14-36
Cisco Security Appliance Command Line Configuration Guide
OL-12172-03
Chapter 14 Configuring Failover
Configuring Failover
You can prevent the return packets from being dropped using the
asr-group
command on interfaces
where this is likely to occur. When an interface configured with the
asr-group
command receives a
packet for which it has no session information, it checks the session information for the other interfaces
that are in the same group. If it does not find a match, the packet is dropped. If it finds a match, then one
of the following actions occurs:
•
If the incoming traffic originated on a peer unit, some or all of the layer 2 header is rewritten and
the packet is redirected to the other unit. This redirection continues as long as the session is active.
•
If the incoming traffic originated on a different interface on the same unit, some or all of the layer
2 header is rewritten and the packet is reinjected into the stream.
Note
Using the
asr-group
command to configure asymmetric routing support is more secure than using the
static
command with the
nailed
option.
The
asr-group
command does not provide asymmetric routing; it restores asymmetrically routed packets
to the correct interface.
Prerequisites
You must have to following configured for asymmetric routing support to function properly:
•
Active/Active Failover
•
Stateful Failover—passes state information for sessions on interfaces in the active failover group to
the standby failover group.
•
replication http
—HTTP session state information is not passed to the standby failover group, and
therefore is not present on the standby interface. For the security appliance to be able re-route
asymmetrically routed HTTP packets, you need to replicate the HTTP state information.
You can configure the
asr-group
command on an interface without having failover configured, but it
does not have any effect until Stateful Failover is enabled.
Configuring Support for Asymmetrically Routed Packets
To configure support for asymmetrically routed packets, perform the following steps:
Step 1
Configure Active/Active Stateful Failover for the failover pair. See
Configuring Active/Active Failover,
page 14-27
.
Step 2
For each interface that you want to participate in asymmetric routing support enter the following
command. You must enter the command on the unit where the context is in the active state so that the
command is replicated to the standby failover group. For more information about command replication,
see
Command Replication, page 14-12
.
hostname/ctx(config)#
interface
phy_if
hostname/ctx(config-if)#
asr-group
num
Valid values for
num
range from 1 to 32. You need to enter the command for each interface that
participates in the asymmetric routing group. You can view the number of ASR packets transmitted,
received, or dropped by an interface using the
show interface detail
command. You can have more than
one ASR group configured on the security appliance, but only one per interface. Only members of the
same ASR group are checked for session information.
Содержание 500 Series
Страница 38: ...Contents xxxviii Cisco Security Appliance Command Line Configuration Guide OL 12172 03 ...
Страница 45: ...P A R T 1 Getting Started and General Information ...
Страница 46: ......
Страница 277: ...P A R T 2 Configuring the Firewall ...
Страница 278: ......
Страница 354: ...17 38 Cisco Security Appliance Command Line Configuration Guide OL 12172 03 Chapter 17 Configuring NAT NAT Examples ...
Страница 561: ...P A R T 3 Configuring VPN ...
Страница 562: ......
Страница 891: ...P A R T 4 System Administration ...
Страница 892: ......
Страница 975: ...P A R T 5 Reference ...
Страница 976: ......