<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASK THE EXPERTS:Configuring and troubleshooting Session Persiste in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693181#M34044</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a software to mac ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Linksys Wireless-G PTZ Internet Camera with Audio - WVC210&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sat, 23 Jul 2011 02:19:23 GMT</pubDate>
    <dc:creator>m.paulo.pires</dc:creator>
    <dc:date>2011-07-23T02:19:23Z</dc:date>
    <item>
      <title>ASK THE EXPERTS:Configuring and troubleshooting Session Persistence on Application Control Engine</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693176#M34039</link>
      <description>&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/legacy/1/8/3/52381-ohynderi.jpg" align="left" alt="Read the bio" border="0" hspace="10" style="padding-right: 10px; padding-bottom: 20px;" width="90" /&gt;&lt;STRONG&gt;With &lt;A _jive_internal="true" href="https://community.cisco.com/servlet/JiveServlet/showImage/102-17374-2-52380/450-148/Oliver_Hynderick_bio.gif" onclick="" target="globalCDCpopup"&gt;Olivier Hynderick&lt;/A&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Welcome to the Cisco Support Community Ask the Expert conversation. This is an opportunity to get an update on how to configure and troubleshoot session persistence (stickiness) on ACE with regards to specific protocols with Cisco expert Olivier Hynderick. Olivier has been working for the Cisco Technical Assistance Center for four years. He focuses on the Cisco Application Control Engine (ACE), Cisco Security Manager, and Cisco Wide Area Application Services and related technologies. He initially joined the Security team focusing on the Cisco ASA firewall and VPN on Cisco IOS applications before getting involved in the support of the Cisco ACE load balancer.&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Remember to use the rating system to let Olivier know if you have received an adequate response.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier might not be able to answer each question due to the volume expected during this event. Remember that you can continue the conversation on the &lt;A _jive_internal="true" href="https://community.cisco.com/community/netpro/data-center/application-network"&gt;Application Networking discussion forum&lt;/A&gt; shortly after the event. &lt;STRONG&gt;This event lasts through July 29, 2011&lt;/STRONG&gt;. Visit this forum often to view responses to your questions and the questions of other community members.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2011 22:48:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693176#M34039</guid>
      <dc:creator>ciscomoderator</dc:creator>
      <dc:date>2011-07-15T22:48:05Z</dc:date>
    </item>
    <item>
      <title>Re: ASK THE EXPERTS:Configuring and troubleshooting Session Pers</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693177#M34040</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have a cluster of ACE4710 and I use cookies for stickiness.&lt;/P&gt;&lt;P&gt;My question is the following:&lt;/P&gt;&lt;P&gt;I have a farm with server01 and server02. When server01 goes down but the client has already received a cookie for server01, will ACE clear the cookie and send the client a cookie for server02? and are there any special commands to do this?&lt;/P&gt;&lt;P&gt;here is what I have&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky http-cookie ACE_COOKIE_mobile ebanking_mobile_sticky&lt;/P&gt;&lt;P&gt;&amp;nbsp; cookie insert&lt;/P&gt;&lt;P&gt;&amp;nbsp; replicate sticky&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm SF_Ebanking_Mobile&lt;/P&gt;&lt;P&gt;&amp;nbsp; 16 static cookie-value "server01" rserver RS_IAS_1&lt;/P&gt;&lt;P&gt;&amp;nbsp; 24 static cookie-value "server02" rserver RS_IAS_2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;P&gt;george&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jul 2011 07:11:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693177#M34040</guid>
      <dc:creator>g.eleftheriou</dc:creator>
      <dc:date>2011-07-18T07:11:38Z</dc:date>
    </item>
    <item>
      <title>ASK THE EXPERTS:Configuring and troubleshooting Session Persiste</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693178#M34041</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello George,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case ACE receives a request containing a cookie value but the corresponding server in in the sticky database is down, ACE should loadbalancing the new request to one of the available servers ignoring the cookie.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To illustrate this, see below a quick test that I did in my lab:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky http-cookie ACE_COOKIE_mobile ebanking_mobile_sticky&lt;/P&gt;&lt;P&gt;&amp;nbsp; cookie insert&lt;/P&gt;&lt;P&gt;&amp;nbsp; replicate sticky&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm sf1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE/ctx# sh sticky cookie-insert group ebanking_mobile_sticky &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cookie&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HashKey&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rserver-instance&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; ------------+----------------------+----------------------------------------+&lt;/P&gt;&lt;P&gt;&amp;nbsp; R4072271931 | 15598686253581426628 | sf1/server1:0&lt;/P&gt;&lt;P&gt;&amp;nbsp; R4072273020 | 6532832188001237582&amp;nbsp; | sf1/server2:0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;GET / HTTP/1.1&lt;/P&gt;&lt;P&gt;Host: 10.10.170.13&lt;/P&gt;&lt;P&gt;User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:5.0.1) Gecko/20100101 Firefox/5.0.1&lt;/P&gt;&lt;P&gt;Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8&lt;/P&gt;&lt;P&gt;Accept-Language: en-us,en;q=0.5&lt;/P&gt;&lt;P&gt;Accept-Encoding: gzip, deflate&lt;/P&gt;&lt;P&gt;Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7&lt;/P&gt;&lt;P&gt;Connection: keep-alive&lt;/P&gt;&lt;P&gt;Cookie: ACE_COOKIE_mobile=R4072273020 --&amp;gt; cookie value corresponding to server2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTTP/1.1 200 OK&lt;/P&gt;&lt;P&gt;Set-Cookie: ACE_COOKIE_mobile=R4072271931; path=/; expires=Tue, 19-Jul-2011 09:22:39 GMT --&amp;gt; server2 is down, so request went to server1 and corresponding cookie was inserted.&lt;/P&gt;&lt;P&gt;...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Small remark, you shouldn't configure both "cookie insert" and static value for a server. What would you like to achieve?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jul 2011 09:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693178#M34041</guid>
