<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ACE SSL termination problem in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710519#M34296</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank You Daniel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Jun 2011 14:31:08 GMT</pubDate>
    <dc:creator>Vladimir Pavlinic</dc:creator>
    <dc:date>2011-06-09T14:31:08Z</dc:date>
    <item>
      <title>Cisco ACE SSL termination problem</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710511#M34288</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have problem setting up the SSL termination on Cisco 4710 ACE. Setup is in One-arm mode.&lt;/P&gt;&lt;P&gt;On ACE I need to do SSL client authentication.&lt;/P&gt;&lt;P&gt;We have 2 types of devices connecting to ACE.&lt;/P&gt;&lt;P&gt;With first one everything is working fine. But with second one i cant make client authentication to work.&lt;/P&gt;&lt;P&gt;When I issue "show stats crypto server", I see following counters increasing:&lt;/P&gt;&lt;PRE&gt;SSL alert BAD_CERTIFICATE sent:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will appriciate some explanation about this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;</description>
      <pubDate>Mon, 30 May 2011 06:31:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710511#M34288</guid>
      <dc:creator>Vladimir Pavlinic</dc:creator>
      <dc:date>2011-05-30T06:31:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACE SSL termination problem</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710512#M34289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This counter indicates that connections are being dropped because the client certificate is not valid (or at least the ACE is not able to validate it).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would start by finding the differences between the working and failing clients. At first sight, I wouldn't be surprised if they are using diferent CA or certificate types. Once you know better what is different, we can troubleshoot further.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2011 13:29:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710512#M34289</guid>
      <dc:creator>Daniel Arrondo Ostiz</dc:creator>
      <dc:date>2011-05-30T13:29:02Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACE SSL termination problem</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710513#M34290</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;it looks like the ACE ir refusing the certificate sent by the client for authenthication, I would check:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;are the 2 devices connecting to the same VIP/authgroup?&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;I would take a capture to check if the client is actually sending the certificate and which, in the trace i would capture also a successful session from the other device for comparison.&lt;/LI&gt;&lt;LI&gt;I would check wich other counters are increasing together with &lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;PRE&gt;SSL alert BAD_CERTIFICATE sent&lt;/PRE&gt;&lt;UL&gt;&lt;LI&gt;I would raise the logging level and check for messages like:&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE style="font-family: monospace; font-size: 12px; white-space: pre-wrap; word-wrap: break-word;"&gt;%ACE-6-253003: Certificate /CN=user1 is signed by an unknown C&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN style="font-family: arial,helvetica,sans-serif;"&gt;Hope it helps,&lt;BR /&gt;Francesco&lt;BR /&gt;&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 May 2011 13:38:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710513#M34290</guid>
      <dc:creator>Francesco Casotto</dc:creator>
      <dc:date>2011-05-30T13:38:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACE SSL termination problem</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710514#M34291</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am trying to find differences between certificates.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;!--[if gte mso 9]&gt;&lt;xml&gt; &lt;o:OfficeDocumentSettings&gt; &lt;o:AllowPNG&gt;&lt;/o:AllowPNG&gt; &lt;/o:OfficeDocumentSettings&gt; &lt;/xml&gt;&lt;![endif]--&gt;&lt;!--[if gte mso 10]&gt;
&lt;style&gt;
 /* Style Definitions */
 table.MsoNormalTable
	{mso-style-name:"Table Normal";
	mso-tstyle-rowband-size:0;
	mso-tstyle-colband-size:0;
	mso-style-noshow:yes;
	mso-style-priority:99;
	mso-style-parent:"";
	mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
	mso-para-margin:0cm;
	mso-para-margin-bottom:.0001pt;
	mso-pagination:widow-orphan;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";
	mso-ascii-font-family:Calibri;
	mso-ascii-theme-font:minor-latin;
	mso-hansi-font-family:Calibri;
	mso-hansi-theme-font:minor-latin;
	mso-bidi-font-family:"Times New Roman";
	mso-bidi-theme-font:minor-bidi;
	mso-fareast-language:EN-US;}
&lt;/style&gt;
&lt;![endif]--&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;* are the 2 devices connecting to the same VIP/authgroup?&lt;/P&gt;&lt;P class="MsoPlainText"&gt;No. Different VIP/authgroup.&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;I will let You know of any findings.&lt;/P&gt;&lt;P class="MsoPlainText"&gt;&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Regards,&lt;/P&gt;&lt;P class="MsoPlainText"&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jun 2011 07:26:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710514#M34291</guid>
      <dc:creator>Vladimir Pavlinic</dc:creator>
      <dc:date>2011-06-02T07:26:40Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACE SSL termination problem</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710515#M34292</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We managed to correct issues with certificates. There was a problem with time synchronization.&lt;/P&gt;&lt;P&gt;Now SSL termination works as expected.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Aftrer fixing SSL problems, we found another problem. &lt;/P&gt;&lt;P&gt;After client (device) hits VIP and SSL terminates on ACE, client (end device) is expecting to recive packet from Real server before sending enything to Real.&lt;/P&gt;&lt;P&gt;When ACE is doing SSL termination, there is no TCP conn to REAL SERVER until the APP Data is seen from client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any way to force ACE to open tcp connection to REAL without receiving APP data after SSL termination?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 12:33:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710515#M34292</guid>
      <dc:creator>Vladimir Pavlinic</dc:creator>
      <dc:date>2011-06-09T12:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACE SSL termination problem</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710516#M34293</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The moment SSL termination is done, the ACE will treat the connection as a L7 one, and therefore, it will wait to get the HTTP request before it tries to contact the server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Normally, this should not cause any issues to the application, so, could you please let me know why this behavior is not desirable?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 13:57:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710516#M34293</guid>
      <dc:creator>Daniel Arrondo Ostiz</dc:creator>
      <dc:date>2011-06-09T13:57:25Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACE SSL termination problem</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710517#M34294</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Daniel,&lt;/P&gt;&lt;P&gt;This is normal and expected behavior for L7 on ACE.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Application on end device is configured to send packets only after first packet is recived from Real. &lt;/P&gt;&lt;P&gt;We are trying to migrate existing SSL termination from STunnel to ACE. Stunnel is not an LB and it opens TCP connection to real after SSL termination. In this case Real can send required packet to end device and everything works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our end devices are configured this way and it will take a lot of time to reconfigure them to work with ACE.&lt;/P&gt;&lt;P&gt;I am just searching for an answer is this behavior achievable with ACE. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 14:16:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710517#M34294</guid>
      <dc:creator>Vladimir Pavlinic</dc:creator>
      <dc:date>2011-06-09T14:16:35Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACE SSL termination problem</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710518#M34295</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm afraid this behavior is not configurable. With L7 connections, the ACE will always wait for the client request before opening the connection to the server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Daniel&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 14:22:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710518#M34295</guid>
      <dc:creator>Daniel Arrondo Ostiz</dc:creator>
      <dc:date>2011-06-09T14:22:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACE SSL termination problem</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710519#M34296</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank You Daniel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Vladimir&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Jun 2011 14:31:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-ssl-termination-problem/m-p/1710519#M34296</guid>
      <dc:creator>Vladimir Pavlinic</dc:creator>
      <dc:date>2011-06-09T14:31:08Z</dc:date>
    </item>
  </channel>
</rss>

