Description


This articles explains SRX support for SRX HA mode as active-backup.

Symptoms


Customer has a scenario, they config SRX HA mode as active-backup, the udp traffic pass through node0 and the return packets go into node1, arrive node0 by data forwarding. Does SRX support this scenario?

Here is the SRX topology:

                                           IXIA 2
Untrust   ge-3/1/2: 200.1.1.1             ge-15/1/2: 201.1.1.1
node0-------------------------------------------------node1
Trust   reth1: 100.1.1.1
                                          IXIA 1

Node0 is reth1's primary and node1 is secondary, traffic1 is IXIA1--reth1--ge-3/1/2--IXIA2, traffic2 is IXIA2--ge-15/1/2--data forwarding--node0--reth1.

Here are the node0's HA configuration and status:
root@SRX5800-A# show chassis cluster 
redundancy-mode active-backup;

root@SRX5800-A# run show chassis cluster status 
Cluster ID: 1 
Node                  Priority          Status    Preempt  Manual failover

Redundancy group: 0 , Failover count: 1
    node0                   200         primary        no       no  
    node1                   100         secondary      no       no  

Redundancy group: 1 , Failover count: 1
    node0                   200         primary        no       no  
    node1                   100         secondary      no       no  

root@SRX5800-A# run show chassis cluster information 
node0:
--------------------------------------------------------------------------
Redundancy mode:
    Configured mode: active-backup
    Operational mode: active-backup

root@SRX5800-A# show security policies 
from-zone trust to-zone untrust {
    policy p1 {
        match {
            source-address any;
            destination-address any;
            application any;
        }
        then {
            permit;
        }
    }
}
Then create 100 udp traffic from 100.1.1.2 to 200.1.1.3-200.1.1.103, make traffic pass through node0, after sessions established, create reverse 100 udp traffic from 200.1.1.3-200.1.1.103 to 100.1.1.2 to match session, make traffic ingress to node1's ge-15/1/2.

Here are the sessions in node0 and node1:
root@SRX5800-A# run show security flow session node 0 
node0:
--------------------------------------------------------------------------

Flow Sessions on FPC8 PIC0:

Session ID: 320000401, Policy name: p1/4, State: Active, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.18/63;udp, If: reth0.0, Pkts: 35402, Bytes: 1628492
  Out: 200.1.1.18/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 0, Bytes: 0

Session ID: 320000402, Policy name: p1/4, State: Active, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.16/63;udp, If: reth0.0, Pkts: 35414, Bytes: 1629044
  Out: 200.1.1.16/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 0, Bytes: 0

Session ID: 320000403, Policy name: p1/4, State: Active, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.23/63;udp, If: reth0.0, Pkts: 35404, Bytes: 1628584
  Out: 200.1.1.23/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 0, Bytes: 0

Session ID: 320000404, Policy name: p1/4, State: Active, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.4/63;udp, If: reth0.0, Pkts: 35426, Bytes: 1629596
  Out: 200.1.1.4/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 0, Bytes: 0

Session ID: 320000405, Policy name: p1/4, State: Active, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.7/63;udp, If: reth0.0, Pkts: 35358, Bytes: 1626468
  Out: 200.1.1.7/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 0, Bytes: 0

Session ID: 320000406, Policy name: p1/4, State: Active, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.9/63;udp, If: reth0.0, Pkts: 35397, Bytes: 1628262
  Out: 200.1.1.9/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 0, Bytes: 0

Session ID: 320000407, Policy name: p1/4, State: Active, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.22/63;udp, If: reth0.0, Pkts: 35412, Bytes: 1628952
  Out: 200.1.1.22/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 0, Bytes: 0

Session ID: 320000408, Policy name: p1/4, State: Active, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.31/63;udp, If: reth0.0, Pkts: 35420, Bytes: 1629320
  Out: 200.1.1.31/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 0, Bytes: 0

Session ID: 320000409, Policy name: p1/4, State: Active, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.29/63;udp, If: reth0.0, Pkts: 35430, Bytes: 1629780
  Out: 200.1.1.29/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 0, Bytes: 0

Session ID: 320000410, Policy name: p1/4, State: Active, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.5/63;udp, If: reth0.0, Pkts: 35373, Bytes: 1627158
  Out: 200.1.1.5/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 0, Bytes: 0

Session ID: 320000411, Policy name: p1/4, State: Active, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.38/63;udp, If: reth0.0, Pkts: 35419, Bytes: 1629274
  Out: 200.1.1.38/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 0, Bytes: 0
......
                                        
{primary:node0}[edit]
root@SRX5800-A# run show security flow session node 1    
node1:
--------------------------------------------------------------------------

Flow Sessions on FPC8 PIC0:

Session ID: 320072567, Policy name: p1/4, State: Backup, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.28/63;udp, If: reth0.0, Pkts: 33588, 
  100.1.1.2/63 --> 200.1.1.9/63;udp, If: reth0.0, Pkts: 0, Bytes: 0
  Out: 200.1.1.9/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 131103, Bytes: 6030738                     <------------

Session ID: 320072569, Policy name: p1/4, State: Backup, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.22/63;udp, If: reth0.0, Pkts: 0, Bytes: 0
  Out: 200.1.1.22/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 131112, Bytes: 6031152                   <-------------

