<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSS - 11506 - Adding New SSL Services on Single SSL Modules in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371889#M28548</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pl. reply we need confirm on urgent basis.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 11 Feb 2010 07:41:40 GMT</pubDate>
    <dc:creator>Dulal Ray</dc:creator>
    <dc:date>2010-02-11T07:41:40Z</dc:date>
    <item>
      <title>CSS - 11506 - Adding New SSL Services on Single SSL Modules</title>
      <link>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371888#M28547</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are having one pair of CCS 11506 currently SSL services are running on slot4 with single SSL module.Now we are planning to add one more SSL application with different certificates &amp;amp; keys on different VIP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can we use the same slot4 for new application &amp;amp; using different certicates &amp;amp; keys on same SSL modules.Your reponse is appriecated&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2010 07:19:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371888#M28547</guid>
      <dc:creator>Dulal Ray</dc:creator>
      <dc:date>2010-02-11T07:19:11Z</dc:date>
    </item>
    <item>
      <title>Re: CSS - 11506 - Adding New SSL Services on Single SSL Modules</title>
      <link>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371889#M28548</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pl. reply we need confirm on urgent basis.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Feb 2010 07:41:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371889#M28548</guid>
      <dc:creator>Dulal Ray</dc:creator>
      <dc:date>2010-02-11T07:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: CSS - 11506 - Adding New SSL Services on Single SSL Modules</title>
      <link>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371890#M28549</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, you can use the same SSL module for multiple applications.&amp;nbsp; No need to add a second SSL module.&amp;nbsp; Below are the typical and general steps:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Import the new certificate and key onto the CSS&lt;/LI&gt;&lt;LI&gt;Associate the new certificate and key to filenames&lt;/LI&gt;&lt;LI&gt;Create your new ssl-server on the existing ssl-proxy-list (including VIPs, cert, key, etc.)&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;Add any necessary content rules, services, groups, and redundant VIPs&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can find more details on the SSL configuration at the link below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;CSS SSL Configuration Guide&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/css11500series/v8.20/configuration/ssl/guide/sslgd.html"&gt;http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/css11500series/v8.20/configuration/ssl/guide/sslgd.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Sean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Feb 2010 17:38:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371890#M28549</guid>
      <dc:creator>Sean Merrow</dc:creator>
      <dc:date>2010-02-11T17:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: CSS - 11506 - Adding New SSL Services on Single SSL Modules</title>
      <link>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371891#M28550</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sean,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pl. can you confirm the statement which is given in CSS admin guide which states &lt;SPAN style="font-family: Verdana; font-size: 10pt;"&gt;t&lt;SPAN style="font-size: 10pt; font-family: Times-Roman; "&gt;he CSS supports one active SSL service for each SSL module in the CSS (one SSL service per slot). You can configure more than one SSL service for a slot but only a single SSL service can be active at a time.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV dir="ltr"&gt; &lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN style="font-family: Verdana; font-size: 10pt;"&gt;Pl. find the below URL for your reference.&lt;/SPAN&gt;&lt;/DIV&gt;&lt;DIV dir="ltr"&gt; &lt;/DIV&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN style="font-family: Verdana; color: #000000; font-size: 10pt;"&gt;&lt;DIV dir="ltr"&gt;&lt;SPAN lang="EN"&gt;&lt;SPAN style="color: #0000ff; text-decoration: underline; "&gt;&lt;A href="http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/css11500series/v7.50/configuration/ssl/guide/terminat.html#wp999928" title="http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/css11500series/v7.50/configuration/ssl/guide/terminat.html#wp999928"&gt;http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/css11500series/v7.50/configuration/ssl/guide/terminat.html#wp999928&lt;/A&gt;&lt;/SPAN&gt;&lt;A href="https://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/css11500series/v8.20/configuration/ssl/guide/sslcggde.pdf" target="_blank" title="https://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/css11500series/v8.20/configuration/ssl/guide/sslcggde.pdf"&gt;https://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/css11500series/v8.20/configuration/ssl/guide/sslcggde.pdf&lt;/A&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Feb 2010 19:32:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371891#M28550</guid>
      <dc:creator>Dulal Ray</dc:creator>
      <dc:date>2010-02-11T19:32:04Z</dc:date>
    </item>
    <item>
      <title>Re: CSS - 11506 - Adding New SSL Services on Single SSL Modules</title>
      <link>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371892#M28551</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, I can see how that statement could lead to a bit of confusion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Although the SSL module is inserted into the CSS, you can think of it as an external device.&amp;nbsp; For example, a connection coming into the CSS on port 443 for SSL termination would first hit a content rule on the CSS.&amp;nbsp; The CSS would then load balance that connection to the internal SSL module.&amp;nbsp; In order to do this, you would have to configure a service under that content rule.&amp;nbsp; This service would represent the have a type of ssl-accel, specify the slot that the SSL module is in, and specify the ssl-proxy-list that is applied to that SSL module.&amp;nbsp; After the SSL module terminates the SSL connection, the connection is sent back to the CSS.&amp;nbsp; The statement you are referring to means that you can only have one active service in your CSS configuration per SSL module. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is completely different from having multiple applications or VIPs on your SSL module. The ssl-proxy-list that is applied to the SSL module is where you would configure your various applications.&amp;nbsp; Each application can use the same or a different set of keys and certs.&amp;nbsp; Below is an example of a ssl-proxy-list that contains two different applications/VIPs.&amp;nbsp; Notice that each one is using a unique key and certificate.&amp;nbsp; Also notice that this ssl-proxy-list, with two applications in it, is applied to a single SSL module via the service that represents this module.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;!*********************** SSL PROXY LIST ***********************&lt;BR /&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;ssl-proxy-list SSL_PROXY&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; ssl-server 1 &lt;BR /&gt;&amp;nbsp; ssl-server 1 cipher rsa-with-rc4-128-md5 10.86.179.198 81 &lt;BR /&gt;&amp;nbsp; ssl-server 1 &lt;STRONG&gt;vip address 10.86.178.198&lt;/STRONG&gt; &lt;BR /&gt;&amp;nbsp; ssl-server 1 rsakey site-1-key &lt;BR /&gt;&amp;nbsp; ssl-server 1 rsacert site-1-cert&lt;BR /&gt;&amp;nbsp; ssl-server 2 &lt;BR /&gt;&amp;nbsp; ssl-server 2 cipher rsa-with-rc4-128-md5 10.86.179.199 81 &lt;BR /&gt;&amp;nbsp; ssl-server 2 &lt;STRONG&gt;vip address 10.86.178.199 &lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; ssl-server 2 rsakey site-2-key&lt;BR /&gt;&amp;nbsp; ssl-server 2 rsacert site-2-cert&lt;BR /&gt;&amp;nbsp; active&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;!************************** SERVICE **************************&lt;BR /&gt;service SSL_SLOT_3 &lt;BR /&gt;&amp;nbsp; &lt;STRONG&gt;type ssl-accel&lt;/STRONG&gt; &lt;BR /&gt;&amp;nbsp; add &lt;STRONG style="color: #0000ff; "&gt;ssl-proxy-list SSL_PROXY&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; &lt;STRONG&gt;slot 3&lt;/STRONG&gt; &lt;BR /&gt;&amp;nbsp; keepalive type none &lt;BR /&gt;&amp;nbsp; active &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps clear it up for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;Sean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Feb 2010 19:52:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371892#M28551</guid>
      <dc:creator>Sean Merrow</dc:creator>
      <dc:date>2010-02-11T19:52:30Z</dc:date>
    </item>
    <item>
      <title>Re: CSS - 11506 - Adding New SSL Services on Single SSL Modules</title>
      <link>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371893#M28552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sean,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your wonderful explanation.&lt;/P&gt;&lt;P&gt;However a small clarification on the configuration below:-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Instead of having it as you suggested, (i.e. Add the new virtual SSL Server in the same proxy-list),&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can we have a different proxy-list for the new Virtual Server and then add this list as-well in the exisisting Service? and with the other corresponding Config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier; font-size: 10pt;"&gt;!*********************** SSL PROXY LIST ***********************&lt;BR /&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;ssl-proxy-list SSL_PROXY&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; ssl-server 1 &lt;BR /&gt;&amp;nbsp; ssl-server 1 cipher rsa-with-rc4-128-md5 10.86.179.198 81 &lt;BR /&gt;&amp;nbsp; ssl-server 1 &lt;STRONG&gt;vip address 10.86.178.198&lt;/STRONG&gt; &lt;BR /&gt;&amp;nbsp; ssl-server 1 rsakey site-1-key &lt;BR /&gt;&amp;nbsp; ssl-server 1 rsacert site-1-cert&lt;BR /&gt;&amp;nbsp; active&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #0000ff; font-size: 10pt; font-family: courier new, courier; "&gt;&lt;STRONG&gt;ssl-proxy-list SSL_PROXY_NEW&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier; font-size: 10pt;"&gt;&amp;nbsp; ssl-server 2 &lt;BR /&gt;&amp;nbsp; ssl-server 2 cipher rsa-with-rc4-128-md5 10.86.179.199 81 &lt;BR /&gt;&amp;nbsp; ssl-server 2 &lt;STRONG&gt;vip address 10.86.178.199 &lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; ssl-server 2 rsakey site-2-key&lt;BR /&gt;&amp;nbsp; ssl-server 2 rsacert site-2-cert&lt;BR /&gt;&amp;nbsp; active&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier; font-size: 10pt;"&gt;!************************** SERVICE **************************&lt;BR /&gt;service SSL_SLOT_3 &lt;BR /&gt;&amp;nbsp; &lt;STRONG&gt;type ssl-accel&lt;/STRONG&gt; &lt;BR /&gt;&amp;nbsp; add &lt;STRONG style="color: #0000ff;"&gt;ssl-proxy-list SSL_PROXY&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new, courier; font-size: 10pt;"&gt;&lt;SPAN style="color: #0000ff;"&gt;&lt;STRONG&gt;&amp;nbsp; &lt;/STRONG&gt;&lt;SPAN style="color: #333333;"&gt;add &lt;/SPAN&gt;&lt;STRONG&gt;ssl-proxy-list SSL_PROXY_NEW&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; &lt;STRONG&gt;slot 3&lt;/STRONG&gt; &lt;BR /&gt;&amp;nbsp; keepalive type none &lt;BR /&gt;&amp;nbsp; active &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot for your time... Awaiting your response.!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Feb 2010 05:57:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371893#M28552</guid>
      <dc:creator>Dulal Ray</dc:creator>
      <dc:date>2010-02-12T05:57:18Z</dc:date>
    </item>
    <item>
      <title>Re: CSS - 11506 - Adding New SSL Services on Single SSL Modules</title>
      <link>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371894#M28553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I like the way you think ;- )&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You probably want to do that so that you don't have to suspend all the applications on the ssl-proxy-list when making changes.&amp;nbsp; However, the service will only allow you to add a single ssl-proxy-list to it.&amp;nbsp; So if you only have a single SSL module, then you would only have a single ssl-proxy-list and it would be added to the service for the SSL module. If you try to add a second ssl-proxy-list to the service, you'll see this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;CSS11503(config)# &lt;STRONG&gt;service &lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;SSL_SLOT_3&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;CSS11503(config-service[&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;SSL_SLOT_3&lt;/SPAN&gt;])# &lt;STRONG&gt;add ssl-proxy-list &lt;SPAN style="color: #0000ff;"&gt;SSL_PROXY&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;CSS11503(config-service[&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;SSL_SLOT_3&lt;/SPAN&gt;])# &lt;STRONG&gt;add ssl-proxy-list &lt;SPAN style="color: #0000ff;"&gt;SSL_PROXY_NEW&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;%% Maximum number of Ssl Proxy Lists added to service&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;BR /&gt;CSS11503(config-service[&lt;SPAN style="font-family: courier new,courier; font-size: 10pt;"&gt;SSL_SLOT_3&lt;/SPAN&gt;])#&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In most cases, even if customers have more than one SSL module, they will still only have a single ssl-proxy-list containing all their applications using SSL, add it to both services (one for each SSL module) and add both of those services to the content.rule.&amp;nbsp; This way, both SSL modules handle the same traffic and the CSS will load balance them.&amp;nbsp; If one SSL module fails, the other will handle the load and there is no outage.&amp;nbsp; The CSS will allow you to assign a unique ssl-proxy-list to each SSL module in the chassis, but then you lose the benefits of load balancing and redundancy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Feb 2010 13:56:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371894#M28553</guid>
      <dc:creator>Sean Merrow</dc:creator>
      <dc:date>2010-02-12T13:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: CSS - 11506 - Adding New SSL Services on Single SSL Modules</title>
      <link>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371895#M28554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sean,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for replying back just want few clarifcations in configuration part.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. If new vlan is given for new application then how to point routes to the new vlan as default routes to exisitng vlan is already present.&lt;/P&gt;&lt;P&gt;2. I've prepare sample config template with details steps &amp;amp; let us know will it work &amp;amp; if changes is required kindly let us know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;1.# ftp-record ssl_record 192.168.19.21 johndoe "abc123"&lt;/P&gt;&lt;P&gt;/home/johndoe&lt;/P&gt;&lt;P&gt;2.# copy ssl sftp ssl_record import rsacert.pem PEM "passwd123"&lt;/P&gt;&lt;P&gt;Connecting&lt;/P&gt;&lt;P&gt;Completed successfully&lt;/P&gt;&lt;P&gt;3.# copy ssl sftp ssl_record import rsakey.pem PEM "passwd123"&lt;/P&gt;&lt;P&gt;Connecting&lt;/P&gt;&lt;P&gt;Completed successfully&lt;/P&gt;&lt;P&gt;4.Enter configuration mode.&lt;/P&gt;&lt;P&gt;# config&lt;/P&gt;&lt;P&gt;(config) #&lt;/P&gt;&lt;P&gt;4. To use RSA public key exchange and authentication:&lt;/P&gt;&lt;P&gt;a. Associate the imported RSA certificate with a file.&lt;/P&gt;&lt;P&gt;(config) # ssl associate cert myrsacert1 rsacert.pem&lt;/P&gt;&lt;P&gt;b. Associate the imported RSA key pair with a file.&lt;/P&gt;&lt;P&gt;(config) # ssl associate rsakey myrsakey1 rsakey.pem&lt;/P&gt;&lt;P&gt;5. Compare the public key in the associated certificate with the public key&lt;/P&gt;&lt;P&gt;stored with the associated private key and verify that they are identical.&lt;/P&gt;&lt;P&gt;(config) # ssl verify myrsacert1 myrsakey1&lt;/P&gt;&lt;P&gt;Certificate mycert1 matches key mykey1&lt;/P&gt;&lt;P&gt;ssl associate rsakey NEWKEY newkey.pem&lt;/P&gt;&lt;P&gt;ssl associate cert NEWCERT newcert.pem&lt;/P&gt;&lt;P&gt;!************************* INTERFACE *************************&lt;/P&gt;&lt;P&gt;interface 3/3&lt;/P&gt;&lt;P&gt;description "****WEB SIDE****"&lt;/P&gt;&lt;P&gt;bridge vlan _ID_X.X.X.X&lt;/P&gt;&lt;P&gt;bridge port-fast enable&lt;/P&gt;&lt;P&gt;interface 3/4&lt;/P&gt;&lt;P&gt;bridge vlan_ID_Y.Y.Y.Y&lt;/P&gt;&lt;P&gt;bridge port-fast enable&lt;/P&gt;&lt;P&gt;description "****PIX SIDE****"&lt;/P&gt;&lt;P&gt;!************************** CIRCUIT **************************&lt;/P&gt;&lt;P&gt;circuit VLAN_ID_X&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address A.A.A.A B.B.B.0&lt;/P&gt;&lt;P&gt;ip virtual-router 2 priority 101 preempt&lt;/P&gt;&lt;P&gt;ip redundant-interface 3 C.C.C.C&lt;/P&gt;&lt;P&gt;ip critical-service 3 chk-con-pix_Y.Y.Y.Y&lt;/P&gt;&lt;P&gt;ip critical-service 3 chk-con-web_X.X.X.X&lt;/P&gt;&lt;P&gt;circuit VLAN_ID_Y&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip address D.D.D.D E.E.E.0&lt;/P&gt;&lt;P&gt;ip virtual-router 4 priority 101 preempt&lt;/P&gt;&lt;P&gt;ip redundant-vip 4 F.F.F.F&lt;/P&gt;&lt;P&gt;ip critical-service 4 chk-con-pix_Y.Y.Y.Y&lt;/P&gt;&lt;P&gt;ip critical-service 4 chk-con-web_X.X.X.X&lt;/P&gt;&lt;P&gt;!*********************** SSL PROXY LIST ***********************&lt;/P&gt;&lt;P&gt;ssl-proxy-list NEW&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl-server 20&lt;/P&gt;&lt;P&gt;ssl-server 20 vip address F.F.F.F&lt;/P&gt;&lt;P&gt;ssl-server 20 cipher rsa-with-rc4-128-sha F.F.F.F 81&lt;/P&gt;&lt;P&gt;ssl-server 20 cipher rsa-with-rc4-128-md5 F.F.F.F 81&lt;/P&gt;&lt;P&gt;ssl-server 20 rsacert NEWCERT&lt;/P&gt;&lt;P&gt;ssl-server 20 rsakey NEWKEY&lt;/P&gt;&lt;P&gt;active&lt;/P&gt;&lt;P&gt;!