<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I load balance TFTP between two servers and a client  in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674977#M33749</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried using the same IP (10.0.0.10) for NATing the response back from your TFTP server? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regardless of the one-armed mode you still need the dummy (all zero) virtual to match the UDP random port sent from your servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you haven't tried with that kind of NAT let me know and I'll drop you a config sample &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tnx&lt;/P&gt;&lt;P&gt;__ __&lt;/P&gt;&lt;P&gt;Pablo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 19 Apr 2011 03:40:17 GMT</pubDate>
    <dc:creator>pablo.nxh</dc:creator>
    <dc:date>2011-04-19T03:40:17Z</dc:date>
    <item>
      <title>How do I load balance TFTP between two servers and a client on the same subnet?</title>
      <link>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674976#M33748</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have trawled through several documents and tried umpteen different configs, all to no avail. I have a PXE boot client trying to access a boot file via TFTP from a couple of TFTP servers on the same VLAN/subnet. For HA purposes I want to load balance the two TFTP servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config is currently;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;=====&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;probe icmp ICMP_PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp; description icmp probe for default gateway tracking&lt;/P&gt;&lt;P&gt;&amp;nbsp; interval 5&lt;/P&gt;&lt;P&gt;&amp;nbsp; passdetect interval 15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host server1&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Server1&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host server2&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Server 2&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.2&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host serverfarm_01&lt;/P&gt;&lt;P&gt;&amp;nbsp; description servers used&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe ICMP_PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver server1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver server2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all L4_VIP_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; 10 match virtual-address 10.0.0.10 udp eq 69&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match L7_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm serverfarm_01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match L4_LB_VIP_POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; class L4_VIP_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy L7_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt; &lt;/SPAN&gt;nat dynamic 1 vlan 200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 200&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.250 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 1 10.0.0.241 10.0.0.243 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input L4_LB_VIP_POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.0.0.254&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;=====&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;I have read the doco by Ivan Kovacevic amongst many others but as my clients and servers are on the same subnet, the config doesnt work.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Can anybody point me in the right direction please. The devices are ACE 4710 running A3(2.3).&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Thanks&lt;/DIV&gt;</description>
      <pubDate>Tue, 19 Apr 2011 03:19:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674976#M33748</guid>
      <dc:creator>pjwhitby_2</dc:creator>
      <dc:date>2011-04-19T03:19:15Z</dc:date>
    </item>
    <item>
      <title>Re: How do I load balance TFTP between two servers and a client</title>
      <link>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674977#M33749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello there,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Have you tried using the same IP (10.0.0.10) for NATing the response back from your TFTP server? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regardless of the one-armed mode you still need the dummy (all zero) virtual to match the UDP random port sent from your servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you haven't tried with that kind of NAT let me know and I'll drop you a config sample &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tnx&lt;/P&gt;&lt;P&gt;__ __&lt;/P&gt;&lt;P&gt;Pablo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Apr 2011 03:40:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674977#M33749</guid>
      <dc:creator>pablo.nxh</dc:creator>
      <dc:date>2011-04-19T03:40:17Z</dc:date>
    </item>
    <item>
      <title>Re: How do I load balance TFTP between two servers and a client</title>
      <link>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674978#M33750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Pablo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I knew it would something on the NAT as I can see the connections in 'show connection'. If you have a sample config for this example that would be awesome.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks alot,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Apr 2011 05:50:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674978#M33750</guid>
      <dc:creator>pjwhitby_2</dc:creator>
      <dc:date>2011-04-19T05:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: How do I load balance TFTP between two servers and a client</title>
      <link>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674979#M33751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try simply changing the nat-pool or create a new one but using the same IP as the VIP. (The decision depends whether you have other protocols&lt;/P&gt;&lt;P&gt;being balanced besides TFTP),&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; class L4_VIP_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy L7_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;nat dynamic &lt;SPAN style="color: #ff0000;"&gt;2 &lt;/SPAN&gt;vlan 200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 200&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.250 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 1 10.0.0.241 10.0.0.243 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool &lt;SPAN style="color: #ff0000;"&gt;2 &lt;/SPAN&gt;10.0.0.10 10.0.0.10 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input L4_LB_VIP_POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;HTH&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;__ __&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="min-height: 8pt; height: 8pt; padding: 0px;"&gt;Pablo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Apr 2011 18:22:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674979#M33751</guid>
      <dc:creator>pablo.nxh</dc:creator>
      <dc:date>2011-04-25T18:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: How do I load balance TFTP between two servers and a client</title>
      <link>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674980#M33752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi pablo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the config, but it didnt work, here is my current config,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;=====&lt;/P&gt;&lt;P&gt;probe icmp ICMP_PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp; description icmp probe for default gateway tracking&lt;/P&gt;&lt;P&gt;&amp;nbsp; interval 5&lt;/P&gt;&lt;P&gt;&amp;nbsp; passdetect interval 15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host server1&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Server1&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host server2&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Server 2&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.2&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host serverfarm_01&lt;/P&gt;&lt;P&gt;&amp;nbsp; description servers used&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe ICMP_PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver server1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver server2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all L4_VIP_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; 10 match virtual-address 10.0.0.10 udp eq 69&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match L7_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm serverfarm_01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match L4_LB_VIP_POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; class L4_VIP_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy L7_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 2 vlan 200&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 200&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.250 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN&gt;nat-pool 1 10.0.0.241 10.0.0.243 netmask 255.255.255.255 pat&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 2 10.0.0.10 10.0.0.10 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input L4_LB_VIP_POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.0.0.254&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;=====&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;I have the following in the 'show conn&amp;nbsp; detail' output&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;conn-id&amp;nbsp;&amp;nbsp;&amp;nbsp; np dir proto vlan source&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state&lt;/DIV&gt;&lt;DIV&gt;----------+--+---+-----+----+---------------------+---------------------+------+&lt;/DIV&gt;&lt;DIV&gt;43455&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; in&amp;nbsp; UDP&amp;nbsp;&amp;nbsp; 212&amp;nbsp; 10.0.0.200:52007&amp;nbsp;&amp;nbsp; 10.0.0.10:69&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -- &lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ idle time&amp;nbsp;&amp;nbsp; : 00:00:02,&amp;nbsp;&amp;nbsp; byte count&amp;nbsp; : 79&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ]&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ elapsed time: 00:00:02,&amp;nbsp;&amp;nbsp; packet count: 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ]&lt;/DIV&gt;&lt;DIV&gt;1847713&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; out UDP&amp;nbsp;&amp;nbsp; 212&amp;nbsp; 10.0.0.2:69&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.0.0.10:52007&amp;nbsp;&amp;nbsp;&amp;nbsp; -- &lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ conn in reuse pool : FALSE]&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ idle time&amp;nbsp;&amp;nbsp; : 00:00:02,&amp;nbsp;&amp;nbsp; byte count&amp;nbsp; : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ]&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; [ elapsed time: 00:00:02,&amp;nbsp;&amp;nbsp; packet count: 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ]&lt;/DIV&gt;&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;and then the connection times out after approx 3 minutes with no increase in the latter connections byte or packet count.&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;I am guesssing the packet or request contains the clients real IP address and the server is trying to talk directly to the client rather than the LB VIP?&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Can anyone suggest the next step, I am running out of ideas?&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt;Thanks&lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Apr 2011 01:53:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674980#M33752</guid>
      <dc:creator>pjwhitby_2</dc:creator>
      <dc:date>2011-04-27T01:53:58Z</dc:date>
    </item>
    <item>
      <title>Re: How do I load balance TFTP between two servers and a client</title>
      <link>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674981#M33753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Oh I thought the dummy virtual was already in place, please configure the highlighted portion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;SPAN style="color: #ff6600;"&gt;class-map match-any TFTP&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;&amp;nbsp;&amp;nbsp; match virtual-address 0.0.0.0 0.0.0.0 udp eq any&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;P&gt;policy-map multi-match L4_LB_VIP_POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; class L4_VIP_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy L7_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 2 vlan 200&lt;/P&gt;&lt;PRE&gt;&lt;SPAN style="color: #ff6600;"&gt;&amp;nbsp; class TFTP&lt;BR /&gt;&amp;nbsp;&amp;nbsp; &lt;SPAN style="color: #ff0000;"&gt;nat dynamic 2 vlan 20&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="color: #ff0000;"&gt;0&lt;SPAN style="text-decoration: line-through;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;BR /&gt;* I don't see the ACL permitting traffic into VLAN 200, did you remove it from the example? &lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;__ __ &lt;BR /&gt;Pablo &lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="color: #ff6600;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Apr 2011 15:48:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674981#M33753</guid>
      <dc:creator>pablo.nxh</dc:creator>
      <dc:date>2011-04-27T15:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: How do I load balance TFTP between two servers and a client</title>
      <link>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674982#M33754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi pablo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for sticking with this one its really appreciated, but it still isnt working. I did have the ip any any for access into the vlan, heres is the current config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Theres is now a second VIP 10.0.0.201 as I am running through this case with Cisco TAC and I wanted to keep both yourself on this thread and the Cisco TAC engineer active, if I get an answer from either method I will let everybody know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and sorry, the VLAN is VLAN212 not VLAN200.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;====&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ALL line 10 extended permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;probe icmp ICMP_PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp; interval 5&lt;/P&gt;&lt;P&gt;&amp;nbsp; passdetect interval 15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host server1&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Server1&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host server2&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Server2&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.2&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host serverfarm_01&lt;/P&gt;&lt;P&gt;&amp;nbsp; description servers used&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe ICMP_PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver server1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver server2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all L4_VIP_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; 10 match virtual-address 10.0.0.10 udp eq 69&lt;/P&gt;&lt;P&gt;class-map match-all L4_VIP_TFTP2&lt;/P&gt;&lt;P&gt;&amp;nbsp; 10 match virtual-address 10.0.0.201 any&lt;/P&gt;&lt;P&gt;class-map match-any TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; 10 match virtual-address 0.0.0.0 0.0.0.0 udp any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match L7_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm serverfarm_01&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match L7_TFTP2&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm serverfarm_01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match L4_LB_VIP_POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; class L4_VIP_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy L7_TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 2 vlan 212&lt;/P&gt;&lt;P&gt;&amp;nbsp; class L4_VIP_TFTP2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy L7_TFTP2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 3 vlan 212&lt;/P&gt;&lt;P&gt;&amp;nbsp; class TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 2 vlan 212&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 212&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.250 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input ALL&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 1 10.0.0.241 10.0.0.243 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 2 10.0.0.10 10.0.0.10 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 3 10.0.0.201 10.0.0.201 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input L4_LB_VIP_POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.0.0.254&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;====&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please feel free to ask any questions, I am on BNE time.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;DIV&gt; &lt;/DIV&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Apr 2011 23:55:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674982#M33754</guid>
      <dc:creator>pjwhitby_2</dc:creator>
      <dc:date>2011-04-27T23:55:31Z</dc:date>
    </item>
    <item>
      <title>Re: How do I load balance TFTP between two servers and a client</title>
      <link>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674983#M33755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi pablo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any thoughts or configs I can try please.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If anybody else has any ideas, please feel free to jump in, just to remind everybody.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have two TFTP servers that will be issuing a boot file (ardbp32.bin) to PXE booting clients. The two TFTP servers reside within the same VLAN as the PXE booting clients and in order to supply a degree of HA, I want to place the two TFTP servers (.1 and .2) behind a VIP on a ACE4710 (.10). When we distribute the TFTP server address via DHCP (option 66) I want to send the VIP address (.10) and allow the ACE4710 to load balance the TFTP conversation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks to all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 May 2011 00:55:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674983#M33755</guid>
