<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSM-S bridge mode design in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629537#M11986</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will try that and get back to you. thought there was no need sine the SSL DC adds the "route 0.0.0.0 0.0.0.0 10.6.78.1" by itself. as shown on this link&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/switches/ps708/module_installation_and_configuration_guides_chapter09186a00804638c2.html#wp1043233" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/switches/ps708/module_installation_and_configuration_guides_chapter09186a00804638c2.html#wp1043233&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks you for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hash&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 21 Mar 2007 13:08:43 GMT</pubDate>
    <dc:creator>hashng</dc:creator>
    <dc:date>2007-03-21T13:08:43Z</dc:date>
    <item>
      <title>CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629523#M11972</link>
      <description>&lt;P&gt;Hi all, &lt;/P&gt;&lt;P&gt;I have a CSM-S module in a Cat65xx system and working on my design. The MSFC is on the client side and the server and client side at the CSM should be in the same subnet (so bridge mode!?). &lt;/P&gt;&lt;P&gt;How can I integrate the SSL daughtercard (DC)? Can I use the DC in the same subnet/vlan? If not, which other possibility I have to use the DC in this configuration? Thanks in advance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thomas.&lt;/P&gt;</description>
      <pubDate>Mon, 15 Jan 2007 22:03:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629523#M11972</guid>
      <dc:creator>bogdahnt</dc:creator>
      <dc:date>2007-01-15T22:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629524#M11973</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;here is a document showing how to do it with a CSM and SSL module separate, but it should work with csm-s as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00802c1201.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00802c1201.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 10:15:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629524#M11973</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2007-01-16T10:15:09Z</dc:date>
    </item>
    <item>
      <title>Re: CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629525#M11974</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Thomas &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use CSM-S in our environment. Here is a base config which might help. We bridge for http and route to the SSL daughter card for https. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;6500 CSM config &lt;/P&gt;&lt;P&gt;===============&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 10 client&lt;/P&gt;&lt;P&gt;  description Firewalled vlan - bridge mode 10/11&lt;/P&gt;&lt;P&gt;  ip address 10.5.1.6 255.255.255.0 alt 10.5.1.7 255.255.255.0&lt;/P&gt;&lt;P&gt;  gateway 10.5.1.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt; vlan 11 server&lt;/P&gt;&lt;P&gt;  description Bridge mode 11/10&lt;/P&gt;&lt;P&gt;  ip address 10.5.1.6 255.255.255.0 alt 10.5.1.7 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt; vlan 41 server&lt;/P&gt;&lt;P&gt;  description SSL admin vlan&lt;/P&gt;&lt;P&gt;  ip address 10.9.1.246 255.255.255.0 alt 10.9.1.245 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt; vlan 301 server&lt;/P&gt;&lt;P&gt;  description SSL offload vlan&lt;/P&gt;&lt;P&gt;  ip address 10.100.1.19 255.255.255.0 alt 10.100.1.20 255.255.255.0&lt;/P&gt;&lt;P&gt;  alias 10.100.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; probe TCP tcp&lt;/P&gt;&lt;P&gt;  interval 5&lt;/P&gt;&lt;P&gt;  failed 10&lt;/P&gt;&lt;P&gt;  open 4&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; serverfarm WEB-FARM01&lt;/P&gt;&lt;P&gt;  nat server&lt;/P&gt;&lt;P&gt;  no nat client&lt;/P&gt;&lt;P&gt;  real 10.5.1.11 80&lt;/P&gt;&lt;P&gt;   inservice&lt;/P&gt;&lt;P&gt;  real 10.5.1.12 80&lt;/P&gt;&lt;P&gt;   no inservice&lt;/P&gt;&lt;P&gt;  probe TCP&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; serverfarm WEBSSL&lt;/P&gt;&lt;P&gt;  nat server&lt;/P&gt;&lt;P&gt;  no nat client&lt;/P&gt;&lt;P&gt;  real 10.100.1.40 local&lt;/P&gt;&lt;P&gt;   inservice&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt; vserver VSSL&lt;/P&gt;&lt;P&gt;  virtual 10.5.1.5 tcp https&lt;/P&gt;&lt;P&gt;  serverfarm WEBSSL&lt;/P&gt;&lt;P&gt;  persistent rebalance&lt;/P&gt;&lt;P&gt;  inservice&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt; vserver WEB01&lt;/P&gt;&lt;P&gt;  virtual 10.5.1.5 tcp www&lt;/P&gt;&lt;P&gt;  serverfarm WEB-FARM01&lt;/P&gt;&lt;P&gt;  no persistent rebalance&lt;/P&gt;&lt;P&gt;  inservice&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SSL Daughtercard &lt;/P&gt;&lt;P&gt;================&lt;/P&gt;&lt;P&gt;ip domain name rivendell.com&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ip ssh rsa keypair-name ssh_rivendell&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;ssl-proxy service sslterm&lt;/P&gt;&lt;P&gt; virtual ipaddr 10.100.1.40 255.255.255.0 protocol tcp port 443 secondary&lt;/P&gt;&lt;P&gt; server ipaddr 10.5.1.5 protocol tcp port 80&lt;/P&gt;&lt;P&gt; certificate rsa general-purpose trustpoint Cert-W2K&lt;/P&gt;&lt;P&gt; inservice&lt;/P&gt;&lt;P&gt;ssl-proxy vlan 41&lt;/P&gt;&lt;P&gt; ipaddr 10.9.1.244 255.255.255.0&lt;/P&gt;&lt;P&gt; gateway 10.9.1.1&lt;/P&gt;&lt;P&gt; admin&lt;/P&gt;&lt;P&gt;ssl-proxy vlan 301&lt;/P&gt;&lt;P&gt; ipaddr 10.100.1.21 255.255.255.0&lt;/P&gt;&lt;P&gt; gateway 10.100.1.1&lt;/P&gt;&lt;P&gt; route 10.5.1.0 255.255.255.0 gateway 10.100.1.1&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Obviously you need certs on your SSL card. I've left vlan 41 config in there - we use this for admin of ssl DC's, they are not used for https traffic. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It works fine for us. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Jan 2007 18:53:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629525#M11974</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-01-16T18:53:29Z</dc:date>
    </item>
    <item>