************************** SERVICE **************************&lt;/P&gt;&lt;P&gt;service FRONT_SSL&lt;/P&gt;&lt;P&gt;type ssl-accel&lt;/P&gt;&lt;P&gt;slot 4&lt;/P&gt;&lt;P&gt;keepalive type none&lt;/P&gt;&lt;P&gt;add ssl-proxy-list NEW&lt;/P&gt;&lt;P&gt;active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service WEBSERVER-03&lt;/P&gt;&lt;P&gt;ip address G.G.G.G&lt;/P&gt;&lt;P&gt;redundant-index 3&lt;/P&gt;&lt;P&gt;protocol tcp&lt;/P&gt;&lt;P&gt;port 80&lt;/P&gt;&lt;P&gt;active&lt;/P&gt;&lt;P&gt;service WEBSERVER-04&lt;/P&gt;&lt;P&gt;ip address H.H.H.H&lt;/P&gt;&lt;P&gt;redundant-index 4&lt;/P&gt;&lt;P&gt;protocol tcp&lt;/P&gt;&lt;P&gt;port 80&lt;/P&gt;&lt;P&gt;active&lt;/P&gt;&lt;P&gt;service chk-con-pix_Y.Y.Y.Y&lt;/P&gt;&lt;P&gt;keepalive type script ap-kal-pinglist "N.N.N.N"&lt;/P&gt;&lt;P&gt;ip address J.J.J.J&lt;/P&gt;&lt;P&gt;keepalive frequency 2&lt;/P&gt;&lt;P&gt;keepalive maxfailure 2&lt;/P&gt;&lt;P&gt;keepalive retryperiod 2&lt;/P&gt;&lt;P&gt;active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service chk-con-web_X&lt;/P&gt;&lt;P&gt;ip address K.K.K.K&lt;/P&gt;&lt;P&gt;keepalive type script ap-kal-pinglist "P.P.P.P"&lt;/P&gt;&lt;P&gt;keepalive frequency 2&lt;/P&gt;&lt;P&gt;keepalive maxfailure 2&lt;/P&gt;&lt;P&gt;keepalive retryperiod 2&lt;/P&gt;&lt;P&gt;active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!*************************** OWNER ***************************&lt;/P&gt;&lt;P&gt;owner NEW&lt;/P&gt;&lt;P&gt;content BACKNEW_HTTP&lt;/P&gt;&lt;P&gt;vip address F.F.F.F&lt;/P&gt;&lt;P&gt;add service WEBSERVER-03&lt;/P&gt;&lt;P&gt;add service WEBSERVER-04&lt;/P&gt;&lt;P&gt;protocol tcp&lt;/P&gt;&lt;P&gt;port 81&lt;/P&gt;&lt;P&gt;url "/*"&lt;/P&gt;&lt;P&gt;redundant-index 5&lt;/P&gt;&lt;P&gt;no persistent&lt;/P&gt;&lt;P&gt;active&lt;/P&gt;&lt;P&gt;content FRONTENDNEW_SSL&lt;/P&gt;&lt;P&gt;vip address F.F.F.F&lt;/P&gt;&lt;P&gt;protocol tcp&lt;/P&gt;&lt;P&gt;port 443&lt;/P&gt;&lt;P&gt;application ssl&lt;/P&gt;&lt;P&gt;add service FRONT_SSL&lt;/P&gt;&lt;P&gt;active&lt;/P&gt;&lt;P&gt;content NEW&lt;/P&gt;&lt;P&gt;url "//www.ABC.com/*"&lt;/P&gt;&lt;P&gt;vip address F.F.F.F&lt;/P&gt;&lt;P&gt;protocol tcp&lt;/P&gt;&lt;P&gt;port 80&lt;/P&gt;&lt;P&gt;redundant-index 4&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;redirect "&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://ABC.com"&gt;https://ABC.com&lt;/A&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;your reply on this would be highly appericated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Feb 2010 06:39:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371895#M28554</guid>
      <dc:creator>Dulal Ray</dc:creator>
      <dc:date>2010-02-19T06:39:06Z</dc:date>
    </item>
    <item>
      <title>Re: CSS - 11506 - Adding New SSL Services on Single SSL Modules</title>
      <link>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371896#M28555</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;1. If new vlan is given for new application then how to point routes to the new vlan as default routes to exisitng vlan is already present.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ideally, you'll keep your configuration as simple as possible, and use only one default gateway.&amp;nbsp; This is the most common configuration.&amp;nbsp; However, if you need multiple default gateways (one for each client VLAN), then you can do this.&amp;nbsp; By default, when a client connection comes in from one gateway, the CSS will send the server's response back to the same gateway.&amp;nbsp; For server initiated connections, you might want to enable ECMP.&amp;nbsp; See the CSS documentation for details on &lt;A href="http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/css11500series/v8.20/configuration/routing/guide/IP.html#wp1015783"&gt;Configuring IP Equal-Cost Multipath&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;STRONG&gt;2. I've prepare sample config template with details steps &amp;amp; let us know will it work &amp;amp; if changes is required kindly let us know.&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would say that your config looks good. However, there are some lines in it that can be removed that I've put in bold.&amp;nbsp; &lt;STRONG&gt;redundant-index&lt;/STRONG&gt; is only used for connection replication, which cannot be used for SSL terminated connections.&amp;nbsp; Since it cannot be used for SSL, then there is no gain in configuring for the non-SSL related connections .&amp;nbsp; &lt;STRONG&gt;application ssl&lt;/STRONG&gt; is only needed when you are doing sticky on SSL session ID.&amp;nbsp; This would only be needed if you had more than one SSL module.&amp;nbsp; Adding the &lt;STRONG&gt;url &lt;/STRONG&gt;statement in the BACKNEW_HTTP rule unnecessarily makes this rule a layer-5 rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;content BACKNEW_HTTP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; vip address F.F.F.F&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; add service WEBSERVER-03&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; add service WEBSERVER-04&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; protocol tcp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; port 81&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: courier new,courier; "&gt;&amp;nbsp; url "/*"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: courier new,courier; "&gt;&amp;nbsp; redundant-index 5&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: courier new,courier; "&gt;&amp;nbsp; no persistent&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; active&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;content FRONTENDNEW_SSL&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; vip address F.F.F.F&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; protocol tcp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; port 443&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: courier new,courier; "&gt;&amp;nbsp; application ssl&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; add service FRONT_SSL&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; active&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;content NEW&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; url "//www.ABC.com/*"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; vip address F.F.F.F&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; protocol tcp&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; port 80&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: courier new,courier; "&gt;&amp;nbsp; redundant-index 4&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&lt;SPAN&gt;&amp;nbsp; redirect "&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://abc.com/"&gt;https://ABC.com&lt;/A&gt;&lt;SPAN&gt;"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; active&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can also remove the &lt;STRONG&gt;redundant-index&lt;/STRONG&gt; lines from the services configs.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;While I have made some observations and offered some recommendations regarding your config, until it has been thoroughly tested in a staging environment, or in the production environment, I make no guarrantees that you won't need to make further modifications to reach the ultimately desired operation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Sean&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Feb 2010 14:39:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371896#M28555</guid>
      <dc:creator>Sean Merrow</dc:creator>
      <dc:date>2010-02-19T14:39:52Z</dc:date>
    </item>
    <item>
      <title>Re: CSS - 11506 - Adding New SSL Services on Single SSL Modules</title>
      <link>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371897#M28556</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sean,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the information &amp;amp; sharing the depth knowledge on this niche CSS products.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However i'm yet to configure the new application but yet to confirm two things as follow&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 1. Whether CSS will support two default routes as there are different VLAN for each application &amp;amp; already one default routes is configured for previous application &amp;amp; for new application can we configured kindly confirm.You had explain it earlier but still the things not so clarfied to me.&lt;/P&gt;&lt;P&gt;2. I have certifcate in .pfx format if i import the same in CSS whether CSS will convert it into Keys &amp;amp; Certifcates as the.pfx file contains boths.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your reply is highy appriecated as the activity is already planned&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Mar 2010 11:44:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371897#M28556</guid>
      <dc:creator>Dulal Ray</dc:creator>
      <dc:date>2010-03-04T11:44:56Z</dc:date>
    </item>
    <item>
      <title>Re: CSS - 11506 - Adding New SSL Services on Single SSL Modules</title>
