<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACE Issue. in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753678#M34908</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know about this config why its required and how it will work. if I remove class SOURCE_NAT how it will impact.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does that mean source-nat will only check class source-nat frist then next ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match SOURCE_NAT_POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; class SOURCE_NAT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 3 vlan 1201&lt;/P&gt;&lt;P&gt;policy-map multi-match vip-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; class prod-ad&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy prod-ad-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active primary-inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 3 vlan 1201&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ajay&lt;/P&gt;</description>
    <pubDate>Fri, 05 Aug 2011 15:49:25 GMT</pubDate>
    <dc:creator>ajay chauhan</dc:creator>
    <dc:date>2011-08-05T15:49:25Z</dc:date>
    <item>
      <title>ACE Issue.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753678#M34908</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to know about this config why its required and how it will work. if I remove class SOURCE_NAT how it will impact.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;does that mean source-nat will only check class source-nat frist then next ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match SOURCE_NAT_POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; class SOURCE_NAT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 3 vlan 1201&lt;/P&gt;&lt;P&gt;policy-map multi-match vip-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; class prod-ad&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy prod-ad-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active primary-inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 3 vlan 1201&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ajay&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2011 15:49:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753678#M34908</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2011-08-05T15:49:25Z</dc:date>
    </item>
    <item>
      <title>ACE Issue.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753679#M34909</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ajay, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It depends where the SOURCE_NAT_POLICY is being applied, you can get really granular with ACE NAT options, it could be for server to VIP traffic, server to outside initiated conns etc. It's all about what's being matched with the class SOURCE_NAT and where the multi-match policy is implemented.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;__ __ &lt;/P&gt;&lt;P&gt;Pablo &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2011 18:40:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753679#M34909</guid>
      <dc:creator>pablo.nxh</dc:creator>
      <dc:date>2011-08-05T18:40:44Z</dc:date>
    </item>
    <item>
      <title>ACE Issue.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753680#M34910</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks Pablo.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have one more issue here on switch ACE module is there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a user vlan on switch and one management vlan/ vip vlan /server vlan associated with ACE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;when VIP is access via firewall for remote users it works and when used by this user group which is sitting on same switch &lt;/P&gt;&lt;P&gt;it comes like connection refused.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The only thing I have seen this traffic is routed over management vlan means SVI is on switch for management vlan also one ip is configured on ACE for managemnet .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The static route is pointing to management IP on ACE for VIP subnet from switch.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just wanted to confirm if routing over management vlan does work .&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using same routing i can telnet on servers successfully not sure if we can use the same routing for VIPs as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ajay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2011 19:18:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753680#M34910</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2011-08-05T19:18:52Z</dc:date>
    </item>
    <item>
      <title>ACE Issue.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753681#M34911</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;DIV&gt;&lt;P&gt;Hello Ajay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sounds&amp;nbsp; to me you're running into an asymmetric routing issue... Can you share a&amp;nbsp; sanited copy of your configuration so I can take a quick look?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;__ __ &lt;/P&gt;&lt;P&gt;Pablo&lt;/P&gt;&lt;/DIV&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2011 19:40:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753681#M34911</guid>
      <dc:creator>pablo.nxh</dc:creator>
      <dc:date>2011-08-05T19:40:08Z</dc:date>
    </item>
    <item>