      <title>Re: CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629526#M11975</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks both of you for your replay. Jon, I planned exactly the same configuration like you. Last week I configured the csm and the dc in this way but got a strange result (my confs as attachments - IP changed to 1.1): &lt;/P&gt;&lt;P&gt;A client starts with a connect to the vserver INTER_443 with port 443. I get back the question for the correct certificate from the dc which I allow. After the confirm of the certificate the connections change from https to http and all other traffic goes via normal http traffic. Now is the question after the confirmation of the certificate why does the traffic fall back to http and not using https. Any ideas for this issue??? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon, may I have another question: Did you ever tried to connect from one real server at the server vlan to a vserver. Should this work? I saw at other posts that this should work!? My customer has at his webservers a java app running which will connect to one of the vservers and we get no result. But I will post this in another message. &lt;/P&gt;&lt;P&gt;Thanks for any help or ideas to check, Thomas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jan 2007 20:57:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629526#M11975</guid>
      <dc:creator>bogdahnt</dc:creator>
      <dc:date>2007-01-23T20:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629527#M11976</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your config differs from mine in a couple of ways. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) On mine the serverfarm IP address for the SSL service matches the VIP used on the DC under the ssl-proxy service config. Yours differs - you have  1.1.147.133 on your serverfarm and 172.28.147.133 under your ssl-proxy service. &lt;/P&gt;&lt;P&gt;2) On mine the server IP address under the ssl-proxy service matches my http vserver WEB01. On your you have used a different vserver, SSL_CLEARTEXT  from your standard http vserver INTER_80. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure whether these were intended ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes we did try connecting from a real server back to a vserver. We even went one further and had the same server recontact itself on a different VIP. It didn't work well for us but yes it should work, especially the simpler solution of a real talking to a vserver which points to different servers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the end we switched to one-arm mode, although that is often not recommened, as we had quite a few interconnections going through the CSM-S which didn't need to be load-balanced. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jan 2007 08:58:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629527#M11976</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-01-24T08:58:33Z</dc:date>
    </item>
    <item>
      <title>Re: CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629528#M11977</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, thanks for your quick answer.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Maybe I'm reading something wrong but I can't see the difference between our configs!?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ooooo, during the reading I see my mistake. In my attachment is the failure - I didn't changed the 172.28.147.133 to 1.1.147.133 ;o) Sorry for the confusion. Think the 172.28 as 1.1 and I have the same conf like you. So that should not the problem :o( &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For point 2 of your message you're right. I used another vserver "SSL_CLEARTEXT" to be more flexible and more secure (finally I plan that just the DC can connect to this vserver). This vserver is pointing to the same real servers and should work like the other vserver for http. Maybe I give a try to use the same webserver but I assume this is not the problem!? And this configuration works for you fine? Great for you - it seems that I've not this luck ;o) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jan 2007 17:06:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629528#M11977</guid>
      <dc:creator>bogdahnt</dc:creator>
      <dc:date>2007-01-24T17:06:08Z</dc:date>
    </item>
    <item>
      <title>Re: CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629529#M11978</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thomas &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't see it making much difference either to be honest. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i get a chance i'll try and put the config back onto our test environment and see what happens. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you sure that the application itself is not passing back URL's that point to the http vserver address ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jan 2007 18:54:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629529#M11978</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-01-24T18:54:18Z</dc:date>
    </item>
    <item>
      <title>Re: CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629530#M11979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon, yep that is exactly what I'm thinking too. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to check with the customer. Will let you know if I find it out. Many thanks for your time,&lt;/P&gt;&lt;P&gt;Thomas.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jan 2007 21:32:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629530#M11979</guid>
      <dc:creator>bogdahnt</dc:creator>
      <dc:date>2007-01-24T21:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629531#M11980</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thomas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;if the server uses HTTP redirect because the location of the HTTP objects has been moved, then you need to translate this redirect from HTTP to HTTPS with the SSL module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is done with a url-rewrite function.&lt;/P&gt;&lt;P&gt;There are a few examples on how to do this @&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/switches/ps708/module_installation_and_configuration_guides_chapter09186a0080441258.html#wp1247453" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/switches/ps708/module_installation_and_configuration_guides_chapter09186a0080441258.html#wp1247453&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Jan 2007 08:44:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629531#M11980</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2007-01-25T08:44:17Z</dc:date>
