<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACE PAT to two IP-number in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-pat-to-two-ip-number/m-p/1789741#M35484</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;Connections are very shortlived, so no&amp;nbsp; connection stays longer than 4 minutes.&lt;/P&gt;&lt;P&gt;I have done a show tech and attached the file.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mats&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 05 Oct 2011 06:24:05 GMT</pubDate>
    <dc:creator>mruuth</dc:creator>
    <dc:date>2011-10-05T06:24:05Z</dc:date>
    <item>
      <title>ACE PAT to two IP-number</title>
      <link>https://community.cisco.com/t5/application-networking/ace-pat-to-two-ip-number/m-p/1789737#M35480</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;ACE20 module with A2(3.3)&lt;/P&gt;&lt;P&gt;I have tried to config a NAT-pool with two adresses, but only one is used. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all NAT015_VLAN702&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match source-address 192.168.137.93 255.255.255.255&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3 match destination-address 192.168.137.0 255.255.255.255&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;/P&gt;&lt;P&gt;policy-map multi-match lb-int-vlan802&lt;/P&gt;&lt;P&gt;&amp;nbsp; class V13700080&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy V13700080-l7slb&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options PAMHTTP001&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options PAMCONNSV&lt;/P&gt;&lt;P&gt;&amp;nbsp; class NAT015_VLAN702&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 70203 vlan 702 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; interface vlan 702&lt;/P&gt;&lt;P&gt;&amp;nbsp; bridge-group 802&lt;/P&gt;&lt;P&gt;&amp;nbsp; no normalization&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input BPDU&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input alla&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group output alla&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 70202 192.168.32.1 192.168.32.2 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 70203 192.168.32.5 192.168.32.6 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 70204 192.168.32.9 192.168.32.10 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 70205 192.168.32.13 192.168.32.14 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 70206 192.168.32.17 192.168.32.18 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 70207 192.168.32.21 192.168.32.22 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input lb-int-vlan802&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;SPAN id="mce_marker"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can someone tell me what is wrong?&lt;/P&gt;&lt;P&gt;Regards &lt;/P&gt;&lt;P&gt;Mats&lt;/P&gt;</description>
      <pubDate>Thu, 22 Sep 2011 09:28:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-pat-to-two-ip-number/m-p/1789737#M35480</guid>
      <dc:creator>mruuth</dc:creator>
      <dc:date>2011-09-22T09:28:03Z</dc:date>
    </item>
    <item>
      <title>ACE PAT to two IP-number</title>
      <link>https://community.cisco.com/t5/application-networking/ace-pat-to-two-ip-number/m-p/1789738#M35481</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hello Mats-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; How exactly did you verify only 1 of the 2 IPs were in use? ACE actually tries to conserve ports and IP addresses, so it will exhaust all ~64k PAT entries on the first IP before it uses the 2nd address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Chris Higgins&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Sep 2011 17:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-pat-to-two-ip-number/m-p/1789738#M35481</guid>
      <dc:creator>chrhiggi</dc:creator>
      <dc:date>2011-09-26T17:54:51Z</dc:date>
    </item>
    <item>
      <title>ACE PAT to two IP-number</title>
      <link>https://community.cisco.com/t5/application-networking/ace-pat-to-two-ip-number/m-p/1789739#M35482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Chris,&lt;/P&gt;&lt;P&gt;Been away a couple of days.&lt;/P&gt;&lt;P&gt; I'm doing show xlate global 192.168.32.5 and 192.168.35.6 and I never see xlate's on 192.168.32.6.&lt;/P&gt;&lt;P&gt;A#1/prod1# sho xlate global 192.168.32.5&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/22524 to vlan702:192.168.32.5/62357&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/22565 to vlan702:192.168.32.5/62396&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/22600 to vlan702:192.168.32.5/62433&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/22686 to vlan702:192.168.32.5/62519&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/22814 to vlan702:192.168.32.5/62645&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/21368 to vlan702:192.168.32.5/61201&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/22514 to vlan702:192.168.32.5/64626&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/22605 to vlan702:192.168.32.5/64720&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/22527 to vlan702:192.168.32.5/64644&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/21935 to vlan702:192.168.32.5/64052&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/22863 to vlan702:192.168.32.5/64978&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/22882 to vlan702:192.168.32.5/64998&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/22893 to vlan702:192.168.32.5/65008&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/22996 to vlan702:192.168.32.5/65113&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/23012 to vlan702:192.168.32.5/65129&lt;/P&gt;&lt;P&gt;A#1/prod1#&lt;/P&gt;&lt;P&gt;A couple of seconds later it start over with low portnumbers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;A#1/prod1# sho xlate global 192.168.32.5&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/23673 to vlan702:192.168.32.5/1279&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/23728 to vlan702:192.168.32.5/1334&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/23984 to vlan702:192.168.32.5/1588&lt;/P&gt;&lt;P&gt;TCP PAT from vlan702:192.168.137.93/24113 to vlan702:192.168.32.5/63943&lt;/P&gt;&lt;P&gt;A#1/prod1#&lt;/P&gt;&lt;P&gt;This server has about 140 conn/sec at this moment, but under high load about 250 conn /sec.&lt;/P&gt;&lt;P&gt;As You can see from my show command, that the connectionstime are very short&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mats Ruuth&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 30 Sep 2011 11:02:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-pat-to-two-ip-number/m-p/1789739#M35482</guid>
      <dc:creator>mruuth</dc:creator>
      <dc:date>2011-09-30T11:02:50Z</dc:date>
    </item>
    <item>
      <title>ACE PAT to two IP-number</title>
      <link>https://community.cisco.com/t5/application-networking/ace-pat-to-two-ip-number/m-p/1789740#M35483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Mats-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Can you get a show tech for me?&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;@250 CPS, if connections were to hang around for more than 4 minutes, we would expect to see the other IP used - otherwise, ACE will just recycle the existing IP since it is using PAT and controlling the ports.&amp;nbsp; We can check some of the stats to see if it sees the other IP or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Oct 2011 16:36:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-pat-to-two-ip-number/m-p/1789740#M35483</guid>
      <dc:creator>chrhiggi</dc:creator>
      <dc:date>2011-10-03T16:36:58Z</dc:date>
    </item>
    <item>
      <title>Re: ACE PAT to two IP-number</title>
      <link>https://community.cisco.com/t5/application-networking/ace-pat-to-two-ip-number/m-p/1789741#M35484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris,&lt;/P&gt;&lt;P&gt;Connections are very shortlived, so no&amp;nbsp; connection stays longer than 4 minutes.&lt;/P&gt;&lt;P&gt;I have done a show tech and attached the file.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mats&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 06:24:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-pat-to-two-ip-number/m-p/1789741#M35484</guid>
      <dc:creator>mruuth</dc:creator>
      <dc:date>2011-10-05T06:24:05Z</dc:date>
    </item>
    <item>
      <title>Re: ACE PAT to two IP-number</title>
      <link>https://community.cisco.com/t5/application-networking/ace-pat-to-two-ip-number/m-p/1789742#M35485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Mats-&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ARP is up for both IPs:&lt;/P&gt;&lt;P&gt;192.168.32.5&amp;nbsp;&amp;nbsp;&amp;nbsp; 00.0b.fc.fe.1b.01&amp;nbsp; vlan702&amp;nbsp;&amp;nbsp; NAT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LOCAL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; _&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; up &lt;BR /&gt; - 192.168.32.6&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are the global stats:&lt;/P&gt;&lt;P&gt;NAT Pool Alloc [fail]:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 13498&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;NAT Pool Alloc [addr/port]:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 954879764&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 516&lt;BR /&gt;NAT Pool Free [addr/port]:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 954879609&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 515&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;NAT Pool Alloc [fail]:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 19584&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0&lt;BR /&gt;NAT Pool Alloc [addr/port]:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 954728191&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 298&lt;BR /&gt;NAT Pool Free [addr/port]:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 954728038&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 305&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something interesting to note - With NAT, there are 4 types - Static with/without pat and Dynamic with/without pat.&lt;/P&gt;&lt;P&gt;When PAT is not used, ACE times out the xlate in 3 hours by default.&amp;nbsp; When PAT is used, ACE times out the xlate when the connection closes. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to your stats - Some of the natpools ran out of resources at some point in time.&amp;nbsp; However, it has been .00001% of the total translations where that occured.&amp;nbsp; As you can see in the stats - the allocation vs. the purges are very, very close as expected because you are using PAT on all of your translations. If you were to exhaust the translations for a single IP, you would need to push 16000 cps @ 4 seconds long each. According to what you noted - this will never happen for your current setup.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 05 Oct 2011 17:09:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-pat-to-two-ip-number/m-p/1789742#M35485</guid>
      <dc:creator>chrhiggi</dc:creator>
      <dc:date>2011-10-05T17:09:30Z</dc:date>
    </item>
    <item>
      <title>Re: ACE PAT to two IP-number</title>
      <link>https://community.cisco.com/t5/application-networking/ace-pat-to-two-ip-number/m-p/1789743#M35486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Chris,&lt;/P&gt;&lt;P&gt;Thank you for your response to my question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mats&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;P.S. I want to rate this with three stars. How do I do that?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Oct 2011 06:03:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-pat-to-two-ip-number/m-p/1789743#M35486</guid>
      <dc:creator>mruuth</dc:creator>
      <dc:date>2011-10-06T06:03:46Z</dc:date>
    </item>
  </channel>
</rss>

