<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Configuring Cisco ACE in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764709#M14652</link>
    <description>&lt;P&gt;I have been given the task of configuring a Cisco ACE20 initially for SLB. I have configured IOS SLB sucesfully but the ACE appears far more complex. Does anyone have any confgiuration guides with diagrams. The Cisco documentation only gives command guides which I am finding difficult to follow. I have set up a test scenario as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client side vlan 10 - 172.22.152.0 / 21&lt;/P&gt;&lt;P&gt;Server side vlan 17 - 172.22.244.0 /24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vlan 10 is set up on Sup720 as L2/3&lt;/P&gt;&lt;P&gt;Vlan 17 is set up on Sup720 as L2 only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC with IIS running with IP address 172.22.244.101&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VIP address 172.22.152.6&lt;/P&gt;&lt;P&gt;Rserver address 172.22.244.101&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Route on ACE 0.0.0.0 0.0.0.0 172.22.152.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ping the rserver from ACE OK as I have captured the ICMP traffic with analyser, when I attempt to HTTP to the vserver address I see the traffic hit the ACE but it sends TCP resets. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can provide the full config of the ACE etc if needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With IOS SLB (without NAT) I used loopback addresses on the real servers from the ACE documentation it appears the VIP address has to be completely unique, does this mean there is no need for loopback interfaces. Also does the VIP address have to be in a different subnet than the clients as mine is not but it is in the same subnet as my client side vlan as was stated in the ACE getting started guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am very new to content swithing especially classifying traffic etc, can anyone please help ?&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jul 2007 19:31:31 GMT</pubDate>
    <dc:creator>Dan Smith</dc:creator>
    <dc:date>2007-07-10T19:31:31Z</dc:date>
    <item>
      <title>Configuring Cisco ACE</title>
      <link>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764709#M14652</link>
      <description>&lt;P&gt;I have been given the task of configuring a Cisco ACE20 initially for SLB. I have configured IOS SLB sucesfully but the ACE appears far more complex. Does anyone have any confgiuration guides with diagrams. The Cisco documentation only gives command guides which I am finding difficult to follow. I have set up a test scenario as follows:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client side vlan 10 - 172.22.152.0 / 21&lt;/P&gt;&lt;P&gt;Server side vlan 17 - 172.22.244.0 /24&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vlan 10 is set up on Sup720 as L2/3&lt;/P&gt;&lt;P&gt;Vlan 17 is set up on Sup720 as L2 only&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PC with IIS running with IP address 172.22.244.101&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;VIP address 172.22.152.6&lt;/P&gt;&lt;P&gt;Rserver address 172.22.244.101&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Route on ACE 0.0.0.0 0.0.0.0 172.22.152.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ping the rserver from ACE OK as I have captured the ICMP traffic with analyser, when I attempt to HTTP to the vserver address I see the traffic hit the ACE but it sends TCP resets. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can provide the full config of the ACE etc if needed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With IOS SLB (without NAT) I used loopback addresses on the real servers from the ACE documentation it appears the VIP address has to be completely unique, does this mean there is no need for loopback interfaces. Also does the VIP address have to be in a different subnet than the clients as mine is not but it is in the same subnet as my client side vlan as was stated in the ACE getting started guide.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am very new to content swithing especially classifying traffic etc, can anyone please help ?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2007 19:31:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764709#M14652</guid>
      <dc:creator>Dan Smith</dc:creator>
      <dc:date>2007-07-10T19:31:31Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Cisco ACE</title>
      <link>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764710#M14653</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;could you please share your config and a 'show service-policy'.&lt;/P&gt;&lt;P&gt;Will start helping you from there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The vip can be any ip you want.&lt;/P&gt;&lt;P&gt;You can use it as a loopback on the servers, but we usually do this when the loabalancer forward without nating.&lt;/P&gt;&lt;P&gt;This is not mandatory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2007 05:30:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764710#M14653</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2007-07-11T05:30:10Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Cisco ACE</title>
      <link>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764711#M14654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Config attached.........&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2007 07:04:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764711#M14654</guid>