      <title>ACE Issue.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753682#M34912</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Pablo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the config-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ON LB&lt;/P&gt;&lt;P&gt;interface vlan 1100&lt;BR /&gt;&amp;nbsp; description to ASA&lt;BR /&gt;&amp;nbsp; ip address 10.222.133.250 255.255.255.248&lt;BR /&gt;&amp;nbsp; alias 10.222.133.249 255.255.255.248&lt;BR /&gt;&amp;nbsp; peer ip address 10.222.133.251 255.255.255.248&lt;BR /&gt;&amp;nbsp; ip address 10.222.159.1 255.255.255.0 secondary&lt;BR /&gt;&amp;nbsp; peer ip address 10.222.159.2 255.255.255.0 secondary&lt;BR /&gt;&amp;nbsp; mac-address autogenerate&lt;BR /&gt;&amp;nbsp; access-group input TRAFFIC&lt;BR /&gt;&amp;nbsp; service-policy input vip&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;interface vlan 1205&lt;BR /&gt;&amp;nbsp; description SERVERS&lt;BR /&gt;&amp;nbsp; ip address 10.222.163.4 255.255.255.0&lt;BR /&gt;&amp;nbsp; ip dhcp relay server 10.222.163.57&lt;BR /&gt;&amp;nbsp; ip dhcp relay enable&lt;BR /&gt;&amp;nbsp; alias 10.222.163.1 255.255.255.0&lt;BR /&gt;&amp;nbsp; peer ip address 10.222.163.5 255.255.255.0&lt;BR /&gt;&amp;nbsp; mac-address autogenerate&lt;BR /&gt;&amp;nbsp; access-group input TRAFFIC&lt;BR /&gt;&amp;nbsp; access-group output TRAFFIC&lt;BR /&gt;&amp;nbsp; nat-pool 4 10.222.163.253 10.222.163.253 netmask 255.255.255.0 pat&lt;BR /&gt;&amp;nbsp; service-policy input vip&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;interface vlan 1105&lt;BR /&gt;&amp;nbsp; description to MG&lt;BR /&gt;&amp;nbsp; ip address 10.222.129.18 255.255.255.0&lt;BR /&gt;&amp;nbsp; alias 10.222.129.21 255.255.255.0&lt;BR /&gt;&amp;nbsp; peer ip address 10.222.129.19 255.255.255.0&lt;BR /&gt;&amp;nbsp; mac-address autogenerate&lt;BR /&gt;&amp;nbsp; access-group input TRAFFIC&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ip route 10.222.128.0 255.255.128.0 10.224.129.1&amp;nbsp; &amp;lt; .1 is SVI on switch.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;On switch &lt;/P&gt;&lt;P&gt;ip route 10.222.159.0 255.255.255.0 10.222.129.21&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2011 20:26:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753682#M34912</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2011-08-05T20:26:06Z</dc:date>
    </item>
    <item>
      <title>ACE Issue.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753683#M34913</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ajay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you tell me the IP address of the client(s) that is getting connection refused? I think it is within the same server subnet 10.222.163.0/24 but I want to make sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;__ __ &lt;/P&gt;&lt;P&gt;Pablo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2011 20:56:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753683#M34913</guid>
      <dc:creator>pablo.nxh</dc:creator>
      <dc:date>2011-08-05T20:56:14Z</dc:date>
    </item>
    <item>
      <title>ACE Issue.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753684#M34914</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Pablo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have multiple VLANs in range of 10.222.128.0 255.255.128.0 on switch and no success from any of the vlan for exmple&lt;/P&gt;&lt;P&gt;10.222.203.0/24.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ajay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2011 20:59:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753684#M34914</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2011-08-05T20:59:50Z</dc:date>
    </item>
    <item>
      <title>ACE Issue.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753685#M34915</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh in that case can you attach the ful show run of your ACE? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;__ __ &lt;/P&gt;&lt;P&gt;Pablo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2011 21:09:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753685#M34915</guid>
      <dc:creator>pablo.nxh</dc:creator>
      <dc:date>2011-08-05T21:09:11Z</dc:date>
    </item>
    <item>
      <title>ACE Issue.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753686#M34916</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Pablo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am just wondering if the problem is to get into LB from management interface which has not got any service policy applied &lt;/P&gt;&lt;P&gt;on it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Creating another SVI on switch and giving a IP address from VIP range can that solve my issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Ajay&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2011 21:40:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753686#M34916</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2011-08-05T21:40:43Z</dc:date>
    </item>
    <item>
      <title>ACE Issue.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753687#M34917</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ajay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That's the problem at this point I don't know to which SVI your VIP belongs to; I see the service policy applied under both "traffic" interfaces; I guess it is on VLAN 1100 as it is working for remote users but that's what I wanted to confirm with the show run. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does VLAN 1100 has a SVI created on the switch? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;__ __ &lt;/P&gt;&lt;P&gt;Pablo &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 Aug 2011 21:54:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753687#M34917</guid>
      <dc:creator>pablo.nxh</dc:creator>
      <dc:date>2011-08-05T21:54:41Z</dc:date>
    </item>
    <item>
      <title>ACE Issue.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753688#M34918</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Applying VIP policy on Management interface resolved the issue.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2011 11:12:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-issue/m-p/1753688#M34918</guid>
      <dc:creator>ajay chauhan</dc:creator>
      <dc:date>2011-08-10T11:12:51Z</dc:date>
    </item>
  </channel>
</rss>

