.  It might be this traffic that you are seeing.

--
Please remember to select a correct answer and rate helpful posts
Review Cisco Networking for a $25 gift card