<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACE dropped conns problem (Bridged mode) in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688292#M33962</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very likely you have asymetric routing (ie traffic from server to client bypassing the ACE). If this is indeed the case, you should see the client pkt counter increasing but not the server pkt counter in show service-policy. To workaround this you should source nat traffic from server in that vlan to vip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 16 May 2011 09:56:15 GMT</pubDate>
    <dc:creator>ohynderi</dc:creator>
    <dc:date>2011-05-16T09:56:15Z</dc:date>
    <item>
      <title>ACE dropped conns problem (Bridged mode)</title>
      <link>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688288#M33958</link>
      <description>&lt;P&gt;Dear all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configured an ACE in bridged mode (inside vlan: 2012, outside vlan: 2021) and I apply the L4 policy on the 2 VLAN interface to loadbalance HTTP incoming request (Virtual IP: 172.22.22.130).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 2112&lt;BR /&gt;&amp;nbsp; bridge-group 1&lt;BR /&gt;&amp;nbsp; access-group input BPDU-Allow&lt;BR /&gt;&amp;nbsp; service-policy input POLICY-LB-HMC-2112&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;interface vlan 2122&lt;BR /&gt;&amp;nbsp; bridge-group 1&lt;BR /&gt;&amp;nbsp; access-group input BPDU-Allow&lt;BR /&gt;&amp;nbsp; service-policy input POLICY-LB-HMC-2112&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But I need also that some other server connected to the same vlan 2112 and having to send HTTP request on the same VIP but this failed and I get dropped conns.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can anyone helps?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Abdelaziz&lt;/P&gt;</description>
      <pubDate>Sun, 15 May 2011 22:06:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688288#M33958</guid>
      <dc:creator>Adelaziz Ben Aziza</dc:creator>
      <dc:date>2011-05-15T22:06:27Z</dc:date>
    </item>
    <item>
      <title>Re: ACE dropped conns problem (Bridged mode)</title>
      <link>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688289#M33959</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Abdelaziz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure to understand your issue. Are all connections to vip (172.22.22.130) failing or only connections initiated from server in vlan 2122 to vip failing? Do you see some hits in show service-policy when connection are failing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 07:24:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688289#M33959</guid>
      <dc:creator>ohynderi</dc:creator>
      <dc:date>2011-05-16T07:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: ACE dropped conns problem (Bridged mode)</title>
      <link>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688290#M33960</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Olivier,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Only connections initiated from server in vlan 2122 to vip&amp;nbsp; (172.22.22.130) failing. No problem with connection from Outside. Moreover, I see hits in show service-policy when connection are failing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanx,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Abdelaziz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 08:16:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688290#M33960</guid>
      <dc:creator>Adelaziz Ben Aziza</dc:creator>
      <dc:date>2011-05-16T08:16:27Z</dc:date>
    </item>
    <item>
      <title>Re: ACE dropped conns problem (Bridged mode)</title>
      <link>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688291#M33961</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;My guess is, that you have a direct-server-return in your VLAN 2122.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 09:20:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688291#M33961</guid>
      <dc:creator>Marko Leopold</dc:creator>
      <dc:date>2011-05-16T09:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: ACE dropped conns problem (Bridged mode)</title>
      <link>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688292#M33962</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Very likely you have asymetric routing (ie traffic from server to client bypassing the ACE). If this is indeed the case, you should see the client pkt counter increasing but not the server pkt counter in show service-policy. To workaround this you should source nat traffic from server in that vlan to vip.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 09:56:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688292#M33962</guid>
      <dc:creator>ohynderi</dc:creator>
      <dc:date>2011-05-16T09:56:15Z</dc:date>
    </item>
    <item>
      <title>Re: ACE dropped conns problem (Bridged mode)</title>
      <link>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688293#M33963</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Olivier,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This below the full config, and my need is to make a server in the inside VLAN 2112 (172.22.22.121) to open HTTPS connexion on the VIP (172.22.22.130 for rserver .131 &amp;amp; .132). Trafic from the outside is working well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanx,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Abdealziz&lt;/P&gt;&lt;P&gt;--------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generating configuration....