现场两台防火墙做了IRF,反馈SLOT1上来的流量打开服务器页面正常,SLOT2上来的流量打开服务器页面卡慢。大致拓扑如下:
本次涉及设备的型号以及版本:SecPath F1070 Version 7.1.064, Release 9333P37
防火墙通过SLOT1和服务器相连,下行通过聚合口的方式和交换机互联。从SLOT2上来的流量打开服务器web页面卡慢,提示正在加载中,如下:
1、从现场反馈的组网,从SLOT2进来的流量需要从SLOT1回包,说明存在非对称流量。检查现场配置,开启了如下的会话同步,且现场反馈会话同步没有加asymmetric参数时备框上来的流量访问服务器不通。asymmetric:表示会话业务热备份功能支持处理非对称流量。如果不配置该参数,会话业务热备份功能仅支持处理对称流量。
session synchronization enable asymmetric
session synchronization dns http
2、接着查看会话表,看来回方向的报文数量,需要开启session statistics enable会话统计功能。SLOT1下连终端的会话表如下:
[FW]dis session table ipv4 sour 10.203.44.33 destination-ip 10.10.20.17 ver
Slot 1:
Initiator:
Source IP/port: 10.203.44.33/1
Destination IP/port: 10.10.20.17/2048
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: ICMP(1)
Inbound interface: Vlan-interface886
Source security zone: 11
Responder:
Source IP/port: 10.10.20.17/255
Destination IP/port: 10.10.20.16/0
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: ICMP(1)
Inbound interface: Vlan-interface820
Source security zone: BGW
State: ICMP_REPLY
Application: ICMP
Rule ID: 10
Rule name: ping
Start time: 2022-01-12 15:42:54 TTL: 18s
Initiator->Responder: 4 packets 240 bytes
Responder->Initiator: 4 packets 240 bytes
Total sessions found: 1
Slot 2:
Initiator:
Source IP/port: 10.203.44.33/1
Destination IP/port: 10.10.20.17/2048
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: ICMP(1)
Inbound interface: Vlan-interface886
Source security zone: 11
Responder:
Source IP/port: 10.10.20.17/255
Destination IP/port: 10.10.20.16/0
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: ICMP(1)
Inbound interface: Vlan-interface820
Source security zone: BGW
State: INACTIVE
Application: ICMP
Rule ID: 10
Rule name: ping
Start time: 2022-01-12 15:42:54 TTL: 285s
Initiator->Responder: 0 packets 0 bytes
Responder->Initiator: 0 packets 0 bytes
可以看到来回方向的包数量一致且都在SLOT1下。进一步查看SLOT2下的终端对应的会话,如下:
<FW>dis session table ipv4 source-ip 10.203.44.50 destination-ip 10.10.20.17 verbose
Slot 1:
Initiator:
Source IP/port: 10.203.44.50/64908
Destination IP/port: 10.10.20.17/80
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: TCP(6)
Inbound interface: Vlan-interface886
Source security zone: 11
Responder:
Source IP/port: 10.10.20.17/80
Destination IP/port: 10.10.20.16/57820
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: TCP(6)
Inbound interface: Vlan-interface820
Source security zone: BGW
State: INACTIVE
Application: HTTP
Rule ID: 50
Rule name: 11-to-bgw
Start time: 2022-01-12 15:12:59 TTL: 203s
Initiator->Responder: 1 packets 41 bytes
Responder->Initiator: 0 packets 0 bytes
Total sessions found: 1
Slot 2:
Initiator:
Source IP/port: 10.203.44.50/64908
Destination IP/port: 10.10.20.17/80
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: TCP(6)
Inbound interface: Vlan-interface886
Source security zone: 11
Responder:
Source IP/port: 10.10.20.17/80
Destination IP/port: 10.10.20.16/57820
DS-Lite tunnel peer: -
VPN instance/VLAN ID/Inline ID: -/-/-
Protocol: TCP(6)
Inbound interface: Vlan-interface820
Source security zone: BGW
State: TCP_ESTABLISHED
Application: HTTP
Rule ID: 50
Rule name: 11-to-bgw
Start time: 2022-01-12 15:12:59 TTL: 1193s
Initiator->Responder: 3 packets 123 bytes
Responder->Initiator: 0 packets 0 bytes
Total sessions found: 1
SLOT2上只有发起方的报文,没有看到回包。从如上的信息看可能是回包的流量部分被丢弃导致的打开服务器web页面卡慢。
1、由于现场的组网是非常规组网,存在非对称的流量,而防火墙会进行会话状态检测,当检测不通过时会导致报文被丢弃。因此可以更改组网,连接服务器和SLOT2,让来回方向的流量只经过一个设备处理。
2、开启会话的双主功能session dual-active enable,让会话工作在双主模式下,两台设备可以同时处理安全业务。
该案例暂时没有网友评论
✖
案例意见反馈
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作