      <link>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371898#M28557</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You did not specify what you are still unclear on with regard to the multiple default routes.&amp;nbsp; The CSS supports multiple default gateways, and by default, it will use the same gateway for the response to a client as was used for the incoming connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the .pfx file, if it contains both the certificate and key, then you would first import the file, then associate both a cert and key to that same file as such:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&lt;STRONG&gt;ssl associate cert client-cert client.pfx&lt;BR /&gt;ssl associate rsakey client-key client.pfx&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps clear it up.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 Mar 2010 16:45:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371898#M28557</guid>
      <dc:creator>Sean Merrow</dc:creator>
      <dc:date>2010-03-04T16:45:31Z</dc:date>
    </item>
    <item>
      <title>Re: CSS - 11506 - Adding New SSL Services on Single SSL Modules</title>
      <link>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371899#M28558</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sean,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the support thru out the entire discussion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was able to complete the activity the only challegen i faced was the ceritfcate &amp;amp; key was a single file in .pfx format which exported from Windows server &amp;amp; due to this i was unable to assoicate the keys &amp;amp; certifcates in CSS after uploadig the files.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I used open SSL tool to create Key &amp;amp; Ceritficate in files separtely afterwhich we were able to assoicate the files but really like to appericate the support given thru out the issues.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Mar 2010 14:50:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371899#M28558</guid>
      <dc:creator>Dulal Ray</dc:creator>
      <dc:date>2010-03-08T14:50:28Z</dc:date>
    </item>
    <item>
      <title>Re: CSS - 11506 - Adding New SSL Services on Single SSL Modules</title>
      <link>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371900#M28559</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;:- )&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Glad I could help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 08 Mar 2010 14:53:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371900#M28559</guid>
      <dc:creator>Sean Merrow</dc:creator>
      <dc:date>2010-03-08T14:53:59Z</dc:date>
    </item>
    <item>
      <title>Re: CSS - 11506 - Adding New SSL Services on Single SSL Modules</title>
      <link>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371901#M28560</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sean,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We shifted the setup to production &amp;amp; faced issue from local lan of web &amp;amp; app communication below are detial explanation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We are using two default routes as there two different applications in different Vlans old application is working fine after configuring new application with new default routes,&lt;/P&gt;&lt;P&gt; ip route 0.0.0.0 0.0.0.0 10.250.Y.Y&amp;nbsp; - Old application&lt;BR /&gt; ip route 0.0.0.0 0.0.0.0 10.30.X.X - New Application&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Following is the issues&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Web1 - APP1 - Able to ping &amp;amp; Telnet to port 8080 or 80&lt;BR /&gt;Web 1 - App2 - Unable to ping &amp;amp; Telnet to port 8080 or 80&lt;BR /&gt;Web1 - NLB - Able to ping &amp;amp; Telnet to port 8080 or 80&lt;/P&gt;&lt;P&gt;Web2 - App1 -Unable to ping &amp;amp; Telnet to port 8080 or 80&lt;BR /&gt;Web2 - App2 - Able to ping &amp;amp; Telnet to port 8080 or 80&lt;BR /&gt;Web2 - NLB - Unable to ping &amp;amp; Telnet to port 8080 or 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But we configured static route from app segment towards firewall the above ping/telnet started working fine ive attached n/w block diagram just want to understand where is the issues.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 26 Mar 2010 12:21:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-11506-adding-new-ssl-services-on-single-ssl-modules/m-p/1371901#M28560</guid>
      <dc:creator>Dulal Ray</dc:creator>
      <dc:date>2010-03-26T12:21:44Z</dc:date>
    </item>
  </channel>
</rss>

