02-22-2023 02:37 PM
Hello.
ASA-5525<===> Nexus 9300 <===> Load-Balancer
1. If ASA-5525 high-availability setup sends a gratuitous APR to layer-2 Nexus port, will Nexus forward this packet out the interface connected to the load balancer?
--
2. If ASA-5525 HA setup is connected to Nexus on Vlan 10, BUT Loadbalancer is on Vlan 20, will Nexus forward gratuitous ARP to load balancer?
Thank you.
02-22-2023 04:59 PM
G-ARP is L2/L3 what that meaning ?
if the nexus have L2 connect to load balance then G-ARP will flood from NSK to Load
if not then the G-ARP will not flood
02-23-2023 05:36 AM
Yesterday we had a major network failure because devices downstream of the Nexus9300 failed to get the gratuitous arp from a ASA 5525 firewall failover event. (Possibly the stale arp entry remained for some other reason).
Why could this have occurred?
02-23-2023 05:39 AM
Are you config ASA HA active/standby ?
Are you config NSK as vPC ?
show failover <<- check the status in both ASA I think you have split brain ?
02-23-2023 06:11 AM - edited 02-23-2023 06:26 AM
Hi MHM. May you please answer the below questions?
I have migrated the rest of this thread to...
HA ASA-5525 pair failed to send gratuitous ARPs during failover. Why? - Cisco Community
What is nsk?
What would be the result of "split brain"?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide