<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic what does the bug mean? in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/what-does-the-bug-mean/m-p/19511#M208</link>
    <description>&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is the meaning of that bug?&lt;/P&gt;&lt;P&gt;===&lt;/P&gt;&lt;P&gt;CSCdx35082 - When the CSS detects a mid-NAT reject, the RST (reset) going back to the client has a sequence number of 0.&lt;/P&gt;&lt;P&gt;===&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;at the momement I use CSS 11005 with app v 5.00. &lt;/P&gt;&lt;P&gt;I have two layers of CSSs: &lt;/P&gt;&lt;P&gt;-one I use load balancing over a few SSL servers&lt;/P&gt;&lt;P&gt;-sec I use for firewall load balancing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so my topology looks like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SSL&lt;/P&gt;&lt;P&gt;SSL---CSS11005_B-----PIX-----CSS11005_A-----router_IOS----Internet&lt;/P&gt;&lt;P&gt;...                                        PIX&lt;/P&gt;&lt;P&gt;SSL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;only router_IOS has a public IP address, all other IPs are private&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the router_IOS there is a static NAT for VIP from CSS11005_B &lt;/P&gt;&lt;P&gt;CSS11005_A is used only for firewall loadbalancing and there is not NAT&lt;/P&gt;&lt;P&gt;PIXs do not make a NAT - only route&lt;/P&gt;&lt;P&gt;CSS11005_B gives VIP for SSL cluster, so there is a NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;all works fine since over a year. but time to time I recive an information for my support departament, that there is a client who cannot use our SSL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is always the same situation: client use some kind of address translation at his point of Internet connection; behind his NAT he cannot use my SSL; If he connect directly to the Internet all works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am wondering is it possible to tunne something at my side to fix that kind of problems?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
    <pubDate>Mon, 21 Oct 2002 07:04:01 GMT</pubDate>
    <dc:creator>p.kodzis</dc:creator>
    <dc:date>2002-10-21T07:04:01Z</dc:date>
    <item>
      <title>what does the bug mean?</title>
      <link>https://community.cisco.com/t5/application-networking/what-does-the-bug-mean/m-p/19511#M208</link>
      <description>&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;what is the meaning of that bug?&lt;/P&gt;&lt;P&gt;===&lt;/P&gt;&lt;P&gt;CSCdx35082 - When the CSS detects a mid-NAT reject, the RST (reset) going back to the client has a sequence number of 0.&lt;/P&gt;&lt;P&gt;===&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;at the momement I use CSS 11005 with app v 5.00. &lt;/P&gt;&lt;P&gt;I have two layers of CSSs: &lt;/P&gt;&lt;P&gt;-one I use load balancing over a few SSL servers&lt;/P&gt;&lt;P&gt;-sec I use for firewall load balancing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;so my topology looks like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SSL&lt;/P&gt;&lt;P&gt;SSL---CSS11005_B-----PIX-----CSS11005_A-----router_IOS----Internet&lt;/P&gt;&lt;P&gt;...                                        PIX&lt;/P&gt;&lt;P&gt;SSL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;only router_IOS has a public IP address, all other IPs are private&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on the router_IOS there is a static NAT for VIP from CSS11005_B &lt;/P&gt;&lt;P&gt;CSS11005_A is used only for firewall loadbalancing and there is not NAT&lt;/P&gt;&lt;P&gt;PIXs do not make a NAT - only route&lt;/P&gt;&lt;P&gt;CSS11005_B gives VIP for SSL cluster, so there is a NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;all works fine since over a year. but time to time I recive an information for my support departament, that there is a client who cannot use our SSL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it is always the same situation: client use some kind of address translation at his point of Internet connection; behind his NAT he cannot use my SSL; If he connect directly to the Internet all works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am wondering is it possible to tunne something at my side to fix that kind of problems?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;</description>
      <pubDate>Mon, 21 Oct 2002 07:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/what-does-the-bug-mean/m-p/19511#M208</guid>
      <dc:creator>p.kodzis</dc:creator>
      <dc:date>2002-10-21T07:04:01Z</dc:date>
    </item>
    <item>
      <title>Re: what does the bug mean?</title>
      <link>https://community.cisco.com/t5/application-networking/what-does-the-bug-mean/m-p/19512#M209</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not sure if there is something to tune or not but according to the following release notes, that bug is fixed in v.5.20. You may need to get with Cisco to see if there is a workaround.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/contnetw/ps792/prod_release_note09186a00800e03a6.html" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/contnetw/ps792/prod_release_note09186a00800e03a6.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Oct 2002 15:52:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/what-does-the-bug-mean/m-p/19512#M209</guid>
      <dc:creator>lisa.hall</dc:creator>
      <dc:date>2002-10-25T15:52:42Z</dc:date>
    </item>
  </channel>
</rss>

