<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Basic config help in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/basic-config-help/m-p/230746#M3233</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using the "destination service" command in your group will NAT the traffic without an ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An ACL would likely work as well though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 30 Jan 2004 19:42:12 GMT</pubDate>
    <dc:creator>d.parks</dc:creator>
    <dc:date>2004-01-30T19:42:12Z</dc:date>
    <item>
      <title>Basic config help</title>
      <link>https://community.cisco.com/t5/application-networking/basic-config-help/m-p/230743#M3230</link>
      <description>&lt;P&gt;I am having problems getting my 11501 to work with my 2000 Terminal servers. I have been through the basic config and see that the hits under content services statistics but client come back with a "The client could not connect to the Terminal server" error message. Clients can connect if pointed at the actual servers IP not the VIP ip. I am new to this product.&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;CSS 11501&lt;/P&gt;&lt;P&gt;OS = 7.20.206&lt;/P&gt;&lt;P&gt;Win2k Terminal servers SP4&lt;/P&gt;&lt;P&gt;RDP and Terminal server clients (Ver 5 build 2195)&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;running config as follows:&lt;/P&gt;&lt;P&gt;configure&lt;/P&gt;&lt;P&gt;!*************************** GLOBAL ***************************&lt;/P&gt;&lt;P&gt;  no restrict web-mgmt&lt;/P&gt;&lt;P&gt;  ftp-record Primary-Boot 192.168.100.114 css des-password xxxx&lt;/P&gt;&lt;P&gt;  ftp-record Secondary-Boot 10.1.1.1 anonymous des-password xxxxx&lt;/P&gt;&lt;P&gt;  ftp-record DEFAULT_FTP 192.168.100.114 css des-password xxxx&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;!************************** CIRCUIT **************************&lt;/P&gt;&lt;P&gt;circuit VLAN1&lt;/P&gt;&lt;P&gt;  ip address 172.16.10.10 255.255.254.0&lt;/P&gt;&lt;P&gt;!************************** SERVICE **************************&lt;/P&gt;&lt;P&gt;service CF01T01&lt;/P&gt;&lt;P&gt;  protocol tcp&lt;/P&gt;&lt;P&gt;  port 3389&lt;/P&gt;&lt;P&gt;  ip address 172.16.10.76&lt;/P&gt;&lt;P&gt;service CF01T02&lt;/P&gt;&lt;P&gt;  ip address 172.16.10.77&lt;/P&gt;&lt;P&gt;  protocol tcp&lt;/P&gt;&lt;P&gt;  port 3389&lt;/P&gt;&lt;P&gt;  max connections 25&lt;/P&gt;&lt;P&gt;  active&lt;/P&gt;&lt;P&gt;service CF01T03&lt;/P&gt;&lt;P&gt;  ip address 172.16.10.78&lt;/P&gt;&lt;P&gt;  protocol tcp&lt;/P&gt;&lt;P&gt;  port 3389&lt;/P&gt;&lt;P&gt;  max connections 25&lt;/P&gt;&lt;P&gt;  active&lt;/P&gt;&lt;P&gt;!*************************** OWNER ***************************&lt;/P&gt;&lt;P&gt;owner CF_Terminal_Servers&lt;/P&gt;&lt;P&gt;  content CF_Terminal_Servers&lt;/P&gt;&lt;P&gt;    add service CF01T01&lt;/P&gt;&lt;P&gt;    add service CF01T02&lt;/P&gt;&lt;P&gt;    vip address 172.16.10.75&lt;/P&gt;&lt;P&gt;    protocol tcp&lt;/P&gt;&lt;P&gt;    port 3389&lt;/P&gt;&lt;P&gt;    add service CF01T03&lt;/P&gt;&lt;P&gt;    active&lt;/P&gt;&lt;P&gt;!*************************** GROUP ***************************&lt;/P&gt;&lt;P&gt;group TerminalServers&lt;/P&gt;&lt;P&gt;  add service CF01T02&lt;/P&gt;&lt;P&gt;  add service CF01T03&lt;/P&gt;&lt;P&gt;  vip address 172.16.10.75&lt;/P&gt;&lt;P&gt;  add service CF01T01&lt;/P&gt;&lt;P&gt;  active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Jan 2004 15:47:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/basic-config-help/m-p/230743#M3230</guid>
      <dc:creator>jaimemurphy</dc:creator>
      <dc:date>2004-01-30T15:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: Basic config help</title>
      <link>https://community.cisco.com/t5/application-networking/basic-config-help/m-p/230744#M3231</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Depending on your network layout, you may need to change your group configuration.  Try "add destination service" instead of "add service"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jan 2004 17:02:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/basic-config-help/m-p/230744#M3231</guid>
      <dc:creator>d.parks</dc:creator>
      <dc:date>2004-01-30T17:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: Basic config help</title>
