<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ssl rewrite issue for IDM application in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778423#M35366</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi oliver,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any suggestion&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 24 Aug 2011 04:31:26 GMT</pubDate>
    <dc:creator>Yahshanulla S</dc:creator>
    <dc:date>2011-08-24T04:31:26Z</dc:date>
    <item>
      <title>ssl rewrite issue for IDM application</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778416#M35359</link>
      <description>&lt;P&gt;We have IDM application with SSL offloading in ACE with action REWRITE statement. We are using IDM for both HTTP and HTTPS applications authentication. But we have problem for HTTP sites like after IDM authentication HTTP header will be rewrite as HTTPS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTTP VIP --&amp;gt; IDM VIP --&amp;gt;Converted to HTTPS because of action REWRITE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;IDM VIP has the following config:&lt;/P&gt;&lt;P&gt;------------------------------------------------&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;action-list type modify http REWRITE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&amp;nbsp; ssl url rewrite location ".*"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;policy-map type loadbalance first-match LB-rtp-login-stg-S443&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm SG-rtp-login-stg-S80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; action REWRITE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: .0001pt; line-height: normal;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; insert-http IS_SSL header-value "ssl"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if we remove action REWRITE&amp;nbsp; then HTTPS applications are breaking after IDM authentication. How to fix this issue?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Aug 2011 12:08:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778416#M35359</guid>
      <dc:creator>Yahshanulla S</dc:creator>
      <dc:date>2011-08-19T12:08:48Z</dc:date>
    </item>
    <item>
      <title>ssl rewrite issue for IDM application</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778417#M35360</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any body is having any idea about this???&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 19 Aug 2011 20:20:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778417#M35360</guid>
      <dc:creator>Yahshanulla S</dc:creator>
      <dc:date>2011-08-19T20:20:03Z</dc:date>
    </item>
    <item>
      <title>ssl rewrite issue for IDM application</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778418#M35361</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you show me your multi-match policy as well? I guess you have a different class for http and https. Are you using the same loadbalance policy for http and https?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 09:15:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778418#M35361</guid>
      <dc:creator>ohynderi</dc:creator>
      <dc:date>2011-08-22T09:15:41Z</dc:date>
    </item>
    <item>
      <title>ssl rewrite issue for IDM application</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778419#M35362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes. we have separate multi-match policy for HTTP and HTTPS IDM VIP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match GP-SUBPROD-01-VIP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class VC-rtp-login-stg-S80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy LB-rtp-login-stg-S80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 2513&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 2514&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options TCP_PARAM_MAP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class VC-rtp-login-stg-S443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy LB-rtp-login-stg-S443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options http_paramater_map&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy server SO-rtp-login-stg-S&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options TCP_PARAM_MAP&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 11:03:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778419#M35362</guid>
      <dc:creator>Yahshanulla S</dc:creator>
      <dc:date>2011-08-22T11:03:08Z</dc:date>
    </item>
    <item>
      <title>ssl rewrite issue for IDM application</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778420#M35363</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I assume you didn't apply the rewrite action to the LB-rtp-login-stg-S80 policy. Do you maybe have some network captures exhibiting the problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 13:28:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778420#M35363</guid>
      <dc:creator>ohynderi</dc:creator>
      <dc:date>2011-08-22T13:28:02Z</dc:date>
    </item>
    <item>
      <title>ssl rewrite issue for IDM application</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778421#M35364</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Well. the problem with only HTTPS( VC-rtp-login-stg-S443), As i explained before. This is IDM application(VIP) and we need to use HTTPS only as this is internet based. So the problem with only if other HTTP application gets authenticated with this IDM HTTPS VIP then the result is HTTPS (original request was HTTP).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style-type: none;"&gt;Application (1) HTTP VIP --&amp;gt; IDM VIP --&amp;gt;Converted to HTTPS of Application (1)&amp;nbsp; because of action REWRITE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="border-collapse: collapse; list-style-type: none;"&gt;I hope you understood the problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 14:21:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778421#M35364</guid>
      <dc:creator>Yahshanulla S</dc:creator>
      <dc:date>2011-08-22T14:21:42Z</dc:date>
    </item>
    <item>
      <title>Re: ssl rewrite issue for IDM application</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778422#M35365</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Adding the screenshots &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Aug 2011 14:49:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778422#M35365</guid>
      <dc:creator>Yahshanulla S</dc:creator>
      <dc:date>2011-08-22T14:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: ssl rewrite issue for IDM application</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778423#M35366</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi oliver,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any suggestion&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Aug 2011 04:31:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778423#M35366</guid>
      <dc:creator>Yahshanulla S</dc:creator>
      <dc:date>2011-08-24T04:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: ssl rewrite issue for IDM application</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778424#M35367</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You basically need to rewrite the action-list so that it doesn't match&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://stagesupport.netap.com"&gt;http://stagesupport.netap.com&lt;/A&gt;&lt;SPAN&gt;. Currently it is matching everything.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should try to have a sniffer trace on the server side so that you can confirm the URL present in the Location header of the http redirection&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Aug 2011 09:21:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778424#M35367</guid>
      <dc:creator>ohynderi</dc:creator>
      <dc:date>2011-08-24T09:21:27Z</dc:date>
    </item>
    <item>
      <title>Re: ssl rewrite issue for IDM application</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778425#M35368</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you want to put exactly under action list. Please give me some example.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2011 06:22:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778425#M35368</guid>
      <dc:creator>Yahshanulla S</dc:creator>
      <dc:date>2011-08-25T06:22:55Z</dc:date>
    </item>
    <item>
      <title>ssl rewrite issue for IDM application</title>
      <link>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778426#M35369</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just have a look at this:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00809c3045.shtml"&gt;http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00809c3045.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the example, ACE is configured to rewrite location headers matching &lt;A href="https://community.cisco.com/www.cisco.com" target="_blank"&gt;www.cisco.com&lt;/A&gt; only. You should do the same: have a restricted list of urls that need to be rewrite in http redirections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Olivier&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 25 Aug 2011 08:11:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ssl-rewrite-issue-for-idm-application/m-p/1778426#M35369</guid>
      <dc:creator>ohynderi</dc:creator>
      <dc:date>2011-08-25T08:11:35Z</dc:date>
    </item>
  </channel>
</rss>

