Asymmetric Routing (Firewall)

Is it possible to have asymmetric routing from a stateful firewall?  The firewall will keep the connections in the state table, but it not the way its routed?
PeraHomanAsked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
JustInCaseConnect With a Mentor Network EngineerCommented:
It is not possible if you perform natting on firewall. How will device that receive packets know where is located source of the traffic since there is no NAT table?
Typically for asymmetric routing you need two connected firewalls.
Asymmetric Routing and Firewalls
0
 
PeraHomanConnect With a Mentor Author Commented:
Natting is done on the FW.  I was just wondering if this was possible.  

We see hits on our FW logs about traffic leaving our FW destined our Vendors public server, but there are no hits on return traffic from the Vendors server back to our FW.
0
 
SIM50Connect With a Mentor Commented:
It's not possible for dynamic NAT but possible for static NAT. Unlike dynamic, where entries are created in xlate table for the current traffic going through, static NAT entries are added upon the configuration and work for any direction. So if you would have two ASA's with the same static NAT and ACLs and configured tcp state bypass, it would be possible for asymmetric routing to happen.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.