      <link>https://community.cisco.com/t5/application-networking/basic-config-help/m-p/230745#M3232</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jaime,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can not be positive, but it looks likely that the servers are not behind the CSS, but in front (sharing an interface with the default gateway).  If this is the case, moving them behind the CSS should get it working.  If this is not possible, you will need access lists to activate the group, since the NAT will have to be more complex.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that is the case, let me know and I will formulate an ACL that should get you moving in the right direction.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jan 2004 17:58:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/basic-config-help/m-p/230745#M3232</guid>
      <dc:creator>stevehall</dc:creator>
      <dc:date>2004-01-30T17:58:13Z</dc:date>
    </item>
    <item>
      <title>Re: Basic config help</title>
      <link>https://community.cisco.com/t5/application-networking/basic-config-help/m-p/230746#M3233</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using the "destination service" command in your group will NAT the traffic without an ACL.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An ACL would likely work as well though.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jan 2004 19:42:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/basic-config-help/m-p/230746#M3233</guid>
      <dc:creator>d.parks</dc:creator>
      <dc:date>2004-01-30T19:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Basic config help</title>
      <link>https://community.cisco.com/t5/application-networking/basic-config-help/m-p/230747#M3234</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The only issue I see with using destination service in the group is you are already using the group with the "add service" option.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can't add a service to a group twice, which included "add service" and "add destination service" for the same service.  That is the reason ACLs will be required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jan 2004 21:10:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/basic-config-help/m-p/230747#M3234</guid>
      <dc:creator>stevehall</dc:creator>
      <dc:date>2004-01-30T21:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Basic config help</title>
      <link>https://community.cisco.com/t5/application-networking/basic-config-help/m-p/230748#M3235</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good point, though I suspect the original group configuration may not be needed.  I'm assuming that the servers' non-loadbalanced traffic does not pass through the CSS due to how the routing is setup.  From what I've seen, this type of group configuration is generally only needed when the servers go through the CSS to get to another address space, usually the internet, and their addresses are not valid in that space.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;One question for you regarding the ACL based NAT configuration since I'm not familiar with it...  Do you have to take an outage to reconfigure the NAT when adding servers to your pool?  My only gripe with the "source group" method is that I've got to suspend my groups to add or remove services.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Jan 2004 22:39:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/basic-config-help/m-p/230748#M3235</guid>
      <dc:creator>d.parks</dc:creator>
      <dc:date>2004-01-30T22:39:03Z</dc:date>
    </item>
    <item>
      <title>Re: Basic config help</title>
      <link>https://community.cisco.com/t5/application-networking/basic-config-help/m-p/230749#M3236</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have a "one-armed configuration" as well and successfully use a simple source group with "add destination service" to ensure traffic is returned through the CSS.&lt;/P&gt;&lt;P&gt;However, I also have the gripe about having to suspend the group (and disrupt existing flows) in order to add a new service.&lt;/P&gt;&lt;P&gt;I would be interested to know if there is a logical reason or should we raise an enhancement request.&lt;/P&gt;&lt;P&gt;The only other ways to avoid down time that I have found is to create a group per service, or configure spare services to insert in the group, to be configured with detail at a later date.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Incidentally how does HSE handle this sort of configuration. We are considering deploying HSE but not if we have to do a lot of fiddling around!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 04 Feb 2004 13:13:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/basic-config-help/m-p/230749#M3236</guid>
      <dc:creator>andrew.thomson</dc:creator>
      <dc:date>2004-02-04T13:13:45Z</dc:date>
    </item>
  </channel>
</rss>

