cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
165
Views
0
Helpful
2
Replies

PAT query (TCP) (in general, but also ASA specific)

Youreateapot418
Level 1
Level 1

So, before anyone goes on the "just design a better solution" train. This is more for educational purposes.

We had a lab setup, which when a failover happened, the PAT session was oblivious to this, so stayed "UP". 

However, the client system knew, so restarted the TCP process (3 way handshake).

Server and FW PAT session stayed active. 

This new 3 way handshake transited the existing PAT session, and the server then sent "RST", (as it should, because why would an active session need a 3 way handshake again).

My query is. When we manually clear a PAT session via CLI in a router or ASA (clear NAT translations, or xlate), does that send a "RST" also in both directions, or does it just disappear and the end systems (if still transmitting) just start another PAT session (which would then be out of sync with new 5tuple, and the connection would fail, timeout, then re-set)?

 

2 Replies 2

clear xlate not force FW to send RST 
clear host or clear conn force FW to send RST

MHM

Hello
Good question - TBH no sure of the rst towards the client but it does clear the entry from the nat table and that gets recreated.


Please rate and mark as an accepted solution if you have found any of the information provided useful.
This then could assist others on these forums to find a valuable answer and broadens the community’s global network.

Kind Regards
Paul