      <dc:creator>ohynderi</dc:creator>
      <dc:date>2011-07-18T09:28:03Z</dc:date>
    </item>
    <item>
      <title>ASK THE EXPERTS:Configuring and troubleshooting Session Persiste</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693179#M34042</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I thought I need to use both.Can you explain the difference please?&lt;/P&gt;&lt;P&gt;If I use only "cookie insert" it creates the cookies for me and if I use static I name the cookies as I like?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jul 2011 10:15:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693179#M34042</guid>
      <dc:creator>g.eleftheriou</dc:creator>
      <dc:date>2011-07-18T10:15:51Z</dc:date>
    </item>
    <item>
      <title>ASK THE EXPERTS:Configuring and troubleshooting Session Persiste</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693180#M34043</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi again George,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With cookie insertion, ACE generates a cookie value based on the serverfarm and the real server name. This value is permanent and inserted in each server response. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With static values, ACE forwards requests containing cookies according to the static command. This is very similar to&amp;nbsp; cookie insertion accept that ACE no longer inserts cookies...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On ACE 20 (module), you can’t combine cookie insertion with static values. Static command will be ignored. On the other hand, you have this possibility on the ACE appliance as of A3(2.2) and on the ACE30.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Jul 2011 14:22:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693180#M34043</guid>
      <dc:creator>ohynderi</dc:creator>
      <dc:date>2011-07-18T14:22:33Z</dc:date>
    </item>
    <item>
      <title>ASK THE EXPERTS:Configuring and troubleshooting Session Persiste</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693181#M34044</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are a software to mac ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Linksys Wireless-G PTZ Internet Camera with Audio - WVC210&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 23 Jul 2011 02:19:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693181#M34044</guid>
      <dc:creator>m.paulo.pires</dc:creator>
      <dc:date>2011-07-23T02:19:23Z</dc:date>
    </item>
    <item>
      <title>ASK THE EXPERTS:Configuring and troubleshooting Session Persiste</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693182#M34045</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, is there a list of useful commands for troubleshooting cookie-insert on the ACE?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will try to get some output, but we have in the past had issues on our ACE modules and cookie insert, so we have resorted to IP based stickiness, but we are finding that we really need to move to the cookie-insert style of stickiness.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 26 Jul 2011 16:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693182#M34045</guid>
      <dc:creator>robwu2006</dc:creator>
      <dc:date>2011-07-26T16:54:51Z</dc:date>
    </item>
    <item>
      <title>ASK THE EXPERTS:Configuring and troubleshooting Session Persiste</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693183#M34046</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Olivier, &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Have you ever seen any issues w/ session persistance and local balancing radius and tacacs? We are trying to put some Cisco ACS servers behind our ACE20, but were not sure if session persistence would be required. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I know that the ACE supports class-maps for radius and tacacs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks, &lt;/P&gt;&lt;P&gt;Bryan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Jul 2011 16:20:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693183#M34046</guid>
      <dc:creator>Thompso7540_2</dc:creator>
      <dc:date>2011-07-27T16:20:53Z</dc:date>
    </item>
    <item>
      <title>ASK THE EXPERTS:Configuring and troubleshooting Session Persiste</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693184#M34047</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Rob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When troubleshooting cookie-insertion issues, best is to look at a network capture. With cookie insertion, ACE should insert below header field in the server responses. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Set-Cookie: &lt;COOKIE_NAME&gt;=R&lt;RSERVER_VALUE&gt;; path=/; expires=&lt;DATE&gt;”&lt;/DATE&gt;&lt;/RSERVER_VALUE&gt;&lt;/COOKIE_NAME&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will see below counter being incremented.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE/ctx# sh stats http | in "Headers inserted"&lt;/P&gt;&lt;P&gt; Headers inserted&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 38&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you then see the client adding the corresponding cookie in subsequent http requests?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Typical error with cookie insertion are:&lt;/P&gt;&lt;P&gt;- Clock on ACE is incorrect causing ACE to insert "Set-Cookie" with the date set in the past. Client will then ignore the Cookie.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- ACE failed to parse a client request because not rfc compliant. Connection is then drop to L4 and the "Static parse errors" counter is incremented.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE/ctx# sh stats http | in Static&lt;/P&gt;&lt;P&gt; Static parse errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 7&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , Resource errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- ACE failed to parse a client request because header is too big. You have the&amp;nbsp; "Max parselen errors" counter for this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE/ctx# sh stats http | in Max&lt;/P&gt;&lt;P&gt; Header insert errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , Max parselen errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you need more info.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jul 2011 07:02:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693184#M34047</guid>
