cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1707
Views
10
Helpful
4
Replies

Firewall connections via wrong interface

Daniel Smith
Level 1
Level 1

Our firewalls utilize dynamic routing to route to the target destinations. Quite often, when a route goes away, a connection will build between an interface and corporate interface, which is where the default route points. The connection really does not work, since the resource is on a different interface. These connections remain built even when the route comes back from the correct interface, and the session continues to not work until we manually clear it. Is there a solution for this issue?

1 Accepted Solution

Accepted Solutions

use this command if the interface change then the NAT will update according to new interface

timeout floating-conn x:x:x

View solution in original post

4 Replies 4

balaji.bandi
Hall of Fame
Hall of Fame

can you show an example: is this NAT connection clear? that is the nature of the process, you need to make an EEM script to clear NAT if NAT involved.

 

if the IGP then once new route available with best cost and path, then FW should send traffic to new best path technically.

 

but we would like to see the config and example output of the routing table to suggest anything we can.

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

use this command if the interface change then the NAT will update according to new interface

timeout floating-conn x:x:x

Thanks very much, I had read about that command before but forgotten it!

 

 

Review Cisco Networking products for a $25 gift card