01-09-2021 01:01 PM
Our firewalls utilize dynamic routing to route to the target destinations. Quite often, when a route goes away, a connection will build between an interface and corporate interface, which is where the default route points. The connection really does not work, since the resource is on a different interface. These connections remain built even when the route comes back from the correct interface, and the session continues to not work until we manually clear it. Is there a solution for this issue?
Solved! Go to Solution.
01-09-2021 07:17 PM
use this command if the interface change then the NAT will update according to new interface
timeout floating-conn x:x:x
01-09-2021 01:56 PM
can you show an example: is this NAT connection clear? that is the nature of the process, you need to make an EEM script to clear NAT if NAT involved.
if the IGP then once new route available with best cost and path, then FW should send traffic to new best path technically.
but we would like to see the config and example output of the routing table to suggest anything we can.
01-09-2021 07:17 PM
use this command if the interface change then the NAT will update according to new interface
timeout floating-conn x:x:x
01-09-2021 09:31 PM
01-10-2021 05:10 AM
Thanks very much, I had read about that command before but forgotten it!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide