<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACE SSL Termination (40) Handshake Failure in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384442#M28780</link>
    <description>&lt;P&gt;I have configured the ACE 4710 as a network load balancer and this is working well for most sites.&amp;nbsp; Now I have installed the SSL cert and the https version of the site will not be displayed.&amp;nbsp; Ran Wireshark protocol analyser and it indicates a RST packet was recieved with error (40) Handshake failure.. any ideas?&lt;/P&gt;</description>
    <pubDate>Wed, 10 Mar 2010 20:02:32 GMT</pubDate>
    <dc:creator>networker99</dc:creator>
    <dc:date>2010-03-10T20:02:32Z</dc:date>
    <item>
      <title>ACE SSL Termination (40) Handshake Failure</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384442#M28780</link>
      <description>&lt;P&gt;I have configured the ACE 4710 as a network load balancer and this is working well for most sites.&amp;nbsp; Now I have installed the SSL cert and the https version of the site will not be displayed.&amp;nbsp; Ran Wireshark protocol analyser and it indicates a RST packet was recieved with error (40) Handshake failure.. any ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Mar 2010 20:02:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384442#M28780</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2010-03-10T20:02:32Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL Termination (40) Handshake Failure</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384443#M28781</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Too hard to say without any data.&amp;nbsp; Would it be possible to upload your config, the capture, and let us know what version of software you are running?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Sean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Mar 2010 21:33:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384443#M28781</guid>
      <dc:creator>Sean Merrow</dc:creator>
      <dc:date>2010-03-10T21:33:56Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL Termination (40) Handshake Failure</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384444#M28782</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here you go.. plus I have check the cert against the keys and all is okay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Mar 2010 22:21:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384444#M28782</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2010-03-10T22:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL Termination (40) Handshake Failure</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384445#M28783</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try maybe without "ssl advanced-options mywebsite.org" under your ssl proxy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, we need a sniffer trace to see the failure and a show tech captured after the problem occured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2010 09:26:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384445#M28783</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2010-03-11T09:26:35Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL Termination (40) Handshake Failure</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384446#M28784</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unless your real server is listening on port 443 for clear-text, then your current config needs to be modified for this to work.&amp;nbsp; Unless the rserver within the serverfarm specifies a port number, then the port number used on the frontend will also be used on the backend. You are using 443 on the frontend, but only doing SSL termination, not SSL intiation.&amp;nbsp; Therefore, you need to specify the clear-text port that the rserver is listening on.&amp;nbsp; For example, assuming your rserver is listening on the default www port of 80, your serverfarm should look like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;serverfarm host WEBFARM&lt;BR /&gt;&amp;nbsp; description Web farm for WEBFARM&lt;BR /&gt;&amp;nbsp; rserver website.orgtest &lt;STRONG style="color: #ff0000; "&gt;80&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps,&lt;/P&gt;&lt;P&gt;Sean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2010 14:19:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384446#M28784</guid>
      <dc:creator>Sean Merrow</dc:creator>
      <dc:date>2010-03-11T14:19:50Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL Termination (40) Handshake Failure</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384447#M28785</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Thanks for the reply.. had worked this out earlier this morning.. thanks again!.. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="background-color: #f8fafd;"&gt;Is there a way on the load balancer to redirect requests to &lt;A href="http://mywebsite.com"&gt;http://mywebsite.com&lt;/A&gt; to &lt;A href="https://mywebsite.com"&gt;https://mywebsite.com&lt;/A&gt; automatically?&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2010 16:49:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384447#M28785</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2010-03-11T16:49:07Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL Termination (40) Handshake Failure</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384448#M28786</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes there is.&amp;nbsp; See the attachment.&amp;nbsp; It will show you how to get the ACE to take care of this.&amp;nbsp; Since your backend server is listening on a clear-text port, any HTTP 301 or 302 redirect that comes from the server will likely have a Location header value of &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://xxxx"&gt;http://xxxx&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp; So, you'll see the action-list in the attachment will force the ACE to re-write the &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://"&gt;http://&lt;/A&gt;&lt;SPAN&gt; in that header to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://"&gt;https://&lt;/A&gt;&lt;SPAN&gt; as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps,&lt;/P&gt;&lt;P&gt;Sean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2010 17:04:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384448#M28786</guid>
      <dc:creator>Sean Merrow</dc:creator>
      <dc:date>2010-03-11T17:04:07Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL Termination (40) Handshake Failure</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384449#M28787</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Many thanks.. however I still have a slight issue.&amp;nbsp; It is regarding the line:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style=": ; color: #ff0000; font-size: 12pt; font-family: Courier New; "&gt;&lt;SPAN class="SpellE"&gt;&lt;SPAN class="GramE"&gt;webhost&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="GramE"&gt;-redirection&lt;/SPAN&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/"&gt;https://%h%p&lt;/A&gt;&lt;SPAN&gt; 301&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #ff0000; font-family: Courier New; "&gt;This only works if I put&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style=": ; color: #ff0000; font-family: Courier New; "&gt;&lt;SPAN class="SpellE"&gt;&lt;SPAN class="GramE"&gt;webhost&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class="GramE"&gt;-redirection&lt;/SPAN&gt; &lt;A href="https://www.mywebsite.com"&gt;https://www.mywebsite.com&lt;/A&gt; 301 and not &lt;A href="https://community.cisco.com/"&gt;https://%h%p&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #ff0000; font-family: Courier New; "&gt;therefore this is fine if someone goes to &lt;A href="http://www.mywebsite.com"&gt;http://www.mywebsite.com&lt;/A&gt; and they get redirected to &lt;A href="https://www.mywebsite.com"&gt;https://www.mywebsite.com&lt;/A&gt; but if they go to &lt;A href="http://www.mywebsite.com/contactus.html"&gt;http://www.mywebsite.com/contactus.html&lt;/A&gt; they get redirected to &lt;A href="https://www.mywebsite.com"&gt;https://www.mywebsite.com&lt;/A&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="color: #ff0000; font-family: Courier New; "&gt;Thanks!&lt;/STRONG&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2010 18:04:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384449#M28787</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2010-03-11T18:04:21Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL Termination (40) Handshake Failure</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384450#M28788</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Interesting that it doesn't work.&amp;nbsp; The %h just says to keep whatever hostname the client used in the original request, but just change the &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://"&gt;http://&lt;/A&gt;&lt;SPAN&gt; to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://"&gt;https://&lt;/A&gt;&lt;SPAN&gt;.&amp;nbsp; The %p simply means to keep the same path as the original request.&amp;nbsp; You don't have to use them, or you can just use one of them if you want.&amp;nbsp; So in your case, perhaps your answer is:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;webhost-redirection &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/"&gt;https://www.mywebsite.com%p&lt;/A&gt;&lt;SPAN&gt; 301&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Now, if someone requests &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.mywebsite.com/contactus"&gt;http://www.mywebsite.com/contactus&lt;/A&gt;&lt;SPAN&gt; they will be redirected to &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.mywebsite.com/contactus"&gt;https://www.mywebsite.com/contactus&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, since the hostname in the original request is the same as the hostname in the redirect, I would've expected the %h to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2010 19:11:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384450#M28788</guid>
      <dc:creator>Sean Merrow</dc:creator>
      <dc:date>2010-03-11T19:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL Termination (40) Handshake Failure</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384451#M28789</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Funny.. I re-entered the commands and now it works.. maybe a typo??!! thanks ago!!!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One last question.&amp;nbsp; Can you direct me on how to set up the health checking so that a webserver will be taken out of the farm if it returns a specific string in the html?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2010 19:23:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384451#M28789</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2010-03-11T19:23:37Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL Termination (40) Handshake Failure</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384452#M28790</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, that's a new one to me.&amp;nbsp; I've yet to see someone want to remove a server from the rotation when it &lt;STRONG&gt;has &lt;/STRONG&gt;a string in the content.&amp;nbsp; Usually, we see customers that want to remove a server from rotation when it &lt;STRONG&gt;doesn't&lt;/STRONG&gt; have the string in the body.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A common HTTP keepalive would be something like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;probe http HTTP-KEEPALIVE&lt;BR /&gt;&amp;nbsp; interval 10&lt;BR /&gt;&amp;nbsp; faildetect 3&lt;BR /&gt;&amp;nbsp; passdetect interval 30&lt;BR /&gt;&amp;nbsp; passdetect count 2&lt;BR /&gt;&amp;nbsp; receive 3&lt;BR /&gt;&amp;nbsp; open 3&lt;BR /&gt;&amp;nbsp; request method get url /keepalive.html&lt;BR /&gt;&amp;nbsp; expect status 200 200&amp;nbsp; &lt;SPAN style="color: #0000ff;"&gt;&amp;lt;-- &lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;this is required when 'expect regex' is not used&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here, as long as it gets a HTTP 200 OK Response, it will pass.