<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Rserver/Vip same network in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770668#M35161</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why do you use the "transparent" keyword ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Oct 2011 14:02:09 GMT</pubDate>
    <dc:creator>Surya ARBY</dc:creator>
    <dc:date>2011-10-21T14:02:09Z</dc:date>
    <item>
      <title>Rserver/Vip same network</title>
      <link>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770663#M35156</link>
      <description>&lt;P&gt;This may sound like a silly question but can I configure the rservers and the vip address on the same network? If so does anyone have a example config?&lt;/P&gt;&lt;P&gt;NAT, policy, etc&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2011 19:11:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770663#M35156</guid>
      <dc:creator>Don Brack</dc:creator>
      <dc:date>2011-10-20T19:11:55Z</dc:date>
    </item>
    <item>
      <title>Rserver/Vip same network</title>
      <link>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770664#M35157</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Sorry this is for a ACE 4710.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 19:13:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770664#M35157</guid>
      <dc:creator>Don Brack</dc:creator>
      <dc:date>2011-10-20T19:13:20Z</dc:date>
    </item>
    <item>
      <title>Rserver/Vip same network</title>
      <link>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770665#M35158</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Don, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes you should be able to configure this, this setup is called Direct server return, since the client will be directly reachable from the server, only incoming connections comes through the vip and the return connection is directly established from the server to the client bypassing the ace. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can find further information on this configuration (Asymmetric Server Normalization) here :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://snippets101.blogspot.com/2008/08/asymmetric-server-normalization-on.html" target="_blank"&gt;http://snippets101.blogspot.com/2008/08/asymmetric-server-normalization-on.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Abijith &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 19:30:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770665#M35158</guid>
      <dc:creator>asharmav</dc:creator>
      <dc:date>2011-10-20T19:30:28Z</dc:date>
    </item>
    <item>
      <title>Re: Rserver/Vip same network</title>
      <link>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770666#M35159</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you need don't need to keep the source ip address for log purposes, use source NAT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you need to keep the source ip address for log purposes :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- for HTTP insert the source IP into the header and use source nat&lt;/P&gt;&lt;P&gt;- otherwise use DSR.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Source NAT config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match DOMINO-WEB-PM&lt;/P&gt;&lt;P&gt;&amp;nbsp; class DOMINO-WEB-VIP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;nat dynamic 1 vlan 3&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy DOMINO-WEB-CLASSIFY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options http_parameter_map&lt;/P&gt;&lt;P&gt;&amp;nbsp; exit&lt;/P&gt;&lt;P&gt;exit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 3&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.123.3.X 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; alias 10.123.3.X+1 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; peer ip address 10.123.3.X+2 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input PERMIT-ALL&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;STRONG&gt;nat-pool 1 10.123.3.245 10.123.3.245 netmask 255.255.255.0 pat&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;and apply the service policy&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Oct 2011 22:02:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770666#M35159</guid>
      <dc:creator>Surya ARBY</dc:creator>
      <dc:date>2011-10-20T22:02:18Z</dc:date>
    </item>
    <item>
      <title>Rserver/Vip same network</title>
      <link>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770667#M35160</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thanks for quick response....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have many services configured with the VIP on a different network then the Rservers, and having no issues. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now I'm having issues because the VIP and Rserver is on same network. Here is my config. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot ping or access the VIP..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks Again for all help..