HSRP and NAT
May I have your opinion on the following matter?
Two 2911 routers.
Doing HSRP on Wan and LAN side with 2 standby groups.
Doing static nat to internal servers.
Added redundacy keyword on the nat statements .
Tracking wan side interface in LAN side hsrp group and tracking
LAN side interface in WAN side hsrp group.
All is working well but I discovered the following convergence time
Issues when hsrp failover.
1. Hsrp active device has a tcp translation in the table.
2. Hsrp active does a failover (shut the interface).
3. The failover goes well but the ip nat session table on the new active is updated with the tcp sessions after about 30s after the failover took place.
Seen from debugs.
The new active device received the nat session table update message from the old active after 30 sec or more.
My client wants the tcp session replication to take place in less than 15s when a hsrp failover.
I will post debug messages in a short time when I get back to work.
Is there a way to make it work in less than 15s?
Also , what are the recommended ip nat translation timeout timers when doing hsrp and static nat .
Thank you for your help.