&amp;nbsp; In addition to, or in place of, the &lt;STRONG&gt;expect status&lt;/STRONG&gt;, you can also use the &lt;STRONG&gt;&lt;A href="http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/slb/guide/probe.html#wp1075645"&gt;expect regex&lt;/A&gt;&lt;/STRONG&gt;.&amp;nbsp; Click the link for details on how to configure that.&amp;nbsp; If you use expect regex, then the response from the server must include the Content-Length header.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;probe http HTTP-KEEPALIVE&lt;BR /&gt;&amp;nbsp;&amp;nbsp; interval 10&lt;BR /&gt;&amp;nbsp;&amp;nbsp; faildetect 3&lt;BR /&gt;&amp;nbsp;&amp;nbsp; passdetect interval 30&lt;BR /&gt;&amp;nbsp;&amp;nbsp; passdetect count 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp; receive 3&lt;BR /&gt;&amp;nbsp;&amp;nbsp; open 3&lt;BR /&gt;&amp;nbsp;&amp;nbsp; request method get url /keepalive.html&lt;BR /&gt;&amp;nbsp;&amp;nbsp; expect regex Hello&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; expect status 200 200&amp;nbsp; &lt;SPAN style="color: #0000ff;"&gt;&amp;lt;-- &lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;this is now optional when the 'expect regex' is used&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the above example, the rserver will be pulled out of rotation if the response &lt;STRONG&gt;does not&lt;/STRONG&gt; contain Hello in its response.&amp;nbsp; I'm not aware of a way to get the ACE to pull the server out of rotation if it &lt;STRONG&gt;does &lt;/STRONG&gt;have this string.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Not sure if this helps or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2010 20:00:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384452#M28790</guid>
      <dc:creator>Sean Merrow</dc:creator>
      <dc:date>2010-03-11T20:00:27Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL Termination (40) Handshake Failure</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384453#M28791</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Maybe I explained it wrong..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there are two servers that provide website search results for a front end web server .&amp;nbsp; If the SQL/search service dies on one I only want the other to be queried.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2010 20:04:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384453#M28791</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2010-03-11T20:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL Termination (40) Handshake Failure</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384454#M28792</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can apply multiple probes to each global rserver.&amp;nbsp; By default, both of them would have to pass for the rserver to be considered healthy.&amp;nbsp; Each probe below can have a unique IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;host1/Admin(config)# rserver WWW-SERVER1&lt;BR /&gt;host1/Admin(config-rserver-host)# ip address 192.168.12.15&lt;BR /&gt;host1/Admin(config-rserver-host)# probe SQL_PROBE&lt;BR /&gt;host1/Admin(config-rserver-host)# probe WWW_PROBE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, in the example above, the WWW_PROBE configuration would not have an IP address associated and therefore would inherit the IP address of the rserver.&amp;nbsp; For the SQL_PROBE, you could specifically configure the IP address of the SQL server in the probe configuration.&amp;nbsp; So both the SQL server and the WWW server would have to be healthy in order for this server to be included in the load balancing rotation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2010 20:42:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384454#M28792</guid>
      <dc:creator>Sean Merrow</dc:creator>
      <dc:date>2010-03-11T20:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL Termination (40) Handshake Failure</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384455#M28793</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I guess what I am asking is how can it detect application errors rather than web errors?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 11 Mar 2010 20:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384455#M28793</guid>
      <dc:creator>networker99</dc:creator>
      <dc:date>2010-03-11T20:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: ACE SSL Termination (40) Handshake Failure</title>
      <link>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384456#M28794</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately, the ACE cannot passively monitor application traffic for specific errors or patterns to determine when an rserver should or should not be in the load balancing rotation.&amp;nbsp; The only options I'm aware of are all the probes described in the &lt;A href="http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/slb/guide/probe.html"&gt;Configuring Health Monitoring&lt;/A&gt; document, which includes several application-layer probes.&amp;nbsp; Obviously, the HTTP and/or HTTPS probes should cover you for your web servers.&amp;nbsp; For the SQL servers, you might be able to accomplish it with a TCP probe and &lt;STRONG&gt;expect regex&lt;/STRONG&gt;.&amp;nbsp; Otherwise, you would need to get creative with using TCL scripts for probing.&amp;nbsp; This is documented in the &lt;A href="http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/slb/guide/script.html"&gt;Using Toolkit Command Language (TCL) Scripts with the ACE&lt;/A&gt; documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Sean&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 12 Mar 2010 16:35:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-ssl-termination-40-handshake-failure/m-p/1384456#M28794</guid>
      <dc:creator>Sean Merrow</dc:creator>
      <dc:date>2010-03-12T16:35:29Z</dc:date>
    </item>
  </channel>
</rss>