      <dc:creator>pjwhitby_2</dc:creator>
      <dc:date>2011-05-03T00:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: How do I load balance TFTP between two servers and a client</title>
      <link>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674984#M33756</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try using the following configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: Please make sure to configure also a udp probe to probe udp port 69, in case the application is down.&lt;/P&gt;&lt;P&gt;You need to configure a management policy on the interface when using a UDP probe.&lt;/P&gt;&lt;P&gt;That is because, when port 69 on the server will be unreachable, the server will send an ICMP unreachable.&lt;/P&gt;&lt;P&gt;ACE will consider a udp probe as "failed" only when it sees ICMP unreachable.&lt;/P&gt;&lt;P&gt;Without a management policy-map, the ICMP unreachable message will be dropped.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, add an ICMP probe to the rserver because udp probe will not be enough when the physical interface will be down.&lt;/P&gt;&lt;P&gt;That is because UDP is a connection-less protocol. To consider a UDP probe successfull, ACE need to see NO answer from the server in respose to the probe.&lt;/P&gt;&lt;P&gt;The ACE will not see any answer from the server when the interface is down and thus, will consider the probe as "sucessful".&lt;/P&gt;&lt;P&gt;With ICMP probe attached to the rserver, you also test the reachability of the server and not only the UDP port.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the configuration (of course, you can chage the names of the of the objects to the name you are using if you want) :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ALL line 10 extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;probe udp TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; port 69&lt;/P&gt;&lt;P&gt;&amp;nbsp; interval 5&lt;/P&gt;&lt;P&gt;&amp;nbsp; passdetect interval 15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;probe icmp ICMP_PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp; interval 5&lt;/P&gt;&lt;P&gt;&amp;nbsp; passdetect interval 15&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host TFTP_1&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe ICMP_PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host TFTP_2&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.2&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe ICMP_PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host TFTP-SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver TFTP_1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver TFTP_2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky ip-netmask 255.255.255.255 address source TFTP-STICKY&lt;/P&gt;&lt;P&gt;&amp;nbsp; timeout 10&lt;/P&gt;&lt;P&gt;&amp;nbsp; replicate sticky&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm TFTP-SFARM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type management match-any MANAGE&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match protocol icmp any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all NAT&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 0.0.0.0 0.0.0.0 udp any&lt;/P&gt;&lt;P&gt;class-map match-all TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 10.0.0.10 udp eq 69&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type management first-match MANAGE&lt;/P&gt;&lt;P&gt;&amp;nbsp; class MANAGE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match ROUTE&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; forward&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match TFTP-POL&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm TFTP-STICKY&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match TFTP-MULTI&lt;/P&gt;&lt;P&gt;&amp;nbsp; class TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy TFTP-POL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 212&lt;/P&gt;&lt;P&gt;&amp;nbsp; class NAT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy ROUTE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 2 vlan 212&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 212&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.250 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; no normalization&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input ALL&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 1 10.0.0.241 10.0.0.243 netmask 255.255.255.0 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 2 10.0.0.10 10.0.0.10 netmask 255.255.255.0 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input TFTP-MULTI&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input MANAGE&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 May 2011 18:26:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674984#M33756</guid>
      <dc:creator>udid</dc:creator>
      <dc:date>2011-05-07T18:26:09Z</dc:date>
    </item>
    <item>
      <title>Re: How do I load balance TFTP between two servers and a client</title>
      <link>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674985#M33757</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm back from leave so I can now reply,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your response Ehud but that didnt work either.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have another test config from TAC that I am going to try and I will then re-visit your solution and try again but I wanted to re-post this (bump it) to see if anybody out these has successfully used a Cisco ACE to load balance TFTP?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Jun 2011 03:57:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674985#M33757</guid>
      <dc:creator>pjwhitby_2</dc:creator>
      <dc:date>2011-06-06T03:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: How do I load balance TFTP between two servers and a client</title>
