<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Erratic CSS &amp;quot;flows&amp;quot;  in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/erratic-css-quot-flows-quot/m-p/1036983#M20657</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Usually when viewing flows for an established connection we see 2 entries: one for the client -&amp;gt; server traffic and one for the server -&amp;gt; client traffic.  In your case we only see client -&amp;gt; server traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible the server -&amp;gt; client traffic is bypassing the CSS (and breaking the load balancing)?  This can happen when another router or L3 device is on the same vlan as the servers.  also, if the client is on the same vlan as the servers the reply will bypass the CSS.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you verify that the server's default gateway is directed to the CSS interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you verify the client vlan is different from the server vlan?  The response from the server needs to traverse the CSS on its way to the client PC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 25 Jul 2008 20:39:38 GMT</pubDate>
    <dc:creator>sthall</dc:creator>
    <dc:date>2008-07-25T20:39:38Z</dc:date>
    <item>
      <title>Erratic CSS "flows"</title>
      <link>https://community.cisco.com/t5/application-networking/erratic-css-quot-flows-quot/m-p/1036982#M20656</link>
      <description>&lt;P&gt;When monitoring a specific flow on our CSS, "show flows" command output does not show this flow even when the user is actively using the content rule/ service. flow-timeout-multiplier has been set to 225 (1 hour). See below output when the "show flows" command was typed every few seconds:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rtanidccs01# show flows | grep 7.154&lt;/P&gt;&lt;P&gt;125.26.203.114  2065  163.189.7.154   10000 163.189.22.140  TCP  1/2       1/1&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;rtanidccs01# show flows | grep 7.154&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;rtanidccs01# show flows | grep 7.154&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;rtanidccs01# show flows | grep 7.154&lt;/P&gt;&lt;P&gt;125.26.203.114  2065  163.189.7.154   10000 163.189.22.140  TCP  1/2       1/1&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;rtanidccs01# show flows | grep 7.154&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;rtanidccs01# show flows | grep 7.154&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;rtanidccs01# show flows | grep 7.154&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;rtanidccs01# show flows | grep 7.154&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;rtanidccs01# show flows | grep 7.154&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;rtanidccs01# show flows | grep 7.154&lt;/P&gt;&lt;P&gt;125.26.203.114  2065  163.189.7.154   10000 163.189.22.140  TCP  1/2       1/1&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;rtanidccs01# show flows | grep 7.154&lt;/P&gt;&lt;P&gt;125.26.203.114  2065  163.189.7.154   10000 163.189.22.140  TCP  1/2       1/1&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;rtanidccs01# show flows | grep 7.154&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;rtanidccs01# show flows | grep 7.154&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;rtanidccs01# show flows | grep 7.154&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 24 Jul 2008 05:48:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/erratic-css-quot-flows-quot/m-p/1036982#M20656</guid>
      <dc:creator>dilip.kulkarni</dc:creator>
      <dc:date>2008-07-24T05:48:04Z</dc:date>
    </item>
    <item>
      <title>Re: Erratic CSS "flows"</title>
      <link>https://community.cisco.com/t5/application-networking/erratic-css-quot-flows-quot/m-p/1036983#M20657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Usually when viewing flows for an established connection we see 2 entries: one for the client -&amp;gt; server traffic and one for the server -&amp;gt; client traffic.  In your case we only see client -&amp;gt; server traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible the server -&amp;gt; client traffic is bypassing the CSS (and breaking the load balancing)?  This can happen when another router or L3 device is on the same vlan as the servers.  also, if the client is on the same vlan as the servers the reply will bypass the CSS.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you verify that the server's default gateway is directed to the CSS interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you verify the client vlan is different from the server vlan?  The response from the server needs to traverse the CSS on its way to the client PC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jul 2008 20:39:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/erratic-css-quot-flows-quot/m-p/1036983#M20657</guid>
      <dc:creator>sthall</dc:creator>
      <dc:date>2008-07-25T20:39:38Z</dc:date>
    </item>
    <item>
      <title>Re: Erratic CSS "flows"</title>
      <link>https://community.cisco.com/t5/application-networking/erratic-css-quot-flows-quot/m-p/1036984#M20658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Steve,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply (was away for a couple of days so didn't see your posting).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CSS is actually "in-line" so the reply packets cannot bypass the CSS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure why we do not see server to client traffic: Will this traffic contain server's real IP address or the Virtual IP? If it contains real IP, then the reason it is not discplayed is because I have done a grep on the virtual IP (7.154).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are no VLANs as such. Clients are out on Internet. Server is on the Inside, both CSS interfaces in Routed mode. The CSS is simply doing a Destination NAT in this instance and then forwarding the packet to the server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jul 2008 06:51:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/erratic-css-quot-flows-quot/m-p/1036984#M20658</guid>
      <dc:creator>dilip.kulkarni</dc:creator>
      <dc:date>2008-07-30T06:51:25Z</dc:date>
    </item>
    <item>
      <title>Re: Erratic CSS "flows"</title>
      <link>https://community.cisco.com/t5/application-networking/erratic-css-quot-flows-quot/m-p/1036985#M20659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dilip,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can run the command &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show flows 0.0.0.0 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;used to show sessions flowing in and out of the CSS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It will show u the output something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show flows 0.0.0.0 &lt;/P&gt;&lt;P&gt;Src Address     SPort Dst Address     DPort NAT Dst Address Prt InPort    OutPort &lt;/P&gt;&lt;P&gt;--------------- ----- --------------- ----- --------------- --- --------- --------- &lt;/P&gt;&lt;P&gt;10.10.10.2      80    10.10.10.6      36805 10.64.104.208   TCP  1         1 &lt;/P&gt;&lt;P&gt;10.64.104.208   37413 10.10.10.6      80    10.10.10.2      TCP  1         1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the case of  one-armed configuration, the InPort and OutPort details show the same port for both directions. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normal CSS configurations where two or more ports are in use must show different InPort and OutPort ports being used.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this command will bring some more information out of your CSS box.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Keep posting,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Till then,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Regards,&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:sachinga@hcl.in"&gt;sachinga@hcl.in&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 31 Jul 2008 04:23:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/erratic-css-quot-flows-quot/m-p/1036985#M20659</guid>
      <dc:creator>sachinga.hcl</dc:creator>
      <dc:date>2008-07-31T04:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Erratic CSS "flows"</title>
      <link>https://community.cisco.com/t5/application-networking/erratic-css-quot-flows-quot/m-p/1036986#M20660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I know I can show all the flows. But because there are over a couple of hundred flows at any given time, I am doing a grep to just look at the flow I am interested in.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, the CSS is deployed "in-line" not in a one-armed configuration.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Aug 2008 03:47:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/erratic-css-quot-flows-quot/m-p/1036986#M20660</guid>
      <dc:creator>dilip.kulkarni</dc:creator>
      <dc:date>2008-08-01T03:47:27Z</dc:date>
    </item>
  </channel>
</rss>

