Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
Kilravock
New Contributor

Cisco ASA connections and xlates doubled

We have recently introduced a Fortigate 1000C (v5.0,build3608 (GA Patch 7)) to do web filtering (not running any other services on this box), running in Transparent mode.  It now sits inline between our network and our perimeter firewall, a Cisco ASA 5540 (8.2(5)).  

As soon as the Fortigate was introduced, the xlate & connection counts on the ASA effectively doubled (which meant we ran out of xlate slots and had to add a second PAT address - this is a big network) We took the Fortigates off line and xlates & conns went back to previous levels, put it back and they doubled again.  Looks to me as if either the Fortigates are somehow creating 2 connections & translation slots for every web connection or not freeing up connections when they are idle or closed.  Anyone come across this or have any suggestions as to how to resolve?

2 REPLIES 2
emnoc
Esteemed Contributor III

The diag debug flow is your best friend, I would run it on the fortigate. If this truly  transparent , then it should be just that "transparent", sounds like your L2 insertion is not correct or your running traffic in/out over the same wire 2x.

 

When you run the show conn on the ASA do you see duplicate sessions? same for xlate ? Maybe the traffic is seeing a session twice due to traffic running the same wire. Does these session matches the diag sys session on the  fortigate ?

 

Also you say webfilter, can you explain or show what policy you have in place?

 

And lastly, if you remove this policy and replace with an ANY>ANY, what happens within the ASA conn/xlate  tables?

 

PCNSE 

NSE 

StrongSwan  

PCNSE NSE StrongSwan
Sartuche24
New Contributor

Did you ever get this resolved, or find out why your connections doubled. Now I know when I setup a FortiGate and had it in transparent mode, I placed the management IP on a different network from the  network that it was sitting in-line with and this caused a huge problem as it started to cause a lot of MAC Flapping issues. You need to ensure that the IP you have on it resides within the same network as you firewall, so I'm thinking this may be a possibility of why you are seeing a huge increase of connections/xlates.

Labels
Top Kudoed Authors