<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Content Switch replacing Client IP in IIS Logs in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/content-switch-replacing-client-ip-in-iis-logs/m-p/1526787#M31389</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shahim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way you can get the original client IP to show up in the server logs is to not use the service GlobalInv in the group. If you remove this service from the group you will need to insure that the server replies back to the CSS. This can be done by changing the default gateway of the server, or using policy based routing (PBR) to force the server reply back to the CSS. You generally need to use client nat with the group command when using a one-armed config, or the servers are not local to the CSS. If you can share your topology I can take a look at it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Oct 2010 19:07:11 GMT</pubDate>
    <dc:creator>jsirstin</dc:creator>
    <dc:date>2010-10-27T19:07:11Z</dc:date>
    <item>
      <title>Content Switch replacing Client IP in IIS Logs</title>
      <link>https://community.cisco.com/t5/application-networking/content-switch-replacing-client-ip-in-iis-logs/m-p/1526786#M31388</link>
      <description>&lt;P&gt;Hello Guys,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I have been facing this problem ever since we configured our content switch infront of our web server. The IIS logs in the web server now show the content switch IP in the 'c-ip' column.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is configuration for the website:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;service GlobalInv &lt;BR /&gt;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp; ip address 172.21.21.31 &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;owner GlobalWebSite &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; content GlobalInv-http &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vip address 172.21.21.52 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; add service GlobalInv &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; advanced-balance sticky-srcip &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;group GlobalInv &lt;BR /&gt;&amp;nbsp; vip address 172.21.21.52 &lt;BR /&gt;&amp;nbsp; add destination service GlobalInv &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone please help me tellin as to how I can have the actual client IP addresses shown in my IIS logs instead of the content switch IP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please this is very important to us.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2010 05:51:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/content-switch-replacing-client-ip-in-iis-logs/m-p/1526786#M31388</guid>
      <dc:creator>etrade.admin</dc:creator>
      <dc:date>2010-10-27T05:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Content Switch replacing Client IP in IIS Logs</title>
      <link>https://community.cisco.com/t5/application-networking/content-switch-replacing-client-ip-in-iis-logs/m-p/1526787#M31389</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shahim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only way you can get the original client IP to show up in the server logs is to not use the service GlobalInv in the group. If you remove this service from the group you will need to insure that the server replies back to the CSS. This can be done by changing the default gateway of the server, or using policy based routing (PBR) to force the server reply back to the CSS. You generally need to use client nat with the group command when using a one-armed config, or the servers are not local to the CSS. If you can share your topology I can take a look at it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Oct 2010 19:07:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/content-switch-replacing-client-ip-in-iis-logs/m-p/1526787#M31389</guid>
      <dc:creator>jsirstin</dc:creator>
      <dc:date>2010-10-27T19:07:11Z</dc:date>
    </item>
    <item>
      <title>Re: Content Switch replacing Client IP in IIS Logs</title>
      <link>https://community.cisco.com/t5/application-networking/content-switch-replacing-client-ip-in-iis-logs/m-p/1526788#M31390</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Jim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am sorry but am not an export in CCS, it would be a great help to me if you can instruct me on how I can actually achieve this.&lt;/P&gt;&lt;P&gt;I have already set the default gateway of my web server to the Content switch.&lt;/P&gt;&lt;P&gt;My topology is quite simple, both the content switch &amp;amp; the web server are in the DMZ zone (same subnet) and are connected to the same switch. Users from outside &amp;amp; inside the company access our corporate website through the content switch&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below is the configuration of my content switch (with the related config marked in red):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;CSS-GLOBAL# sh runn&lt;BR /&gt;!Generated on 10/26/2010 23:14:04&lt;BR /&gt;!Active version: sg0810106&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;configure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;BR /&gt;!*************************** GLOBAL ***************************&lt;BR /&gt;&amp;nbsp; dns primary 172.21.1.13 &lt;BR /&gt;&amp;nbsp; dns secondary 192.168.0.50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; ssl associate rsakey eglobal eglobal.pem &lt;BR /&gt;&amp;nbsp; ssl associate cert eglobal-selfsigned eglobal.selfsigned.pem &lt;BR /&gt;&amp;nbsp; ssl associate rsakey glopedia glopedia.pem &lt;BR /&gt;&amp;nbsp; ssl associate cert glopedia glopedia.selfsigned.pem &lt;BR /&gt;&amp;nbsp; ssl associate cert eglobal-versign e-global-verisign.pem &lt;BR /&gt;&amp;nbsp; ssl associate cert glopedia-verisign glopedia-verisign.pem &lt;BR /&gt;&amp;nbsp; ssl associate cert EGlobal-Web EGlobal-Web.pem &lt;BR /&gt;&amp;nbsp; ssl associate cert EGlobal-Web-Chain EGlobal-Web.pem &lt;BR /&gt;&amp;nbsp; ssl associate cert Glopedia-Web-Chain Glopedia-Web.pem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; ftp-record conf 172.16.143.43 shahim des-password 1bnc2hnduhmgjend /&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; ip route 0.0.0.0 0.0.0.0 172.21.21.1 1 &lt;BR /&gt;&amp;nbsp; ip route 172.21.1.0 255.255.255.0 172.21.21.4 1 &lt;BR /&gt;&amp;nbsp; ip route 172.16.0.0 255.255.0.0 172.21.21.4 1 &lt;BR /&gt;&amp;nbsp; ip route 192.168.0.0 255.255.255.0 172.21.21.4 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;!