      <dc:creator>Dan Smith</dc:creator>
      <dc:date>2007-07-11T07:04:18Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Cisco ACE</title>
      <link>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764712#M14655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;        curr conns       : 0         , hit count        : 2&lt;/P&gt;&lt;P&gt;        dropped conns    : 2&lt;/P&gt;&lt;P&gt;        client pkt count : 3         , client byte count: 240&lt;/P&gt;&lt;P&gt;        server pkt count : 0         , server byte count: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you sure your servers are responding ?&lt;/P&gt;&lt;P&gt;can you sniff on the server to see if they receive a SYN and if they respond with a SYN/ACK in the right direction [ACE].&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config looks good.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2007 09:58:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764712#M14655</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2007-07-11T09:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Cisco ACE</title>
      <link>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764713#M14656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Giles&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Capture attached (etherreal).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am the client on 172.21.17.20, the VIP address 172.22.152.6 replies with a RST/ACK. I can see the connection attempt on the ACE:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;switch/Admin# sh conn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;total current connections : 6&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conn-id    np dir proto vlan source                destination           state&lt;/P&gt;&lt;P&gt;----------+--+---+-----+----+---------------------+---------------------+------+&lt;/P&gt;&lt;P&gt;4          1  in  TCP   10   172.21.17.20:1291     172.22.152.6:80       SYNSEEN&lt;/P&gt;&lt;P&gt;1          1  out TCP   17   172.22.152.6:80       172.21.17.20:1291     INIT&lt;/P&gt;&lt;P&gt;3          1  in  TCP   10   172.21.17.20:1285     172.22.152.5:23       ESTAB&lt;/P&gt;&lt;P&gt;5          1  out TCP   10   172.22.152.5:23       172.21.17.20:1285     ESTAB&lt;/P&gt;&lt;P&gt;4          2  in  UDP   17   172.22.244.101:1042   172.28.7.25:161       --&lt;/P&gt;&lt;P&gt;2          2  out UDP   10   172.28.7.25:161       172.22.244.101:1042   --&lt;/P&gt;&lt;P&gt;switch/Admin#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need a loopback address on the real server. Also I only have one real server set-up at the moment - I didn't think this would matter.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2007 11:57:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764713#M14656</guid>
      <dc:creator>Dan Smith</dc:creator>
      <dc:date>2007-07-11T11:57:35Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Cisco ACE</title>
      <link>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764714#M14657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;remove "transparent" from the server farm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host WEB-FARM&lt;/P&gt;&lt;P&gt;  description WEB SERVERFARM&lt;/P&gt;&lt;P&gt;  rserver WEB1&lt;/P&gt;&lt;P&gt;    inservice&lt;/P&gt;&lt;P&gt;  rserver WEB2&lt;/P&gt;&lt;P&gt;    inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed Iftekhar Ahmed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Jul 2007 20:31:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764714#M14657</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2007-07-11T20:31:04Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Cisco ACE</title>
      <link>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764715#M14658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you very much - That has worked. I read in one of the manuals that this command had to be included.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One other question - If server administrators require remote access to the rservers real IP address (like ours do), as the rservers are not part of a L3 network on our intermidiate routers I configured a static route via the ACE client side interface as follows:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 172.22.244.101 255.255.255.255 172.22.152.5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this best practice or should I be using a different method.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2007 10:03:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764715#M14658</guid>
      <dc:creator>Dan Smith</dc:creator>
      <dc:date>2007-07-12T10:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Configuring Cisco ACE</title>
      <link>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764716#M14659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You just need to make sure that intermediate routing devices can route traffic to the real and     your ACE should allow traffic to the real.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Static routes can definitely help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Syed Iftekhar Ahmed&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2007 16:41:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/configuring-cisco-ace/m-p/764716#M14659</guid>
      <dc:creator>Syed Iftekhar Ahmed</dc:creator>
      <dc:date>2007-07-12T16:41:23Z</dc:date>
    </item>
  </channel>
</rss>

