Go Premium for a chance to win a PS4. Enter to Win

x
  • Status: Solved
  • Priority: Medium
  • Security: Public
  • Views: 149
  • Last Modified:

Asymmetric Routing (Firewall)

Is it possible to have asymmetric routing from a stateful firewall?  The firewall will keep the connections in the state table, but it not the way its routed?
0
PeraHoman
Asked:
PeraHoman
3 Solutions
 
PredragNetwork EngineerCommented:
It is not possible if you perform natting on firewall. How will device that receive packets know where is located source of the traffic since there is no NAT table?
Typically for asymmetric routing you need two connected firewalls.
Asymmetric Routing and Firewalls
0
 
PeraHomanAuthor Commented:
Natting is done on the FW.  I was just wondering if this was possible.  

We see hits on our FW logs about traffic leaving our FW destined our Vendors public server, but there are no hits on return traffic from the Vendors server back to our FW.
0
 
SIM50Commented:
It's not possible for dynamic NAT but possible for static NAT. Unlike dynamic, where entries are created in xlate table for the current traffic going through, static NAT entries are added upon the configuration and work for any direction. So if you would have two ASA's with the same static NAT and ACLs and configured tcp state bypass, it would be possible for asymmetric routing to happen.
0

Featured Post

Free Tool: Subnet Calculator

The subnet calculator helps you design networks by taking an IP address and network mask and returning information such as network, broadcast address, and host range.

One of a set of tools we're offering as a way of saying thank you for being a part of the community.

Tackle projects and never again get stuck behind a technical roadblock.
Join Now