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;probe icmp icmp&lt;BR /&gt;&amp;nbsp; ip address 10.201.13.61&lt;BR /&gt;&amp;nbsp; interval 5&lt;BR /&gt;&amp;nbsp; passdetect interval 60&lt;/P&gt;&lt;P&gt;probe tcp episfdasp-80-probe&lt;BR /&gt;&amp;nbsp; port 80&lt;BR /&gt;&amp;nbsp; interval 5&lt;BR /&gt;&amp;nbsp; passdetect interval 5&lt;BR /&gt;&amp;nbsp; connection term forced&lt;BR /&gt;&amp;nbsp; open 1&lt;/P&gt;&lt;P&gt;rserver host w8v-episfdasp1&lt;BR /&gt;&amp;nbsp; ip address 10.201.13.10&lt;BR /&gt;&amp;nbsp; conn-limit max 4000000 min 4000000&lt;BR /&gt;&amp;nbsp; inservice&lt;BR /&gt;rserver host w8v-episfdasp2&lt;BR /&gt;&amp;nbsp; ip address 10.201.13.11&lt;BR /&gt;&amp;nbsp; conn-limit max 4000000 min 4000000&lt;BR /&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;serverfarm host episfdasp-443&lt;BR /&gt;&amp;nbsp; transparent&lt;BR /&gt;&amp;nbsp; predictor leastconns&lt;BR /&gt;&amp;nbsp; probe episfdasp-443-probe&lt;BR /&gt;&amp;nbsp; probe icmp&lt;BR /&gt;&amp;nbsp; rserver w8v-episfdasp1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;BR /&gt;&amp;nbsp; rserver w8v-episfdasp2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;sticky ip-netmask 255.255.255.255 address source episfdasp-443-sticky&lt;BR /&gt;&amp;nbsp; replicate sticky&lt;BR /&gt;&amp;nbsp; serverfarm episfdasp-443&lt;/P&gt;&lt;P&gt;class-map match-all episfdasp-443&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 10.201.13.61 tcp eq https&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match episfdasp-443-policy&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm episfdasp-443-sticky&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 15 serverfarm primary&lt;/P&gt;&lt;P&gt;policy-map multi-match client-vips&lt;BR /&gt;&amp;nbsp; class episfdasp-443&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy episfdasp-443-policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 15&lt;/P&gt;&lt;P&gt;interface vlan 15&lt;BR /&gt;&amp;nbsp; description dmz network&lt;BR /&gt;&amp;nbsp; ip address 10.201.13.8 255.255.255.0&lt;BR /&gt;&amp;nbsp; no normalization&lt;BR /&gt;&amp;nbsp; mac-sticky enable&lt;BR /&gt;&amp;nbsp; no icmp-guard&lt;BR /&gt;&amp;nbsp; access-group input inbound&lt;BR /&gt;&amp;nbsp; nat-pool 1 10.201.13.240 10.201.13.245 netmask 255.255.255.0 pat&lt;BR /&gt;&amp;nbsp; service-policy input remote_mgmt_allow_policy&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;ip route 0.0.0.0 0.0.0.0 10.201.13.1&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Oct 2011 13:57:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770667#M35160</guid>
      <dc:creator>Don Brack</dc:creator>
      <dc:date>2011-10-21T13:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: Rserver/Vip same network</title>
      <link>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770668#M35161</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Why do you use the "transparent" keyword ?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Oct 2011 14:02:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770668#M35161</guid>
      <dc:creator>Surya ARBY</dc:creator>
      <dc:date>2011-10-21T14:02:09Z</dc:date>
    </item>
    <item>
      <title>Rserver/Vip same network</title>
      <link>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770669#M35162</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Probably bcause I'm reading to much info on a simple problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what I read:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The transparent command prevents the ACE to make a destination NAT, sending the packet as to the real server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Oct 2011 14:14:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770669#M35162</guid>
      <dc:creator>Don Brack</dc:creator>
      <dc:date>2011-10-21T14:14:55Z</dc:date>
    </item>
    <item>
      <title>Re: Rserver/Vip same network</title>
      <link>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770670#M35163</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Using the transparent option on the serverfarm is a non standard design which should be only used when using IDS / FW load balancing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remove the transparent keyword (eventually issue a shut / no shut on the interface or reboot the appliance to be sure to flush the whole memory and reinit all the processes)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Then put a PC in the VLAN15 or try to access the VIP from a server located into that VLAN.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;At least the VIP should reply to a ping.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Oct 2011 14:57:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770670#M35163</guid>
      <dc:creator>Surya ARBY</dc:creator>
      <dc:date>2011-10-21T14:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Rserver/Vip same network</title>
      <link>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770671#M35164</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just let me know if you need further assistance.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Oct 2011 17:06:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770671#M35164</guid>
      <dc:creator>Surya ARBY</dc:creator>
      <dc:date>2011-10-21T17:06:04Z</dc:date>
    </item>
    <item>
      <title>Re: Rserver/Vip same network</title>
      <link>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770672#M35165</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; To resolve this I had to remove and add:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 15&lt;BR /&gt;&amp;nbsp; description dmz network&lt;BR /&gt;&amp;nbsp; ip address 10.201.13.8 255.255.255.0&lt;BR /&gt;&amp;nbsp; no normalization&lt;BR /&gt;&amp;nbsp; mac-sticky enable&lt;BR /&gt;&amp;nbsp; no icmp-guard&lt;BR /&gt;&amp;nbsp; access-group input inbound&lt;BR /&gt;&amp;nbsp; nat-pool 1 10.201.13.240 10.201.13.245 netmask 255.255.255.0 pat&lt;BR /&gt;&amp;nbsp; -----&lt;STRONG&gt;service-policy input remote_mgmt_allow_policy----removed&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;-------&lt;STRONG&gt;service-policy input clients-vips---added&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 24 Oct 2011 16:54:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rserver-vip-same-network/m-p/1770672#M35165</guid>
      <dc:creator>Don Brack</dc:creator>
      <dc:date>2011-10-24T16:54:13Z</dc:date>
    </item>
  </channel>
</rss>

