The new docs.trellix.com features a modernized UI and AI-powered conversational search. Content is currently available in English, with additional languages launching in early November 2026. We hope you enjoy the updated experience.

About asymmetric traffic flows

Prev Next

Asymmetric routing exists when packets travel one path outbound but take a different path inbound. Traffic asymmetry can be a normal routing situation created by dynamic routing protocols. It can also be caused by network hardware failure or misconfigured routing policies. Although it is often undesirable in an IP network, asymmetric routing by itself is not necessarily a problem. It becomes a problem when stateful security devices, such as firewalls and NAT-enabled routers, are on an asymmetric path. Security devices on the return path will not have the state information built by the devices on the outbound path, and return traffic is blocked.

Asymmetric traffic sometimes indicates the presence of threat activity. A SYN flood, for example, is a denial-of-service attack that exploits the normal TCP three-way handshake by using SYN-only flows to consume resources on targeted routers, servers, or IDS devices.

Other types of SYN-only flows can be used to map the devices and scan for vulnerabilities on a network. SYN-only flows of this type can be initiated by a malicious process to perform reconnaissance on a target network. They are also used by commercial vulnerability scanning applications that may be part of your daily scheduled enterprise security hygiene. For this reason, you might not want to include SYN-only flow counts in the calculation of the percentage of asymmetric flows.

The following commands list SYN-only flow counts and non-SYN-only asymmetric flow counts separately:

  • show smartvision event-track asym-flow
    ―Displays collected statistics for SYN-only flows and true (non-SYN-only) asymmetric flows separately.
  • show fume network stats
    ―Displays monitored statistics about the total flow count monitored, the SYN-only flows, and the non-SYN-only asymmetric flows.

To calculate the percentage of true asymmetric flows, divide the count of asymmetric flows by total flow count and multiply by 100.

Note

If a large proportion of the traffic monitored by your Network Security appliance is flowing asymmetrically, the appliance’s detection capabilities are reduced.

A Network Security appliance can display statistics about asymmetric traffic it observes. Viewing statistics on asymmetric traffic can help you to identify an asymmetric source area in the network. Collection of asymmetric traffic flow statistics is disabled by default.

Important

To avoid depleting system resources and degrading appliance performance, enable this feature only while you are collecting and viewing the statistics needed to investigate asymmetric flows in the network.

Note

The Network Security appliance collects and displays statistics for SYN-only flows and non-SYN-only asymmetric flows separately. To conserve system resources, each list can store no more than 100 statistics. After a list is filled to capacity, the appliance stops collecting statistics for that type of flow. Statistics collection for the flow resumes after you refresh the cache. The refresh operation clears both lists even if only one of the lists is full. Enabling statistics collection also clears both lists.