11-12-2012 05:56 AM - edited 03-11-2019 05:22 PM
Hy there
I have a problem with a terminal server cluster.
I have an asa with an interface sided to the terminal server cluster.
The problem is when someone is trying to connect to the cluster this gives back the answer with an different IP so the asa drops the connection.
Example :
Client_source : 192.168.1.1
TS_1 : 10.10.1.1
TS_2 : 10.10.1.2
TS_3 : 10.10.1.3
IP asa
inside : 192.168.1.254
TS_int: 10.10.1.254
When the client 192.168.1.1 attacks the main IP of the TS cluster 10.10.1.1 this loadbalance and answers for example with the IP 10.10.1.2 or 10.10.1.3
The asa drops the connection because it expect and answer from 10.10.1.1 not from other source.
Thank you.
11-12-2012 06:44 AM
Take a look at source NAT (SNAT). I beleive that will take care of the problem.
11-12-2012 06:50 AM
Yeap I was thinking so, but isn't there another way, like some kind of asymetric routing.
11-12-2012 10:14 AM
TCP Bypass may work as well-
http://www.cisco.com/en/US/products/ps6120/products_configuration_example09186a0080b2d922.shtml
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide