<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACE 4710 Connectivity help? in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-4710-connectivity-help/m-p/1641614#M33205</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Brent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Couple of things I was able to see from the config you posted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- Telnet/SSH is not available on VLAN 400 SVI because there's no class-map type management configured on context VC_WBPX,&lt;/P&gt;&lt;P&gt;if you want to access remotely the context just mirror the same mgmt class is configured on the Admin context and apply it under vlan 400.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2- You mentioned that you want requests from clients on vlan 400 to be NAT'd using an IP address of vlan 500 however the 2 policies configured&lt;/P&gt;&lt;P&gt;to do NAT are applied under VLAN 500 so only traffic initiated from that VLAN will be NAT'd.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need multi-match policy "SNAT_POLICY" applied on VLAN 500.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;__ __&lt;/P&gt;&lt;P&gt;Pablo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 04 Apr 2011 18:45:26 GMT</pubDate>
    <dc:creator>pablo.nxh</dc:creator>
    <dc:date>2011-04-04T18:45:26Z</dc:date>
    <item>
      <title>ACE 4710 Connectivity help?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-connectivity-help/m-p/1641611#M33202</link>
      <description>&lt;P&gt;I'm using an ACE 4710 in a new datacenter, with the following setup:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2/4 physical ethernet interfaces port channeled into port-channel 1&lt;/P&gt;&lt;P&gt;2/4 physical ethernet interfaces port channeled into port-channel 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the following vlans defined:&lt;/P&gt;&lt;P&gt;1001 - admin&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - interface ip: 10.53.136.70&lt;/P&gt;&lt;P&gt;400 - client side - interface ip: 10.53.136.100&lt;/P&gt;&lt;P&gt;500 - server side - interface ip: 192.168.128.1&lt;/P&gt;&lt;P&gt;999 - fault tolerance - interface ip: 192.168.11.2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My problem is I am trying to nat ssh and web server traffic from the client side, to the server side, but it's never getting to the server.&amp;nbsp; For example, if I ssh to 10.53.136.102, it times out.&amp;nbsp; (10.53.136.102 should get nat'd to 192.168.128.2) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, I can connect to the ACE 4710 via telnet using 10.53.136.70, but cannot connect to 10.53.136.100. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm thinking there is either something wrong with the port-channels, or the access lists.&amp;nbsp; On the other hand there could be something wrong with the nat'ing, but I had it working before switching over to the port-channels.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brent&lt;/P&gt;</description>
      <pubDate>Fri, 01 Apr 2011 01:37:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-connectivity-help/m-p/1641611#M33202</guid>
      <dc:creator>bwreed001</dc:creator>
      <dc:date>2011-04-01T01:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4710 Connectivity help?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-connectivity-help/m-p/1641612#M33203</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Brent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would be better if you can post a sanitized copy of your admin context and other context (if any) so we can have a bigger of picture&lt;/P&gt;&lt;P&gt;of what you're dealing with.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The fact that you can't telnet to 10.53.136.100 may be related to the mgmt policy missing under VLAN 400 or ACL config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You said that NAT and LB was working before moving to Port-Channel config; have you checked if the ACE updated correctly all the ARP entries&lt;/P&gt;&lt;P&gt;after this change? Can you ping the rservers in question?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is HA designed on active/passive scenario? If so have you checked if each box took the correct role after the interface re-configuration?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;__ __&lt;/P&gt;&lt;P&gt;Pablo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Apr 2011 04:18:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-connectivity-help/m-p/1641612#M33203</guid>
      <dc:creator>pablo.nxh</dc:creator>
      <dc:date>2011-04-01T04:18:56Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4710 Connectivity help?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-connectivity-help/m-p/1641613#M33204</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've attached the two contexts which we are using.&amp;nbsp; The admin context is new_lb_config.txt and the second context where the loadbalancing occurs is in the new_lb_config_VC_WBPX.txt file.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the load balancer, I am able to ping the real server ips in the 192.168. ip range.&amp;nbsp; The 4710 recognizes that they are in service. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe the ACL for the VLAN 400 is set to permit all traffic, but I don't know if the service policies are preventing something from happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Right now, I have disconnected the two 4710s and I am only working on one of them to see if I can get the basic connectivity going.&amp;nbsp; Once I accomplish that, I will work on high availability.&amp;nbsp; I'll have to check whether it thinks it is in passive mode...not entirely sure how to do that, but I will check it out.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Brent&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 01 Apr 2011 13:34:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-connectivity-help/m-p/1641613#M33204</guid>
      <dc:creator>bwreed001</dc:creator>
      <dc:date>2011-04-01T13:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4710 Connectivity help?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-connectivity-help/m-p/1641614#M33205</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Brent,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Couple of things I was able to see from the config you posted.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- Telnet/SSH is not available on VLAN 400 SVI because there's no class-map type management configured on context VC_WBPX,&lt;/P&gt;&lt;P&gt;if you want to access remotely the context just mirror the same mgmt class is configured on the Admin context and apply it under vlan 400.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2- You mentioned that you want requests from clients on vlan 400 to be NAT'd using an IP address of vlan 500 however the 2 policies configured&lt;/P&gt;&lt;P&gt;to do NAT are applied under VLAN 500 so only traffic initiated from that VLAN will be NAT'd.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need multi-match policy "SNAT_POLICY" applied on VLAN 500.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;__ __&lt;/P&gt;&lt;P&gt;Pablo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Apr 2011 18:45:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-connectivity-help/m-p/1641614#M33205</guid>
      <dc:creator>pablo.nxh</dc:creator>
      <dc:date>2011-04-04T18:45:26Z</dc:date>
    </item>
  </channel>
</rss>

