TCP Flow Violation in HA

Hi all.

Does the TCP Flow Violation functionality (e.g., 'Permit'), benefits from the fail-over packet exchange and port clustering on a fail-over group?

I need to know if both sensors share all packets in order to reassemble out-of-order TCP segments on both sensors of the cluster.

Yes.  In a fail-over setup, both sensors see exactly the same packets (via the cable connection they share), so out of order packets can be managed across both sensors.

