<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACE LB SSL Session ID in onearm mode in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-lb-ssl-session-id-in-onearm-mode/m-p/1477551#M30554</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem was caused by an incorrect nat pool.&amp;nbsp;&amp;nbsp; Correct Mask was 255.255.255.0.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 03 Aug 2010 18:22:07 GMT</pubDate>
    <dc:creator>robertsj2609</dc:creator>
    <dc:date>2010-08-03T18:22:07Z</dc:date>
    <item>
      <title>ACE LB SSL Session ID in onearm mode</title>
      <link>https://community.cisco.com/t5/application-networking/ace-lb-ssl-session-id-in-onearm-mode/m-p/1477550#M30553</link>
      <description>&lt;P&gt;I am trying to set-up SSL stickyness using the session ID in a onearm configuration mode and can not access the website via the vip.&amp;nbsp; I can browse to both servers directly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACE is connected to a Cat 6500, via a 4 gigabit ethernet port-channel and only the management and onearm context vlan is trunked down the port-channel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the OneArm Mode context i am able to ping the MSFC (VLAN980) default gateway and both rservers.&amp;nbsp; The rservers, Server Farm and Service Policy are all showing as in service.&amp;nbsp;&amp;nbsp; I am also able to ping the vip from any device on the network.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The incoming connection is establish and nat appears to take place, although the return session is report as init.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have posted the configuration below and was hoping someone could make a few suggestions.&amp;nbsp;&amp;nbsp; One of the things i notice is on the MSFC the nat address isn't in the arp table, although, it's showing on the ACE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;logging enable&lt;BR /&gt;logging buffered 7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list everyoneline 1 extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;script file name SSL_PROBE_SCRIPT&lt;/P&gt;&lt;P&gt;probe scripted ssl443&lt;BR /&gt;&amp;nbsp; port 443&lt;BR /&gt;&amp;nbsp; interval 60&lt;BR /&gt;&amp;nbsp; passdetect interval 60&lt;BR /&gt;&amp;nbsp; script SSL_PROBE_SCRIPT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type generic sslidparam&lt;BR /&gt;&amp;nbsp; set max-parse-length 70&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host host1&lt;BR /&gt;&amp;nbsp; ip address 192.168.20.129&lt;BR /&gt;&amp;nbsp; inservice&lt;BR /&gt;rserver host host2&lt;BR /&gt;&amp;nbsp; ip address 192.168.20.130&lt;BR /&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;serverfarm host ssl-443&lt;BR /&gt;&amp;nbsp; rserver host1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; weight 10&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; probe ssl443&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;BR /&gt;&amp;nbsp; rserver host2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; weight 10&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; probe ssl443&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky layer4-payload sticky-443&lt;BR /&gt;&amp;nbsp; timeout 720&lt;BR /&gt;&amp;nbsp; serverfarm ssl-443&lt;BR /&gt;&amp;nbsp; response sticky&lt;BR /&gt;&amp;nbsp; layer4-payload offset 43 length 32 begin-pattern "\x20"&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;class-map type management match-any MANAGEMENT&lt;BR /&gt;&amp;nbsp; 2 match protocol icmp any&lt;BR /&gt;&amp;nbsp; 3 match protocol http any&lt;BR /&gt;&amp;nbsp; 4 match protocol https any&lt;BR /&gt;&amp;nbsp; 5 match protocol ssh any&lt;BR /&gt;&amp;nbsp; 6 match protocol telnet any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-any slb-vip&lt;BR /&gt;&amp;nbsp; 3 match virtual-address 192.168.198.50 tcp eq https&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type management first-match MANAGEMENT-POLICY&lt;BR /&gt;&amp;nbsp; class MANAGEMENT&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance generic first-match slb-vip&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm sticky-443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match SSL-STICKY&lt;BR /&gt;&amp;nbsp; class slb-vip&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy slb-vip&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 980&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter generic advanced-options sslidparam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 980&lt;BR /&gt;&amp;nbsp; ip address 192.168.198.4 255.255.255.0&lt;BR /&gt;&amp;nbsp; peer ip address 192.168.198.5 255.255.255.0&lt;BR /&gt;&amp;nbsp; access-group input everyone&lt;BR /&gt;&amp;nbsp; nat-pool 1 192.168.198.6 192.168.198.6 netmask 255.255.255.255 pat&lt;BR /&gt;&amp;nbsp; service-policy input MANAGEMENT-POLICY&lt;BR /&gt;&amp;nbsp; service-policy input SSL-STICKY&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 192.168.198.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt;sh conn &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt;total current connections : 2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt;conn-id&amp;nbsp;&amp;nbsp;&amp;nbsp; np dir proto vlan source&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt;----------+--+---+-----+----+---------------------+---------------------+------+&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt;19828&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; in&amp;nbsp; TCP&amp;nbsp;&amp;nbsp; 98&amp;nbsp;&amp;nbsp; 192.168.18.139:2411&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #333333;"&gt;192.168.198.50&lt;/SPAN&gt;:443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ESTAB&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-size: 10pt; sans-serif&amp;amp;quot: ; font-family: &amp;amp;quot; Arial&amp;amp;quot: ; ,&amp;amp;quot: ; "&gt;19829&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; out TCP&amp;nbsp;&amp;nbsp; 98&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #333333;"&gt;192.168.20.129 &lt;/SPAN&gt;:443&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #333333;"&gt;192.168.198.6&lt;/SPAN&gt;:1059&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; INIT&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Aug 2010 18:29:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-lb-ssl-session-id-in-onearm-mode/m-p/1477550#M30553</guid>
      <dc:creator>robertsj2609</dc:creator>
      <dc:date>2010-08-02T18:29:47Z</dc:date>
    </item>
    <item>
      <title>Re: ACE LB SSL Session ID in onearm mode</title>
      <link>https://community.cisco.com/t5/application-networking/ace-lb-ssl-session-id-in-onearm-mode/m-p/1477551#M30554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The problem was caused by an incorrect nat pool.&amp;nbsp;&amp;nbsp; Correct Mask was 255.255.255.0.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Aug 2010 18:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-lb-ssl-session-id-in-onearm-mode/m-p/1477551#M30554</guid>
      <dc:creator>robertsj2609</dc:creator>
      <dc:date>2010-08-03T18:22:07Z</dc:date>
    </item>
  </channel>
</rss>

