SCTP Behavior in Chassis Cluster

This topic explains how SCTP configuration and established SCTP associations are synchronized between peers in a chassis cluster. The SCTP module supports active/active and active/passive operation.

When an SCTP association is created or deleted on the active device, the established SCTP association send a corresponding creation or deletion message to the peer device. Upon receiving this message, the secondary device adds or removes the SCTP association accordingly. The SCTP module registers the appropriate callback functions to receive and process these messages. There is no continuous timer synchronization between the SCTP associations on the two devices.

When a secondary device joins the cluster or reboots, the SCTP module registers a cold-start synchronization function. This function is invoked to synchronize all SCTP associations with the peer device simultaneously.

After a switchover, established SCTP associations continue to function. However, associations that are in the progress of being established are lost and must be re-initiated. Associations that are in the process of being torn down might miss acknowledgment messages, resulting in stale SCTP associations on the Firewall. These stale associations are automatically cleaned up when the inactivity timer expires (five hours by default).

  • You must configure security policies to permit all required SCTP sessions. For example, if endpoint A has an SCTP association with x IP addresses (IP_a1 through IP_ax) and endpoint B has an SCTP association with y IP addresses (IP_b1 through...IP_by), the security policy must allow all possible x*y communication paths in both directions.

  • When an SCTP association is removed, any related SCTP sessions continue to exist until they expire naturally based on their timeout settings.