<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSS11503 &amp; WebLogic Cluster in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/css11503-weblogic-cluster/m-p/246357#M3554</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like we've gotten this resolved. It was a routing issue on the two webserver machines. Guess I'm still a little confused as to how to monitor traffic leaving the CSS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Brett&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Apr 2004 20:44:45 GMT</pubDate>
    <dc:creator />
    <dc:date>2004-04-08T20:44:45Z</dc:date>
    <item>
      <title>CSS11503 &amp; WebLogic Cluster</title>
      <link>https://community.cisco.com/t5/application-networking/css11503-weblogic-cluster/m-p/246354#M3551</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to get a configuration working for our CSS11503 and I'm pretty lost on what I need to do. I'm primarily a application developer/WebLogic admin so I have some understanding of networking but general at best.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What we're trying to accomplish is to establish connectivity through the CSS to a WebLogic cluster. Currently it doesn't look like anything is going through the CSS at all. So, how do I diagnose traffic coming into the CSS? I've turned logging levels to debug-7 and do see some traffic coming in from the outside interface but it shows it as a DOS attack?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is our current configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS11503(config)# show running-config&lt;/P&gt;&lt;P&gt;!Generated on 04/08/2004 07:51:38&lt;/P&gt;&lt;P&gt;!Active version: sg0710405&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;configure&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!*************************** GLOBAL ***************************&lt;/P&gt;&lt;P&gt;  no restrict web-mgmt&lt;/P&gt;&lt;P&gt;  sntp server 149.83.131.15 version 1&lt;/P&gt;&lt;P&gt;  cdp run&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  logging subsystem ipv4 level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem syssoft level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem buffer level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem flowmgr level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem radius level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem wcc level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem chassis level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem vlanmgr level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem netman level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem app level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem rip level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem ospf level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem sntp level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem dhcp level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem vrrp level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem redundancy level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem csdpeer level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem portmapper level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem acl level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem circuit level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem security level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem fac level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem vpm level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem publish level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem keepalive level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem urql level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem nql level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem dql level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem pcm level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem proximity level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem hfg level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem replicate level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem boomerang level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem fp-driver level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem flowagent level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem cdp level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem slr level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem natmgr level debug-7&lt;/P&gt;&lt;P&gt;  logging subsystem ssl-accel level debug-7&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  ip route 0.0.0.0 0.0.0.0 206.88.44.254 1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!************************* INTERFACE *************************&lt;/P&gt;&lt;P&gt;interface Ethernet-Mgmt&lt;/P&gt;&lt;P&gt;  description "Management Access"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface  2/1&lt;/P&gt;&lt;P&gt;  description "web-cluster-server1"&lt;/P&gt;&lt;P&gt;  bridge vlan 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface  2/2&lt;/P&gt;&lt;P&gt;  description "web-cluster-server2"&lt;/P&gt;&lt;P&gt;  bridge vlan 10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface  2/8&lt;/P&gt;&lt;P&gt;  description "Outside-DMZ...206.88.44.225"&lt;/P&gt;&lt;P&gt;  bridge vlan 11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!************************** CIRCUIT **************************&lt;/P&gt;&lt;P&gt;circuit VLAN1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  ip address 206.88.45.225 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;circuit VLAN10&lt;/P&gt;&lt;P&gt;  description "web-cluster"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  ip address 10.1.1.