      <link>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674986#M33758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;sorry, I still don't have a solution but I wasn't able to work on the issue last week.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;anybody any thoughts?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Jul 2011 07:29:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674986#M33758</guid>
      <dc:creator>pjwhitby_2</dc:creator>
      <dc:date>2011-07-05T07:29:07Z</dc:date>
    </item>
    <item>
      <title>How do I load balance TFTP between two servers and a client on t</title>
      <link>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674987#M33759</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi pjwhitby,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm having the same problem here.. So, I get the solution?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 15:00:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674987#M33759</guid>
      <dc:creator>tonesco01</dc:creator>
      <dc:date>2012-04-17T15:00:36Z</dc:date>
    </item>
    <item>
      <title>How do I load balance TFTP between two servers and a client on t</title>
      <link>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674988#M33760</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hey Wallace,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sorry, we never got this running and we worked in a work around, although I cannot remember what it was, I think we went with a round robin DNS solution, but I would have to check.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Apr 2012 23:38:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674988#M33760</guid>
      <dc:creator>pjwhitby_2</dc:creator>
      <dc:date>2012-04-17T23:38:31Z</dc:date>
    </item>
    <item>
      <title>How do I load balance TFTP between two servers and a client on t</title>
      <link>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674989#M33761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; All-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; You can not loadbalance TFTP one-armed (servers and clients on the same vlan).&amp;nbsp; Here is why-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; The way tftp works, the client sends a UDP packet with a random source port destine to the server on port 69.&amp;nbsp; The server responds with source port 69, however, instead of using the client port as a destination like most protocols, TFTP generates a random port number to send data traffic back to the client.&lt;/P&gt;&lt;P&gt;&amp;nbsp; ACE tracks connections via MAC addresses, IP's and port numbers, and ingress/egress interfaces on a connection.&amp;nbsp; When we send the packet out of the interface to the server, we are expecting a response back from to the clients port.&amp;nbsp; To ACE, the port randomization the server is doing looks like a brand new UDP connection coming from the server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; As relates to loadbalancing TFTP - The client is talking to the VIP IP and expects to recieve a response from that IP.&amp;nbsp; The server is talking to the client IP and is communicating with ACE.&amp;nbsp; ACE has to catch the server's traffic destine to the client and modify the source IP from the server back to the VIP.&amp;nbsp; When the server replies to the client connection with a new port, you can catch it with a class map that matches UDP source port 69 and source-nat the packet to the VIP IP.&amp;nbsp;&amp;nbsp; That is what was being done above via this configuration:&lt;/P&gt;&lt;P&gt;class-map match-any TFTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; 10 match virtual-address 0.0.0.0 0.0.0.0 udp any&lt;/P&gt;&lt;P&gt;class NAT &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 2 vlan 212&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However - with one-armed configurations, the gateway on the server is not ACE.&amp;nbsp; That means, the client sends a packet to the VIP, the ACE forwards it to the server IP, the server sends its response back to the client.&amp;nbsp; At that point, the client is confused because it was talking to the VIP IP, but recieved a response from the Server IP.&amp;nbsp; To mitigate that, you need to configure source NAT on the connection going from ACE to the server.&amp;nbsp; That exact part is what makes it impossible to loadbalance TFTP one-armed.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Think about this:&lt;/P&gt;&lt;P&gt;When you configure source nat, many clients use one single IP.&amp;nbsp; Source ports are changed to track which client belongs to which connection on the backend. (since all clients are going to use the same single IP between the ace and the server, how else are you going to track the connection?)&lt;/P&gt;&lt;P&gt;So, when the server is going to reply to the NAT pool IP and the destination port is going to be random - How exactly would the ACE know what client in the NAT table is supposed to recieve that packet?&amp;nbsp; It can't.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only possible way to get this to work is configure policy based routing on the gateway to force any source port 69 traffic from the server back to the ACE so that ace can Un-Nat the traffic with a standard tftp loadbalancing configuration.&amp;nbsp; In that manner, you are replacing the function of source nat by routing.&amp;nbsp; You just need to ensure that the packet goes into the interface that ACE egressed the first udp packet to the server on.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that this is complicated to understand by reading, if you would like a set of wireshark traces to suppliment this, email me: &lt;A href="mailto:chrhiggi@cisco.com"&gt;chrhiggi@cisco.com&lt;/A&gt;.&amp;nbsp; I have both a standard TFTP connection as well as a single trace showing both sides of TFTP being loadbalanced.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt; Chris Higgins&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Apr 2012 20:28:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/how-do-i-load-balance-tftp-between-two-servers-and-a-client-on/m-p/1674989#M33761</guid>
      <dc:creator>chrhiggi</dc:creator>
      <dc:date>2012-04-19T20:28:59Z</dc:date>
    </item>
  </channel>
</rss>