      <dc:creator>ohynderi</dc:creator>
      <dc:date>2011-07-28T07:02:43Z</dc:date>
    </item>
    <item>
      <title>ASK THE EXPERTS:Configuring and troubleshooting Session Persiste</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693185#M34048</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Bryan,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What kind of issues are you facing?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Common problem with radius load balancing is that the clients often use a very limited number of udp connections to sent requests to the aaa servers. Usually those connections never time out as clients keep reusing them. This can lead to unfair load balancing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By configuring radius stickiness, we force the ACE to load balance each radius request individually. So yes, it is good proactive to have it! See below a config example with radius stickiness.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/slb/guide/classlb.html#wp1112138"&gt;http://www.cisco.com/en/US/partner/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/slb/guide/classlb.html#wp1112138&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Radius class-map is something else. You may for instance want to send requests with some particular radius attributes vaule (eg calling station id, …) to a specific serverfarm. I am not sure you need this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Finally, make sure that your context is not running out of sticky resources, otherwise ACE will start reusing exiting sticky entires. You can monitor this with following command:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE/ctx# sh stats sticky &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;+------------------------------------------+&lt;/P&gt;&lt;P&gt;+----------- Sticky statistics ------------+&lt;/P&gt;&lt;P&gt;+------------------------------------------+&lt;/P&gt;&lt;P&gt; Total sticky entries reused&amp;nbsp;&amp;nbsp;&amp;nbsp; : 3464 &amp;lt;&amp;lt;&amp;lt;&amp;lt;&lt;/P&gt;&lt;P&gt; prior to expiry&lt;/P&gt;&lt;P&gt; Total active sticky entries&amp;nbsp;&amp;nbsp;&amp;nbsp; : 2&lt;/P&gt;&lt;P&gt; Total active reverse sticky&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;P&gt; entries&lt;/P&gt;&lt;P&gt; Total active sticky conns&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;P&gt; Total static sticky entries&amp;nbsp;&amp;nbsp;&amp;nbsp; : 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jul 2011 07:34:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693185#M34048</guid>
      <dc:creator>ohynderi</dc:creator>
      <dc:date>2011-07-28T07:34:07Z</dc:date>
    </item>
    <item>
      <title>ASK THE EXPERTS:Configuring and troubleshooting Session Persiste</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693186#M34049</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;HI Olivier,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the tips, at the moment our clock on the&amp;nbsp; ACE module is like 1 hour out, as its in UTC, with&amp;nbsp; all the clients are&amp;nbsp; on BST.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The cat6k that we have the ACE modules in are on the&amp;nbsp; correct time (BST), I thought the ACE clock comes from the cat6k, so&amp;nbsp; they should be the same?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there a way to explicitly set the ACE module clock, having a quick look but can't find any clock/ntp commands in config t&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also&amp;nbsp; some output below, when we go via our VIP, I do not see any sticky&amp;nbsp; entries for my clients IP or the sticky database group while there are&amp;nbsp; active sessions. Is this normal?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE01/DMZ-VRF# sh service-policy TEST_VIP detail &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Status&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : ACTIVE&lt;/P&gt;&lt;P&gt;Description: -&lt;/P&gt;&lt;P&gt;-----------------------------------------&lt;/P&gt;&lt;P&gt;Interface: vlan 849 &lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy: TEST_VIP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; class: TEST_7777&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 102 vlan 849&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; curr conns&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , hit count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 28&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dropped conns&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; client pkt count : 880&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , client byte count: 222069&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; server pkt count : 1062&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , server byte count: 890955&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; conn-rate-limit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , drop-count : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bandwidth-rate-limit : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , drop-count : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VIP Address:&amp;nbsp;&amp;nbsp;&amp;nbsp; Protocol:&amp;nbsp; Port:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.31.XXX.XXX&amp;nbsp; tcp&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; eq&amp;nbsp;&amp;nbsp;&amp;nbsp; 7777 &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; L7 loadbalance policy: STICKY_COOKIE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VIP Route Metric&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VIP Route Advertise&amp;nbsp; : ENABLED-WHEN-ACTIVE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VIP ICMP Reply&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : ENABLED&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VIP State: INSERVICE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; curr conns&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , hit count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 115&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dropped conns&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; client pkt count : 2783&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , client byte count: 720269&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; server pkt count : 3163&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , server byte count: 2530541&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; conn-rate-limit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , drop-count : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bandwidth-rate-limit : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , drop-count : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; L7 Loadbalance policy : STICKY_COOKIE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; class/match : class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LB action : &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky group: websphere-sticky-cookie&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; primary serverfarm: TEST_SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state: UP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; backup serverfarm : -&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; hit count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 983&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dropped conns&amp;nbsp;&amp;nbsp;&amp;nbsp; : 9&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE01/DMZ-VRF# sh sticky database type http-cookie &lt;/P&gt;&lt;P&gt;ACE01/DMZ-VRF# sh sticky database client 172.16.15.7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI, we are running a fairly old version of&amp;nbsp; the ACE code, but I'm assuming that this feature has been ok for quite a&amp;nbsp; while, with the sticky cookie insert?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;disk0:c6ace-t1k9-mz.A2_1_2.bin&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jul 2011 13:29:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693186#M34049</guid>
      <dc:creator>robwu2006</dc:creator>
      <dc:date>2011-07-28T13:29:04Z</dc:date>
    </item>
    <item>
      <title>ASK THE EXPERTS:Configuring and troubleshooting Session Persiste</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693187#M34050</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Rob,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE can indeed sync with the clock of the chassis if chassis is configured with "clock calendar-valid". Although be aware that ACE and chassis can be configured to be in different time zone…&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can't explicitly set the clock on an ACE module. Like you said, it needs to synchronize with the chassis ;-).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With cookie insertion, ACE assigns statically a cookie to each server. The database doesn't actually contain any information related to the client. This is why "sh sticky database client" doesn't return anything. You have to look at "sh sticky database static".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky http-cookie my_cookie cookie1&lt;/P&gt;&lt;P&gt;&amp;nbsp; cookie insert&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm sf1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match lb_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm cookie&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE/ctx# sh sticky database static &lt;/P&gt;&lt;P&gt;sticky group : cookie1&lt;/P&gt;&lt;P&gt;type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : HTTP-COOKIE&lt;/P&gt;&lt;P&gt;timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1440&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; timeout-activeconns : FALSE&lt;/P&gt;&lt;P&gt;&amp;nbsp; sticky-entry&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rserver-instance&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; time-to-expire flags&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; ---------------------+--------------------------------+--------------+-------+&lt;/P&gt;&lt;P&gt;&amp;nbsp; R4072271931&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; server1:0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; never&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - &lt;/P&gt;&lt;P&gt;sticky group : cookie1&lt;/P&gt;&lt;P&gt;type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : HTTP-COOKIE&lt;/P&gt;&lt;P&gt;timeout&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1440&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; timeout-activeconns : FALSE&lt;/P&gt;&lt;P&gt;&amp;nbsp; sticky-entry&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rserver-instance&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; time-to-expire flags&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&amp;nbsp; ---------------------+--------------------------------+--------------+-------+&lt;/P&gt;&lt;P&gt;&amp;nbsp; R4072273020&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; server2:0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; never&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you believe ACE doesn't stick the client connections as it should. You may try to see if configuring "persistence rebalance" does not help.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/partner/docs/interfaces_modules/services_modules/ace/v3.00_A2/configuration/slb/guide/classlb.html#wpxref30971"&gt;http://www.cisco.com/en/US/partner/docs/interfaces_modules/services_modules/ace/v3.00_A2/configuration/slb/guide/classlb.html#wpxref30971&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jul 2011 17:46:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693187#M34050</guid>
      <dc:creator>ohynderi</dc:creator>
      <dc:date>2011-07-28T17:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASK THE EXPERTS:Configuring and troubleshooting Session Pers</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693188#M34051</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any real use case for persistance based on SSL session-id ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It used to be used in the past (let's say, maybe, 10 years ago) but since we discovered issues with some old IE versions restarting the negotiation of SSL session every 2 minutes it was not used anymore, replaced by cookie insertion when possible or source-IP based persistance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've always wondered why all vendors still provide this feature which seems to be useless (SSL sessions should not be related to the applications sessions according to the OSI model).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any clue ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other question, I usually set the cookie insertion with a timeout of 0 (cookie only available until the browser is closed) for web-based (browser-based) applications. Have you ever seen any case where the cookie insert method doesn't work and you had to use cookie learning or other stuff like that ? or timeout different of 0 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any official guide of best practices (even outside Cisco's authorized material) available ? The only book I've found is the one published by Cisco Press (written by Maurizzio Portolani) and it's old.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Jul 2011 19:50:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693188#M34051</guid>
      <dc:creator>Surya ARBY</dc:creator>
      <dc:date>2011-07-28T19:50:03Z</dc:date>
    </item>
    <item>
      <title>ASK THE EXPERTS:Configuring and troubleshooting Session Persiste</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693189#M34052</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Surya,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The SSL/TLS protocol allows clients to re-use same key materials for multiple TCP connections. When this happens, client sends a hello message containing already an SSL Session-ID. From there, there are 2 possibilities. Either the server has or still has the corresponding key materials. Or it responds with a different SSL Session-ID forcing the client to generate new key materials.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess you knew this already. The point of stickiness based on Session-ID is just to make sure that the client hello message is sent to the server that has to correct key materials. This to make the SSL negotiation faster. In case you have to maintain, multiple connections with different Session-ID, then indeed, it won't help. That really depends on your application and what you are looking for...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, ACE actually uses the Generic Protocol Parsing (GPP) to achieve this. So I would say that stickiness based on SSL Session-ID is one of the many thing you can achieve with GPP than a real option...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See below another link on this, which explains more or less the same...&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://docwiki.cisco.com/wiki/Secure_Sockets_Layer_Persistence_Configuration_Example#Limitations_of_SSL_stickiness"&gt;http://docwiki.cisco.com/wiki/Secure_Sockets_Layer_Persistence_Configuration_Example#Limitations_of_SSL_stickiness&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About cookie insertion with 0 timeout, i don't thing i have ever seen any problems with that. Actually doing so, you no longer have to rely on the load balancer clock which may, for whatever reasons, be/become incorrect. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;About learning cookie, again, that depends on your application. I have seen some customer applications where client was only taken into account a specific cookie inserted by the ACE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jul 2011 12:53:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693189#M34052</guid>
      <dc:creator>ohynderi</dc:creator>
      <dc:date>2011-07-29T12:53:05Z</dc:date>
    </item>
    <item>
      <title>ASK THE EXPERTS:Configuring and troubleshooting Session Persiste</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693190#M34053</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for that tip, it looks like my clocks are synced, so I will have another go at this next week.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;FYI, the link you sent :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/partner/docs/interfaces_modules/services_modules/ace/v3.00_A2/configuration/slb/guide/classlb.html#wpxref30971"&gt;http://www.cisco.com/en/US/partner/docs/interfaces_modules/services_modules/ace/v3.00_A2/configuration/slb/guide/classlb.html#wpxref30971&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it doesnt work for me I get a Forbidden File or Application, are you able to provide another link?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rob&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jul 2011 16:26:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693190#M34053</guid>
      <dc:creator>robwu2006</dc:creator>
      <dc:date>2011-07-29T16:26:12Z</dc:date>
    </item>
    <item>
      <title>ASK THE EXPERTS:Configuring and troubleshooting Session Persiste</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693191#M34054</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think I've found the link, is it this one your talking about?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/v3.00_A1/configuration/slb/guide/classlb.html#wp1062907"&gt;http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/v3.00_A1/configuration/slb/guide/classlb.html#wp1062907&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 29 Jul 2011 16:48:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-experts-configuring-and-troubleshooting-session/m-p/1693191#M34054</guid>
      <dc:creator>robwu2006</dc:creator>
      <dc:date>2011-07-29T16:48:10Z</dc:date>
    </item>
  </channel>
</rss>

