1-15
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring a Cluster of ASAs
Information About ASA Clustering
Equal-Cost Multi-Path Routing (Routed Firewall Mode Only)
When using Individual interfaces, each ASA interface maintains its own IP address and MAC address.
One method of load balancing is Equal-Cost Multi-Path (ECMP) routing.
We recommend this method if you are already using ECMP, and want to take advantage of your existing
infrastructure. This method might offer additional tuning options vs. Spanned EtherChannel as well.
ECMP routing can forward packets over multiple “best paths” that tie for top place in the routing metric.
Like EtherChannel, a hash of source and destination IP addresses and/or source and destination ports can
be used to send a packet to one of the next hops. If you use static routes for ECMP routing, then an ASA
failure can cause problems; the route continues to be used, and traffic to the failed ASA will be lost. If
you use static routes, be sure to use a static route monitoring feature such as Object Tracking. We
recommend using dynamic routing protocols to add and remove routes, in which case, you must
configure each ASA to participate in dynamic routing.
Note
If you use this method of load-balancing, you can use a device-local EtherChannel as an Individual
interface.
How the ASA Cluster Manages Connections
•
•
New Connection Ownership, page 1-16
•
•
Rebalancing New TCP Connections Across the Cluster, page 1-17
Connection Roles
There are 3 different ASA roles defined for each connection:
•
Owner—The unit that initially receives the connection. The owner maintains the TCP state and
processes packets. A connection has only one owner.
•
Director—The unit that handles owner lookup requests from forwarders and also maintains the
connection state to serve as a backup if the owner fails. When the owner receives a new connection,
it chooses a director based on a hash of the source/destination IP address and TCP ports, and sends
a message to the director to register the new connection. If packets arrive at any unit other than the
owner, the unit queries the director about which unit is the owner so it can forward the packets. A
connection has only one director.
•
Forwarder—A unit that forwards packets to the owner. If a forwarder receives a packet for a
connection it does not own, it queries the director for the owner, and then establishes a flow to the
owner for any other packets it receives for this connection. The director can also be a forwarder.
Note that if a forwarder receives the SYN-ACK packet, it can derive the owner directly from a SYN
cookie in the packet, so it does not need to query the director. (If you disable TCP sequence
randomization, the SYN cookie is not used; a query to the director is required.) For short-lived flows
such as DNS and ICMP, instead of querying, the forwarder immediately sends the packet to the
director, which then sends them to the owner. A connection can have multiple forwarders; the most
efficient throughput is achieved by a good load-balancing method where there are no forwarders and
all packets of a connection are received by the owner.
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......