The following network diagram shows a standard TSM dual system off-line deployment. The symptom described as follows is discovered during a simulation test.
All traffic is directed to the master firewall FW1 based on policy-based routing on the switch SW1. If the core switch SW1 is down, switch SW2 takes over the work of SW1. Because both firewalls have ports in the down state, the master/slave firewall switchover is not performed. A PC at the access layer sends ping packets to communicate with the slave firewall. In this case, tracert packets are through, but only the first one or two ping packets are through. Every time the session table on the firewall is reset, ping packets are through for a while, but becomes not through soon.
Alarm Information
None.