************************* INTERFACE *************************&lt;BR /&gt;interface e1&lt;BR /&gt;&amp;nbsp; description "To Global Switch Foundary"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;!************************** CIRCUIT **************************&lt;BR /&gt;circuit VLAN1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; ip address 172.21.21.49 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;!*********************** SSL PROXY LIST ***********************&lt;BR /&gt;ssl-proxy-list SSL-Proxy-List &lt;BR /&gt;&amp;nbsp; ssl-server 51 &lt;BR /&gt;&amp;nbsp; ssl-server 51 rsakey eglobal &lt;BR /&gt;&amp;nbsp; ssl-server 51 vip address 172.21.21.51 &lt;BR /&gt;&amp;nbsp; ssl-server 51 cipher rsa-with-rc4-128-md5 172.21.21.51 80 weight 10 &lt;BR /&gt;&amp;nbsp; ssl-server 51 cipher rsa-with-rc4-128-sha 172.21.21.51 80 weight 8 &lt;BR /&gt;&amp;nbsp; ssl-server 51 cipher rsa-export-with-rc4-40-md5 172.21.21.51 80 weight 5 &lt;BR /&gt;&amp;nbsp; ssl-server 50 &lt;BR /&gt;&amp;nbsp; ssl-server 50 rsakey glopedia &lt;BR /&gt;&amp;nbsp; ssl-server 50 vip address 172.21.21.50 &lt;BR /&gt;&amp;nbsp; ssl-server 50 cipher rsa-with-rc4-128-md5 172.21.21.50 80 weight 10 &lt;BR /&gt;&amp;nbsp; ssl-server 50 cipher rsa-with-rc4-128-sha 172.21.21.50 80 weight 8 &lt;BR /&gt;&amp;nbsp; ssl-server 50 cipher rsa-export-with-rc4-40-md5 172.21.21.50 80 weight 5 &lt;BR /&gt;&amp;nbsp; ssl-server 50 urlrewrite 1 * &lt;BR /&gt;&amp;nbsp; ssl-server 51 urlrewrite 1 * &lt;BR /&gt;&amp;nbsp; ssl-server 51 rsacert EGlobal-Web-Chain &lt;BR /&gt;&amp;nbsp; ssl-server 50 rsacert Glopedia-Web-Chain &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;!************************** SERVICE **************************&lt;BR /&gt;service E-Global-https &lt;BR /&gt;&amp;nbsp; ip address 172.21.21.32 &lt;BR /&gt;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;service Ghalia &lt;BR /&gt;&amp;nbsp; port 81 &lt;BR /&gt;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp; ip address 172.21.21.31 &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;service GlobalInv &lt;BR /&gt;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp; ip address 172.21.21.31 &lt;BR /&gt;&amp;nbsp; active &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;service dms &lt;BR /&gt;&amp;nbsp; ip address 172.21.1.115 &lt;BR /&gt;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp; keepalive type http &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;service eglobal-http &lt;BR /&gt;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp; ip address 172.21.21.32 &lt;BR /&gt;&amp;nbsp; keepalive type http &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;service email &lt;BR /&gt;&amp;nbsp; ip address 172.21.1.122 &lt;BR /&gt;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp; keepalive type http &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;service email123 &lt;BR /&gt;&amp;nbsp; ip address 172.21.1.123 &lt;BR /&gt;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp; keepalive type http &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;service glopedia &lt;BR /&gt;&amp;nbsp; ip address 192.168.2.32 &lt;BR /&gt;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;service glopedia-expapps &lt;BR /&gt;&amp;nbsp; ip address 192.168.2.32 &lt;BR /&gt;&amp;nbsp; port 4028 &lt;BR /&gt;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;service secure-transfer &lt;BR /&gt;&amp;nbsp; type redirect &lt;BR /&gt;&amp;nbsp; no prepend-http &lt;BR /&gt;&amp;nbsp; ip address 172.21.21.32 &lt;BR /&gt;&amp;nbsp; keepalive type none &lt;BR /&gt;&lt;SPAN&gt;&amp;nbsp; domain &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.e-global.com.kw"&gt;https://www.e-global.com.kw&lt;/A&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;service ssl-eglobal &lt;BR /&gt;&amp;nbsp; type ssl-accel &lt;BR /&gt;&amp;nbsp; keepalive type none &lt;BR /&gt;&amp;nbsp; slot 2 &lt;BR /&gt;&amp;nbsp; add ssl-proxy-list SSL-Proxy-List &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;service workflow &lt;BR /&gt;&amp;nbsp; ip address 172.21.21.44 &lt;BR /&gt;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp; keepalive type http &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;!*************************** OWNER ***************************&lt;BR /&gt;owner EGlobal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; content eglobal-http &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vip address 172.21.21.51 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; no persistent &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; url "/*" &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; add service eglobal-http &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; content eglobal-https &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vip address 172.21.21.51 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 443 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; add service ssl-eglobal &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;owner GhaliaWebSite&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; content Ghalia-http &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vip address 172.21.21.53 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; add service Ghalia &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;owner GlobalWebSite &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;&amp;nbsp; content GlobalInv-http &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vip address 172.21.21.52 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; add service GlobalInv &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; advanced-balance sticky-srcip &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;owner Glopedia&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; content bpmweb &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vip address 172.21.21.50 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; url "/workflow" &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; redirect "/bpmweb" &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; content cyberdocs &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vip