<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACE: Problem with SSL termination in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-problem-with-ssl-termination/m-p/1303596#M27124</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gilles,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Removing the ciphers didn't help.  I've attached the output of the "before" and "after" stats.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cathy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Sep 2009 12:51:48 GMT</pubDate>
    <dc:creator>ciscocsoc</dc:creator>
    <dc:date>2009-09-02T12:51:48Z</dc:date>
    <item>
      <title>ACE: Problem with SSL termination</title>
      <link>https://community.cisco.com/t5/application-networking/ace-problem-with-ssl-termination/m-p/1303594#M27122</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm seeing a strange problem with SSL termination. The context is using Source NAT to backend webservers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The symptom is that the ACE doesn't send back the "server hello" in response to the "client hello". I get an ACK and then a reset from the client after ca 35 seconds.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The certificates and chains are all valid as far as I can see. I have other contexts with similar configurations working happily.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've been through the troubleshooting wiki but it hasn't helped. Are there any known reasons for the exhibited behaviour or additional debug steps I can go through?  The code level is 2.1.3.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cathy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Sep 2009 06:17:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-problem-with-ssl-termination/m-p/1303594#M27122</guid>
      <dc:creator>ciscocsoc</dc:creator>
      <dc:date>2009-09-02T06:17:42Z</dc:date>
    </item>
    <item>
      <title>Re: ACE: Problem with SSL termination</title>
      <link>https://community.cisco.com/t5/application-networking/ace-problem-with-ssl-termination/m-p/1303595#M27123</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try without the ssl paramter map (with the cipher).  See if that helps.&lt;/P&gt;&lt;P&gt;Also get a 'show stats crypto server' before and after a failure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;G.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Sep 2009 12:21:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-problem-with-ssl-termination/m-p/1303595#M27123</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2009-09-02T12:21:51Z</dc:date>
    </item>
    <item>
      <title>Re: ACE: Problem with SSL termination</title>
      <link>https://community.cisco.com/t5/application-networking/ace-problem-with-ssl-termination/m-p/1303596#M27124</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Gilles,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Removing the ciphers didn't help.  I've attached the output of the "before" and "after" stats.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cathy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Sep 2009 12:51:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-problem-with-ssl-termination/m-p/1303596#M27124</guid>
      <dc:creator>ciscocsoc</dc:creator>
      <dc:date>2009-09-02T12:51:48Z</dc:date>
    </item>
    <item>
      <title>Re: ACE: Problem with SSL termination</title>
      <link>https://community.cisco.com/t5/application-networking/ace-problem-with-ssl-termination/m-p/1303597#M27125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If we check the client hello received, we can see the counters did not increase.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, the client hello is probably dropped internally before it gets to the SSL ME.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can check with 'show np 1 me-stat "-snorm"', 'show np 1 me-stat "-sfp"' and 'show np 1 me-stat "-stcp"' if there are any drops.&lt;/P&gt;&lt;P&gt;Do the same for np 2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Again repeat the operation and see which counters increase with each failure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try to disable normalization if not already done.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also verify that the hw path is correct with the following command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show np 1 access-l trace vlan &lt;XX&gt; in proto 6 source x.x.x.x 0 destaintion x.x.x.x 443&lt;/XX&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check the line which says :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;......vserver: 0x...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Convert the vserver id to decimal and then do&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show cfgmgr internal table l3-vip | i &lt;VSERVER&gt;&lt;/VSERVER&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should get 2 new id.&lt;/P&gt;&lt;P&gt;One for the policy and one for the class-map.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Verify those id with the command&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show cfgmgr internal table class-map&lt;/P&gt;&lt;P&gt;show cfgmgr internal table policy-map&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If this corresponds to your config, then this is ok.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If not, remove the policy from the interface, wait 5 sec and reconfigure it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Sep 2009 08:50:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-problem-with-ssl-termination/m-p/1303597#M27125</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2009-09-03T08:50:48Z</dc:date>
    </item>
    <item>
      <title>Re: ACE: Problem with SSL termination</title>
      <link>https://community.cisco.com/t5/application-networking/ace-problem-with-ssl-termination/m-p/1303598#M27126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you Gilles. There did seem to be a mismatch between the numbers.  Deleting the service-policy and L4POLICY, waiting a few seconds and then reinstating them appears to have done the trick.  I'm now seeing all of the SSL handshake and I can access the servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cathy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Sep 2009 09:22:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-problem-with-ssl-termination/m-p/1303598#M27126</guid>
      <dc:creator>ciscocsoc</dc:creator>
      <dc:date>2009-09-03T09:22:02Z</dc:date>
    </item>
  </channel>
</rss>

