I've got a site-to-site VPN between a couple of Cisco ASAs. It's been up for a very long time (years), but just in the last couple of days I was looking at utilization on the firewall's interfaces and i'm seeing something I can't explain.
There is a constant 10 Mbps of traffic between the two ASAs (which is, historically,not normal in this environment), but I only see that volume of traffic on the Outside interfaces of each ASA. The source/destination for the traffic is the public IP for the other ASA. But there is no traffic on the Inside/LAN interfaces of either ASA.
I can pull a packet capture off the outside/WAN interface, but it's all VPN tunnel traffic so it's encrypted and I can't see what's actually going on.
If I saw a comparable volume of traffic on the Inside/LAN interfaces, I wouldn't think twice about it. But since it's definitely VPN tunnel traffic, and it's reaching the other ASA and then not going anyway, I want to know what's going on.
Any suggestions?
There is a constant 10 Mbps of traffic between the two ASAs (which is, historically,not normal in this environment), but I only see that volume of traffic on the Outside interfaces of each ASA. The source/destination for the traffic is the public IP for the other ASA. But there is no traffic on the Inside/LAN interfaces of either ASA.
I can pull a packet capture off the outside/WAN interface, but it's all VPN tunnel traffic so it's encrypted and I can't see what's actually going on.
If I saw a comparable volume of traffic on the Inside/LAN interfaces, I wouldn't think twice about it. But since it's definitely VPN tunnel traffic, and it's reaching the other ASA and then not going anyway, I want to know what's going on.
Any suggestions?