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;circuit VLAN11&lt;/P&gt;&lt;P&gt;  description "Outside-DMZ"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  ip address 206.88.44.225 255.255.255.0&lt;/P&gt;&lt;P&gt;    ip virtual-router 1 priority 110 preempt&lt;/P&gt;&lt;P&gt;    ip redundant-vip 1 206.88.44.226&lt;/P&gt;&lt;P&gt;    ip critical-service 1 upstream&lt;/P&gt;&lt;P&gt;    ip critical-service 1 webserver1&lt;/P&gt;&lt;P&gt;    ip critical-service 1 webserver2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!************************** SERVICE **************************&lt;/P&gt;&lt;P&gt;service upstream&lt;/P&gt;&lt;P&gt;  ip address 206.88.44.254&lt;/P&gt;&lt;P&gt;  type redundancy-up&lt;/P&gt;&lt;P&gt;  active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service webserver1&lt;/P&gt;&lt;P&gt;  ip address 10.1.1.1&lt;/P&gt;&lt;P&gt;  active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service webserver2&lt;/P&gt;&lt;P&gt;  ip address 10.1.1.2&lt;/P&gt;&lt;P&gt;  active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;!*************************** OWNER ***************************&lt;/P&gt;&lt;P&gt;owner ADP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  content RuleForVIP1&lt;/P&gt;&lt;P&gt;    vip address 206.88.44.226&lt;/P&gt;&lt;P&gt;    balance leastconn&lt;/P&gt;&lt;P&gt;    add service webserver1&lt;/P&gt;&lt;P&gt;    add service webserver2&lt;/P&gt;&lt;P&gt;    active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I should be able to talk to the two servers listening on 10.1.1.1:7003 and 10.1.1.2:7003.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;-Brett&lt;/P&gt;</description>
      <pubDate>Thu, 08 Apr 2004 14:03:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css11503-weblogic-cluster/m-p/246354#M3551</guid>
      <dc:creator>admin_2</dc:creator>
      <dc:date>2004-04-08T14:03:30Z</dc:date>
    </item>
    <item>
      <title>Re: CSS11503 &amp; WebLogic Cluster</title>
      <link>https://community.cisco.com/t5/application-networking/css11503-weblogic-cluster/m-p/246355#M3552</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Brett,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Well, first off, if you are going to have a redundant VIP I am assuming there are 2 CSSs here.  We need to make sure the server responses come back through the same CSS that is active for the VIP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can see who is active the the VIP by typing&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"show redundant-vip"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You do not have any redundant IP on the server side, so is the gateway of the servers 10.1.1.254?  What is the IP of the other CSSs circuit?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Typically, there is a redundant IP on the server side so we can fail over the server's gateway when we fail over the VIP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To see connections to that VIP you can see the hits increment by typing "show summary".  Show flow will show current flows, but HTTP flows are typically pretty quick and you are likely to miss them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Steve&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Apr 2004 17:20:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css11503-weblogic-cluster/m-p/246355#M3552</guid>
      <dc:creator>stevehall</dc:creator>
      <dc:date>2004-04-08T17:20:35Z</dc:date>
    </item>
    <item>
      <title>Re: CSS11503 &amp; WebLogic Cluster</title>
      <link>https://community.cisco.com/t5/application-networking/css11503-weblogic-cluster/m-p/246356#M3553</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Steve, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the response. Our eventual configuration will have 2 CSS's but only one today.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show redundant-vip&lt;/P&gt;&lt;P&gt;Redundant-Vips:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; Interface Address: 206.88.44.225    VRID: 1&lt;/P&gt;&lt;P&gt;  Redundant Address: 206.88.44.226      Range:       1&lt;/P&gt;&lt;P&gt;  State:             Master             Master IP:   206.88.44.225&lt;/P&gt;&lt;P&gt;  State Changes:     3                  Last Change: 04/07/2004 10:39:01&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Show summary does show hits coming in and with debugging turned on I'm seeing messages like the following.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;APR  8 12:56:23 1/1 1377 FLOWMGR-7:&lt;/P&gt;&lt;P&gt;DoS SYN attack: 206.88.41.248:2304-&amp;gt;206.88.44.226:7003&lt;/P&gt;&lt;P&gt;synCnt: 3, initSeq: 2257383471&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this dropping/preventing the packets from routing to the 10.1.1.x network? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Default gateway for the webservers is the 10.1.1.254 address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Brett&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Apr 2004 19:12:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css11503-weblogic-cluster/m-p/246356#M3553</guid>
      <dc:creator />
      <dc:date>2004-04-08T19:12:12Z</dc:date>
    </item>
    <item>
      <title>Re: CSS11503 &amp; WebLogic Cluster</title>
      <link>https://community.cisco.com/t5/application-networking/css11503-weblogic-cluster/m-p/246357#M3554</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Looks like we've gotten this resolved. It was a routing issue on the two webserver machines. Guess I'm still a little confused as to how to monitor traffic leaving the CSS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-Brett&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Apr 2004 20:44:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css11503-weblogic-cluster/m-p/246357#M3554</guid>
      <dc:creator />
      <dc:date>2004-04-08T20:44:45Z</dc:date>
    </item>
  </channel>
</rss>