Session ID: 320072570, Policy name: p1/4, State: Backup, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.39/63;udp, If: reth0.0, Pkts: 0, Bytes: 0
  Out: 200.1.1.39/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 131120, Bytes: 6031520

Session ID: 320072571, Policy name: p1/4, State: Backup, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.68/63;udp, If: reth0.0, Pkts: 0, Bytes: 0
  Out: 200.1.1.68/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 131135, Bytes: 6032210

Session ID: 320072572, Policy name: p1/4, State: Backup, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.82/63;udp, If: reth0.0, Pkts: 0, Bytes: 0
  Out: 200.1.1.82/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 131127, Bytes: 6031842

Session ID: 320072573, Policy name: p1/4, State: Backup, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.75/63;udp, If: reth0.0, Pkts: 0, Bytes: 0
  Out: 200.1.1.75/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 131154, Bytes: 6033084

Session ID: 320072574, Policy name: p1/4, State: Backup, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.81/63;udp, If: reth0.0, Pkts: 0, Bytes: 0
  Out: 200.1.1.81/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 131148, Bytes: 6032808

Session ID: 320095888, Policy name: p1/4, State: Backup, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.61/63;udp, If: reth0.0, Pkts: 0, Bytes: 0
  Out: 200.1.1.61/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 131221, Bytes: 6036166

Session ID: 320095890, Policy name: p1/4, State: Backup, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.64/63;udp, If: reth0.0, Pkts: 0, Bytes: 0
  Out: 200.1.1.64/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 131224, Bytes: 6036304

Session ID: 320095891, Policy name: p1/4, State: Backup, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.102/63;udp, If: reth0.0, Pkts: 0, Bytes: 0
  Out: 200.1.1.102/63 --> 100.1.1.2/63;udp, If: ge-3/1/2.0, Pkts: 131170, Bytes: 6033820

Session ID: 320128445, Policy name: p1/4, State: Backup, Timeout: 60, Valid
  In: 100.1.1.2/63 --> 200.1.1.38/63;udp, If: reth0.0, Pkts: 0, Bytes: 0

......

[flowd]FPC8.PIC0(vty)# show nhdb management fabric    
Stashed Nexthop table:
    Chas-id    NHID     JNH       Remote-Chassis-IP-Addr
--------------------------------------------------------
        1        542    0x84f5302   30.17.0.2

Fabric NH stats:
        NH add messages               :         1
        NH delete messages            :         0
        JNH add messages              :         25
        JNH delete messages           :         5

Fabric stats:
        Receive                       :         903293991
        Fragments Received            :         0
        Parsed                        :         0
        Transmit                      :         51946
        Receive RTOs                  :         78
        Transmit RTOs                 :         288
        Receive Probes                :         52005
        Transmit Probes               :         51913
        Receive flow_fwd              :         881007748                           <------------
        Transmit flow_fwd             :         45
        Receive fabric_fwd            :         0
        Transmit fabric_fwd           :         0
        Receive Mcast fabric_fwd      :         0
        Transmit Mcast fabric_fwd     :         0
        Receive Invalid Types         :         0
        Receive Parse Error           :         0
        Receive IP Checksum Error     :         0
        Receive IP Invalid src-ip     :         0
        Receive Payload Offset Error  :         0
        Receive TLV Length Error      :         0
        Receive TLV Discard           :         0
        No Fabric                     :         0
        Transmit failed (ifnf)        :         0
[flowd]FPC8.PIC0(vty)# show nhdb management fabric    
Stashed Nexthop table:
    Chas-id    NHID     JNH       Remote-Chassis-IP-Addr
--------------------------------------------------------
        0        547    0x84c4b02   30.18.0.1

Fabric NH stats:
        NH add messages               :         1
        NH delete messages            :         0
        JNH add messages              :         1
        JNH delete messages           :         0

Fabric stats:
        Receive                       :         47391
        Fragments Received            :         0
        Parsed                        :         0
        Transmit                      :         779121595
        Receive RTOs                  :         287
        Transmit RTOs                 :         64
        Receive Probes                :         48577
        Transmit Probes               :         52660
        Receive flow_fwd              :         51
        Transmit flow_fwd             :         844601686             <-------------
        Receive fabric_fwd            :         0
        Transmit fabric_fwd           :         0
        Receive Mcast fabric_fwd      :         0
        Transmit Mcast fabric_fwd     :         0
        Receive Invalid Types         :         0
        Receive Parse Error           :         0
        Receive IP Checksum Error     :         0
        Receive IP Invalid src-ip     :         0
        Receive Payload Offset Error  :         0
        Receive TLV Length Error      :         0
        Receive TLV Discard           :         0
        No Fabric                     :         0
        Transmit failed (ifnf)        :         0

Solution




We can find this scenario works on SRX devices. For the return UDP traffic, it will still match sessions and forward packets through fabric data forwarding. However this scenario is not recomended:
  1. For some other traffic which does not have backup session, for example ICMP, it does not work because the return packets need to match the backup session.
  2. When config HA mode is active-backup, this means SRX will use all the resources (NAT and others) in primary node, secondary node will not get any , if traffic goes into secondary requesting to establish a session, it might failed.