- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: ISP redundancy and Security Zones
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ISP redundancy and Security Zones
Hi team!
Two 6400 appliances in the A/S cluster, Gaia R81.20 JHF41. Two ISPs (/29 subnets), Primary/Backup mode. NAT policy is made using Security Zones. Recently we faced the following situation.
When fail-over occurs, ISP from Primary ISP to Backup ISP, all outgoing ICMP requests and TCP sessions are re-established correctly. But some UDP sessions "hang" and are sourced with the address of the Primary ISP.
TAC in my case wrote that "Old connections will not change NAT by design. This as confirmed by the developer is by design this is because the connection is recorded in the connection table."
How do I get to automatically perform UDP sessions cleanup from connections table?
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The way I understand what TAC said, it sounds like this would require an RFE.
It is possible to remove connections from the connections table (fw tab -x, I believe), but it would require some scripting to parse the connections table and figure out which ones to remove.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The way I understand what TAC said, it sounds like this would require an RFE.
It is possible to remove connections from the connections table (fw tab -x, I believe), but it would require some scripting to parse the connections table and figure out which ones to remove.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi! If I understand correctly, when client A sends UDP data to server B via CP, a virtual UDP session is created, which has a timeout (40 seconds by default).
If a UDP reply from server B to client A arrives, is it a second virtual session, which is in no way linked to the first virtual session?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If that reply comes within 40 seconds, it's considered part of the same session.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If TAC confirmed it and developer said the same, then what @PhoneBoy advised makes total sense. Sounds like RFE to me.
Best,
Andy
