<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Loadbalancing TMG 2010 with ACE 4710 in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779466#M35376</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; For the other problem i recommend you this article:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00809c3041.shtml"&gt;http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00809c3041.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 12 Sep 2011 10:47:11 GMT</pubDate>
    <dc:creator>Marko Leopold</dc:creator>
    <dc:date>2011-09-12T10:47:11Z</dc:date>
    <item>
      <title>Loadbalancing TMG 2010 with ACE 4710</title>
      <link>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779465#M35375</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a pair of ACE 4710 devices in front of a TMG 2010 array (3 members) and are having some issues.&amp;nbsp; We have a nat pool on the ACE and need to be able to use integrated authentication in TMG since we are filtering URLs based on user ID.&amp;nbsp; For example some users might have access to certain websites that other users do not have access to.&amp;nbsp; TMG does all this fine when we send traffic directly to one of the TMG servers and it can successfully authenticate the user using the active directory username that was passed through.&amp;nbsp; The problem occurs when we send traffic through the ACE first, upon which time the user credentials are no longer appearing to TMG and the user is getting prompted for a username/password whenever they try to access a website.&amp;nbsp; Even when they do enter their username and password (which they shouldn't have to do) the request is still denied by TMG since it is coming from "anonymous" instead of their actual username.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another problem we seem to be having which isn't as important right now is the fact that since we are using a nat pool on the ACE, every web request to the TMG servers comes from one of the NAT addresses, rather than the original client IP.&amp;nbsp; Is there any way to get around this and have the actual client IP show up instead?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Brandon&lt;/P&gt;</description>
      <pubDate>Sat, 10 Sep 2011 01:37:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779465#M35375</guid>
      <dc:creator>BrandonNC</dc:creator>
      <dc:date>2011-09-10T01:37:19Z</dc:date>
    </item>
    <item>
      <title>Loadbalancing TMG 2010 with ACE 4710</title>
      <link>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779466#M35376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; For the other problem i recommend you this article:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00809c3041.shtml"&gt;http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00809c3041.shtml&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Sep 2011 10:47:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779466#M35376</guid>
      <dc:creator>Marko Leopold</dc:creator>
      <dc:date>2011-09-12T10:47:11Z</dc:date>
    </item>
    <item>
      <title>Loadbalancing TMG 2010 with ACE 4710</title>
      <link>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779467#M35377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For the first problem, I have a question. Do you loadbalance on L7? If yes, what is the header-size? Do you come over the default max-parse-length?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Sep 2011 10:49:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779467#M35377</guid>
      <dc:creator>Marko Leopold</dc:creator>
      <dc:date>2011-09-12T10:49:07Z</dc:date>
    </item>
    <item>
      <title>Loadbalancing TMG 2010 with ACE 4710</title>
      <link>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779468#M35378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marko,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure how to determine the header siz however we have increased the max-parse-length to 4096 (from the default 2048) just to be sure.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACE is still not passing the NTLM/Integrated authentication credentials through to the proxy server.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 12 Sep 2011 18:58:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779468#M35378</guid>
      <dc:creator>BrandonNC</dc:creator>
      <dc:date>2011-09-12T18:58:27Z</dc:date>
    </item>
    <item>
      <title>Loadbalancing TMG 2010 with ACE 4710</title>
      <link>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779469#M35379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Brandon!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please look at &lt;STRONG&gt;show stats http&lt;/STRONG&gt;. Are the counters for &lt;STRONG&gt;Max parselen errors&lt;/STRONG&gt; increasing? If yes, your header will be stil lmuch bigger. To determine the size you can use a sniffer-tool like &lt;STRONG&gt;wireshark &lt;/STRONG&gt;or &lt;STRONG&gt;tcpdump&lt;/STRONG&gt; and just count the bytes in the header.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Another way is to use the command &lt;STRONG&gt;length-exceed&amp;nbsp; continue &lt;/STRONG&gt;in a &lt;STRONG&gt;http parameter-map&lt;/STRONG&gt;.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Sep 2011 05:38:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779469#M35379</guid>
      <dc:creator>Marko Leopold</dc:creator>
      <dc:date>2011-09-13T05:38:21Z</dc:date>
    </item>
    <item>
      <title>Loadbalancing TMG 2010 with ACE 4710</title>
      <link>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779470#M35380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Marko,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It looks like the size of the headers was indeed greater than the allowed size.&amp;nbsp; After increasing the max header size in the parameter-map we are no longer seeing the Max parselen errors counter increase, however credentials are still not passing through the ACE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any other ideas?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time,&lt;/P&gt;&lt;P&gt;Brandon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Sep 2011 17:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779470#M35380</guid>
      <dc:creator>BrandonNC</dc:creator>
      <dc:date>2011-09-13T17:54:51Z</dc:date>
    </item>
    <item>
      <title>Loadbalancing TMG 2010 with ACE 4710</title>
      <link>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779471#M35381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I guess it is time to provide some config now. Everything else would be just playing an oracle &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Sep 2011 06:50:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779471#M35381</guid>
      <dc:creator>Marko Leopold</dc:creator>
      <dc:date>2011-09-14T06:50:33Z</dc:date>
    </item>
    <item>
      <title>Loadbalancing TMG 2010 with ACE 4710</title>
      <link>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779472#M35382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Brandon,&lt;/P&gt;&lt;P&gt;Can post your configuration for this?&lt;/P&gt;&lt;P&gt;I trying configure too...&lt;/P&gt;&lt;P&gt;Tks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 26 Apr 2012 20:25:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/loadbalancing-tmg-2010-with-ace-4710/m-p/1779472#M35382</guid>
      <dc:creator>Rafael Mendes</dc:creator>
      <dc:date>2012-04-26T20:25:00Z</dc:date>
    </item>
  </channel>
</rss>