    </item>
    <item>
      <title>Re: CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629532#M11981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gilles/Everybody,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;had a problem with the SSL access via telnet as shown on the Documentation. I have created a VLAN (SVI) on the MSFC, and Created the same VLAN (server VLAN) on the CSM Module and equally on the SSL_DC all on the same subnet, with my gateway as the ip address on the MSFC, got the normal Default route on the SSL_DC automatically generated pointing to the gateway. &lt;/P&gt;&lt;P&gt;But from the MSFC i am able to ping the ip address on the CSM, but not able to ping the ip on the SSL_DC, have all the configs on the vty lines on the SSL_DC that are required for normal telnet but all in vain. find the configs below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;created the VLAN&lt;/P&gt;&lt;P&gt;on the MSFC of 6513&lt;/P&gt;&lt;P&gt;vlan 801&lt;/P&gt;&lt;P&gt;name SSL-DC_administrative&lt;/P&gt;&lt;P&gt;interface vlan 801&lt;/P&gt;&lt;P&gt;ip address 10.6.78.1 255.255.255.240&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;module ContentSwitchingModule 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;vlan 801 server&lt;/P&gt;&lt;P&gt;ip address 10.6.78.3 255.255.255.240&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl-proxy vlan 801&lt;/P&gt;&lt;P&gt;ipaddr 10.6.78.5 255.255.255.240&lt;/P&gt;&lt;P&gt;gateway 10.6.78.1&lt;/P&gt;&lt;P&gt;admin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;line vty 0 4 &lt;/P&gt;&lt;P&gt;password cisco&lt;/P&gt;&lt;P&gt;login&lt;/P&gt;&lt;P&gt;privi l 15 &lt;/P&gt;&lt;P&gt;loggin sync&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;enable password cisco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 06:48:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629532#M11981</guid>
      <dc:creator>hashng</dc:creator>
      <dc:date>2007-03-21T06:48:17Z</dc:date>
    </item>
    <item>
      <title>Re: CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629533#M11982</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the gateway command is for traffic hitting ssl-vip.&lt;/P&gt;&lt;P&gt;For management traffic [telnet,ping] you need to configure an ip route.  Just like for ios.&lt;/P&gt;&lt;P&gt;So, try to add an 'ip route 0.0.0.0 0.0.0.0 10.6.78.1' on the SSL-DC and see if it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 10:36:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629533#M11982</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2007-03-21T10:36:11Z</dc:date>
    </item>
    <item>
      <title>Re: CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629534#M11983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gilles,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you for your response, the SSL-DC by itself added the "route" command ro the configuration. i.e. route 0.0.0.0 0.0.0.0 10.6.78.1&lt;/P&gt;&lt;P&gt;or did you mean i should add "ip route" just as in the IOS ?&lt;/P&gt;&lt;P&gt;all i need is telne/ping access to the SSL-DC.&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hash&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 11:36:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629534#M11983</guid>
      <dc:creator>hashng</dc:creator>
      <dc:date>2007-03-21T11:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629535#M11984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You need to add the following on your SSL DC. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.6.78.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 12:37:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629535#M11984</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2007-03-21T12:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629536#M11985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;do the following on your ssl-dc&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;  ip route 0.0.0.0 0.0.0.0 10.6.78.1&lt;/P&gt;&lt;P&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;telnet and ping are considered management traffic.  The management traffic has its own routing table that is not the same as the production traffic.&lt;/P&gt;&lt;P&gt;The management route is configured in global config with the 'ip route' command.&lt;/P&gt;&lt;P&gt;NOT the "route" command under the proxy-vlan.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 12:57:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629536#M11985</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2007-03-21T12:57:27Z</dc:date>
    </item>
    <item>
      <title>Re: CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629537#M11986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you Jon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will try that and get back to you. thought there was no need sine the SSL DC adds the "route 0.0.0.0 0.0.0.0 10.6.78.1" by itself. as shown on this link&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/switches/ps708/module_installation_and_configuration_guides_chapter09186a00804638c2.html#wp1043233" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/switches/ps708/module_installation_and_configuration_guides_chapter09186a00804638c2.html#wp1043233&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks you for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hash&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 13:08:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629537#M11986</guid>
      <dc:creator>hashng</dc:creator>
      <dc:date>2007-03-21T13:08:43Z</dc:date>
    </item>
    <item>
      <title>Re: CSM-S bridge mode design</title>
      <link>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629538#M11987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;route and 'ip route' are different.&lt;/P&gt;&lt;P&gt;There is 2 routing table on this box.&lt;/P&gt;&lt;P&gt;The one for managmenet traffic like telnet/ping requires the 'ip route' command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2007 13:37:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/csm-s-bridge-mode-design/m-p/629538#M11987</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2007-03-21T13:37:57Z</dc:date>
    </item>
  </channel>
</rss>