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list BPDU-Allow ethertype permit bpdu&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;probe tcp HTTPS&lt;BR /&gt;&amp;nbsp; port 443&lt;BR /&gt;&amp;nbsp; interval 15&lt;BR /&gt;&amp;nbsp; passdetect interval 15&lt;BR /&gt;&amp;nbsp; passdetect count 1&lt;BR /&gt;probe icmp PING&lt;BR /&gt;&amp;nbsp; interval 5&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;rserver host CASHUB131&lt;BR /&gt;&amp;nbsp; ip address 172.22.22.131&lt;BR /&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host CASHUB132&lt;BR /&gt;&amp;nbsp; ip address 172.22.22.132&lt;BR /&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host SFARM-EXCAS130&lt;BR /&gt;&amp;nbsp; probe HTTPS&lt;BR /&gt;&amp;nbsp; rserver CASHUB131&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;BR /&gt;&amp;nbsp; rserver CASHUB132&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type connection TCP_IDLE_30min&lt;BR /&gt;&amp;nbsp; set timeout inactivity 1800&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all CLASS-L4-VIP-EXCAS130&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 172.22.22.130 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type management match-any REMOTE-ACCESS&lt;BR /&gt;&amp;nbsp; description management ACE&lt;BR /&gt;&amp;nbsp; 10 match protocol telnet any&lt;BR /&gt;&amp;nbsp; 20 match protocol ssh any&lt;BR /&gt;&amp;nbsp; 30 match protocol icmp any&lt;BR /&gt;&amp;nbsp; 31 match protocol https any&lt;BR /&gt;&amp;nbsp; 32 match protocol snmp any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type management first-match REMOTE-MGT&lt;BR /&gt;&amp;nbsp; class REMOTE-ACCESS&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match POLICY-L7-VIP-EXCAS130&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm SFARM-EXCAS130&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match POLICY-LB-HMC-2112&lt;BR /&gt;&amp;nbsp; class CLASS-L4-VIP-EXCAS130&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy POLICY-L7-VIP-EXCAS130&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options TCP_IDLE_30min&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 2112&lt;BR /&gt;&amp;nbsp; bridge-group 1&lt;BR /&gt;&amp;nbsp; access-group input BPDU-Allow&lt;BR /&gt;&amp;nbsp; service-policy input POLICY-LB-HMC-2112&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;interface vlan 2122&lt;BR /&gt;&amp;nbsp; bridge-group 1&lt;BR /&gt;&amp;nbsp; access-group input BPDU-Allow&lt;BR /&gt;&amp;nbsp; service-policy input POLICY-LB-HMC-2112&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface bvi 1&lt;BR /&gt;&amp;nbsp; ip address 172.22.22.250 255.255.255.0&lt;BR /&gt;&amp;nbsp; peer ip address 172.22.22.251 255.255.255.0&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 172.22.22.254&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 May 2011 12:44:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688293#M33963</guid>
      <dc:creator>Adelaziz Ben Aziza</dc:creator>
      <dc:date>2011-05-16T12:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: ACE dropped conns problem (Bridged mode)</title>
      <link>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688294#M33964</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Abdealziz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you check this?&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00809c6ef5.shtml"&gt;http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00809c6ef5.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2011 06:50:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688294#M33964</guid>
      <dc:creator>ohynderi</dc:creator>
      <dc:date>2011-05-17T06:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: ACE dropped conns problem (Bridged mode)</title>
      <link>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688295#M33965</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Olivier,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked this document and it's talking about routed mode where the problem can be easily solved with SNAT. In my cas, i need to iniate traffic from machine 172.22.12.141 to the VIP following this diagram:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/9/8/8/47889-ACE%20-%20Network%20Diagram.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can ping the VIP from .141 but i can't initiate HTTP session. Moreover, I think it's impossible for me to use SNAT with Bridged Mode and I can't change to routed mode. So is there any solution for this issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Abdelaziz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 May 2011 22:42:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688295#M33965</guid>
      <dc:creator>Adelaziz Ben Aziza</dc:creator>
      <dc:date>2011-05-17T22:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: ACE dropped conns problem (Bridged mode)</title>
      <link>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688296#M33966</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Abdelaziz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand that the example i gave to you is in routed mode, but, if not mistaken, you should still be able to configure the nat pool (and so the source nat) under vlan 2012.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 May 2011 13:20:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688296#M33966</guid>
      <dc:creator>ohynderi</dc:creator>
      <dc:date>2011-05-18T13:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: ACE dropped conns problem (Bridged mode)</title>
      <link>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688297#M33967</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Olivier,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I configure the nat pool and apply the SNAT policy under vlan 2012 and it's working. This is the config to be added to the standard configuration in bridged mode:&lt;/P&gt;&lt;P&gt;-------------------------&lt;/P&gt;&lt;P&gt;class-map match-any SNAT&lt;BR /&gt;&amp;nbsp; 2 match source-address 172.22.12.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match POLICY-NAT&lt;BR /&gt;&amp;nbsp; class SNAT&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 2012&lt;/P&gt;&lt;P&gt;interface vlan 2012&lt;BR /&gt;&amp;nbsp; nat-pool 1 172.22.12.200 172.22.12.200 netmask 255.255.255.255 pat&lt;BR /&gt;&amp;nbsp; service-policy input POLICY-NAT&lt;/P&gt;&lt;P&gt;----------------------------&lt;/P&gt;&lt;P&gt;It's working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Abdelaziz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 May 2011 23:20:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-dropped-conns-problem-bridged-mode/m-p/1688297#M33967</guid>
      <dc:creator>Adelaziz Ben Aziza</dc:creator>
      <dc:date>2011-05-18T23:20:05Z</dc:date>
    </item>
  </channel>
</rss>