address 172.21.21.50 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; add service dms &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; url "/CyberDocs*" &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp; content dms &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vip address 172.21.21.50 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; url "/dms*" &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; redirect "/CyberDocs" &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; content email &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vip address 172.21.21.50 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; no persistent &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; url "/email" &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; redirect "/owa" &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; content glopedia-expapps &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vip address 172.21.21.50 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; add service glopedia-expapps &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; no persistent &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 4028 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; content glopedia-http &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vip address 172.21.21.50 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; add service glopedia &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; no persistent &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; url "/*" &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; content glopedia-https &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vip address 172.21.21.50 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; add service ssl-eglobal &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 443 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; content owa &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vip address 172.21.21.50 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; add service email123 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; url "/owa*" &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&amp;nbsp; content workflow &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; vip address 172.21.21.50 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; add service workflow &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; no persistent &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; protocol tcp &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; port 80 &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; url "/bpmweb*" &lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;!*************************** GROUP ***************************&lt;BR /&gt;group Ghalia &lt;BR /&gt;&amp;nbsp; vip address 172.21.21.53 &lt;BR /&gt;&amp;nbsp; add destination service Ghalia &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;group GlobalInv &lt;BR /&gt;&amp;nbsp; vip address 172.21.21.52 &lt;BR /&gt;&amp;nbsp; add destination service GlobalInv &lt;BR /&gt;&amp;nbsp; active &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;group dms &lt;BR /&gt;&amp;nbsp; vip address 172.21.21.50 &lt;BR /&gt;&amp;nbsp; add destination service dms &lt;BR /&gt;&amp;nbsp; add destination service email &lt;BR /&gt;&amp;nbsp; add destination service workflow &lt;BR /&gt;&amp;nbsp; add destination service glopedia &lt;BR /&gt;&amp;nbsp; add destination service email123 &lt;BR /&gt;&amp;nbsp; add destination service glopedia-expapps &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;group eglobal &lt;BR /&gt;&amp;nbsp; vip address 172.21.21.51 &lt;BR /&gt;&amp;nbsp; add destination service eglobal-http &lt;BR /&gt;&amp;nbsp; active&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Oct 2010 05:56:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/content-switch-replacing-client-ip-in-iis-logs/m-p/1526788#M31390</guid>
      <dc:creator>etrade.admin</dc:creator>
      <dc:date>2010-10-28T05:56:47Z</dc:date>
    </item>
    <item>
      <title>Re: Content Switch replacing Client IP in IIS Logs</title>
      <link>https://community.cisco.com/t5/application-networking/content-switch-replacing-client-ip-in-iis-logs/m-p/1526789#M31391</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shahim,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You have two options here.&lt;/P&gt;&lt;P&gt;One is to have the server use the CSS as the default gateway and remove the service from the group command.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;&lt;STRONG&gt;group GlobalInv &lt;BR /&gt;&amp;nbsp; vip address 172.21.21.52 &lt;BR /&gt;&amp;nbsp; add destination service GlobalInv&amp;nbsp;&amp;nbsp; Remove this service from the group.&lt;BR /&gt;&amp;nbsp; active &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is fine for load balancing but any traffic sourced from or destined to the server direct will only have half the conversation passing through the CSS. You may see the CSS flag this traffic as possible DOS attacks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The second option is to move to a bridge design. in this case you create a second layer 2 vlan on the switch and plug a second interface on the CSS to this new vlan. From the CSS perspective both interfaces are part of vlan 1 and will bridge the two vlans on the switch. Any servers that need to see the original client IP address for load balancing would be placed in this new vlan. The IP and gateway of the servers do not need to be changed. Servers would still point to the switch not the CSS as the default gateway. There is no need for client nat in this topology since the servers are behind the CSS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; switch&lt;/P&gt;&lt;P&gt;Vlan 1&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan2----- servcie Globallnv&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&lt;/P&gt;&lt;P&gt;&amp;nbsp; E1-----CSS---E2 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you need more clarification?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Jim&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Oct 2010 14:55:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/content-switch-replacing-client-ip-in-iis-logs/m-p/1526789#M31391</guid>
      <dc:creator>jsirstin</dc:creator>
      <dc:date>2010-10-28T14:55:38Z</dc:date>
    </item>
  </channel>
</rss>

