Clinet--SW-M9000--ISP
The client cannot goto internet. The response traffic from is received by M9000. And M9000 didn't send the packet out.
1. chcek DPI. bypass DPI for troubleshooing. Issue still there.
2. check nat session. The M9000 have the nat session for client, but slot1(where receive the response traffic) dosen't have the natsession. And the FW will add a black-hole route for th nat ip address. Hence the traffic will not match the nat session and will be dropped by the black-hole.
3. why the nat session isn't synchronized between slots?Because the firmware version is not the same.
upgrade the firmware version to the same one, and the nat session will be synchronized between slots.