- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Problem with asymmetry
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Problem with asymmetry
Good morning everyone,
We are facing an issue with a specific access. When trying to access it, the packet that should exit through the eth8.7 interface, one of the providers we have, is going out through another interface that is not configured.
Problem with asymmetry? Has anyone experienced this before?
Below is an image with the packet capture details.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
More details are likely required about your configuration, things like NAT and ISP redundancy config?
What does your routing table show as the correct egress path for the destination?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Make sure topology is correct and routes are also indeed right. Run ip r g command, ie ip r g 8.8.8.8
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Also, Im little confused by your statement "...is going out through another interface that is not configured"
How is that even possible?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I'm sorry for the lack of details in the previous explanation.
The packet enters through the interface eth8.7 (link A), goes through the inspection and NAT flow correctly, and then it is returned through eth8.8 (link B).
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Question...is this brand new issue or just started recently? Any changes made?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you please show the routing table output for this destination also is there any PBR configured that would match this traffic?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would involve CP TAC asap to get this fixed...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We would like to inform you that we are already in contact with the TAC. Thank you.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What was done with TAC so far?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you could send us below from expert mode, would help, for sure.
route
netstat -nr
clish -c "show route all"
Andy
