Hello,
We have an ASA we've configured with global policy. It's attached to the core switches with two /30 interfaces with OSPF. These interfaces learn equal cost routes to subnets on the core.
We seem to be having a symmetry and state issue i.e. Traffic needs to go in and out of the same interface or it doesn't pass. However, the log doesn't show drops, a trace passes and a packet capture shows the traffic leaving (but it never really leaves).
Is the approach we have supported? Is there a way to turn off the interface reference in the stateful tuple?
ASA-5585X on 9.3.
Cheers,
Mike