<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACE Multi-Context Shared VLAN? in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802471#M35663</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Got it, thanks Cesar.&amp;nbsp; The difference is that you are running One-Arm Mode on both contexts.&amp;nbsp; I will be in-line routed mode, so if I understand properly I will need to have separate client VLANS for both contexts in order to avoid this problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 14 Sep 2011 16:58:10 GMT</pubDate>
    <dc:creator>davemit</dc:creator>
    <dc:date>2011-09-14T16:58:10Z</dc:date>
    <item>
      <title>ACE Multi-Context Shared VLAN?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802461#M35653</link>
      <description>&lt;P&gt;I will be deploying the ACE with two virtual contexts in routed mode.&amp;nbsp; Each context will have its own separate server VLAN, but I am wondering if I can share the Client side VLAN&amp;nbsp; between contexts?&amp;nbsp; Is this possible, or does each context need it's own client VLAN for routing back to the network core?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was planning on using VIPs selected from the Client VLAN subnet.&amp;nbsp; If I do share that VLAN between two contexts, would there be any issues with each context responding correctly to the VIP's configured on it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks! &lt;/P&gt;</description>
      <pubDate>Tue, 13 Sep 2011 19:32:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802461#M35653</guid>
      <dc:creator>davemit</dc:creator>
      <dc:date>2011-09-13T19:32:34Z</dc:date>
    </item>
    <item>
      <title>ACE Multi-Context Shared VLAN?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802462#M35654</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can use the same VLAN on different Context but each Context should have its own IP address. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://tools.cisco.com/squish/880AF"&gt;http://tools.cisco.com/squish/880AF&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cesar R&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Sep 2011 20:58:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802462#M35654</guid>
      <dc:creator>Cesar Roque</dc:creator>
      <dc:date>2011-09-13T20:58:29Z</dc:date>
    </item>
    <item>
      <title>ACE Multi-Context Shared VLAN?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802463#M35655</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the answer.&amp;nbsp; Are there any issues with the two contexts responding to VIP's when they're assigned from the shared client VLAN?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 13 Sep 2011 22:47:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802463#M35655</guid>
      <dc:creator>davemit</dc:creator>
      <dc:date>2011-09-13T22:47:41Z</dc:date>
    </item>
    <item>
      <title>ACE Multi-Context Shared VLAN?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802464#M35656</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yes, you can not access the VIP on context A from context B. Or the VIP of context B from context A. That's forbidden by security reasons.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Sep 2011 06:39:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802464#M35656</guid>
      <dc:creator>Marko Leopold</dc:creator>
      <dc:date>2011-09-14T06:39:09Z</dc:date>
    </item>
    <item>
      <title>ACE Multi-Context Shared VLAN?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802465#M35657</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What do you mean by "can not access the VIP"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If servers behind Context A need to talk to a VIP in Context B, will it not work in this scenario?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Sep 2011 12:41:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802465#M35657</guid>
      <dc:creator>davemit</dc:creator>
      <dc:date>2011-09-14T12:41:11Z</dc:date>
    </item>
    <item>
      <title>ACE Multi-Context Shared VLAN?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802466#M35658</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Yep, you are right. Cisco says its forbidden by security reasons. So if you want them to talk together you better use two seperate VLANs.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Sep 2011 12:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802466#M35658</guid>
      <dc:creator>Marko Leopold</dc:creator>
      <dc:date>2011-09-14T12:58:34Z</dc:date>
    </item>
    <item>
      <title>ACE Multi-Context Shared VLAN?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802467#M35659</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Wow, okay thanks.&amp;nbsp; I will definitely set up separate VLANs for this!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Sep 2011 13:05:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802467#M35659</guid>
      <dc:creator>davemit</dc:creator>
      <dc:date>2011-09-14T13:05:57Z</dc:date>
    </item>
    <item>
      <title>ACE Multi-Context Shared VLAN?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802468#M35660</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello David&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is correct.&amp;nbsp; however, a easy way to fix this and still using the same VLAN is configuring the servers in both Context. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cesar R.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Sep 2011 13:27:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802468#M35660</guid>
      <dc:creator>Cesar Roque</dc:creator>
      <dc:date>2011-09-14T13:27:49Z</dc:date>
    </item>
    <item>
      <title>ACE Multi-Context Shared VLAN?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802469#M35661</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Huh?&amp;nbsp; The Real Servers are in separate VLANS (one in each Context).&amp;nbsp; How would I "configure the servers in both contexts"?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Sep 2011 13:43:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802469#M35661</guid>
      <dc:creator>davemit</dc:creator>
      <dc:date>2011-09-14T13:43:03Z</dc:date>
    </item>
    <item>
      <title>ACE Multi-Context Shared VLAN?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802470#M35662</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To expalin this better, I have this two Contexts:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context test&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface vlan 144&lt;/P&gt;&lt;P&gt;&amp;nbsp; member test&lt;/P&gt;&lt;P&gt;context test2&lt;/P&gt;&lt;P&gt;&amp;nbsp; allocate-interface vlan 144&lt;/P&gt;&lt;P&gt;&amp;nbsp; member test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config of test is this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host test&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.198.16.93&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host test&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver test&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all test&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 10.198.44.180 tcp any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match test&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match test1&lt;/P&gt;&lt;P&gt;&amp;nbsp; class test&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy test&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 144&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 144&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.198.44.150 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input Allow_Access&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 1 10.198.44.180 10.198.44.180 netmask 255.255.255.0 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input NSS_MGMT&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input test1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.198.44.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The config of test2 is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host test&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.198.44.24&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host test&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver test&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all test&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 10.198.44.181 tcp any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match test&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm test&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match test1&lt;/P&gt;&lt;P&gt;&amp;nbsp; class test&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy test&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 144&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 144&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.198.44.160 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input Allow_Access&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 1 10.198.44.181 10.198.44.181 netmask 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input NSS_MGMT&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input test1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.198.44.4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the rserver 10.198.44.24, I can get to the VIP of&amp;nbsp; Context test 10.198.44.180.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the output:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE-M3/test# sh conn&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;total current connections : 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conn-id&amp;nbsp;&amp;nbsp;&amp;nbsp; np dir proto vlan source&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state&lt;/P&gt;&lt;P&gt;----------+--+---+-----+----+---------------------+---------------------+------+&lt;/P&gt;&lt;P&gt;2584127&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp; in&amp;nbsp; TCP&amp;nbsp;&amp;nbsp; 144&amp;nbsp; 10.198.44.24:52872&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.198.44.180:80&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ESTAB&lt;/P&gt;&lt;P&gt;2584134&amp;nbsp;&amp;nbsp;&amp;nbsp; 2&amp;nbsp; out TCP&amp;nbsp;&amp;nbsp; 144&amp;nbsp; 10.198.16.93:80&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.198.44.180:1029&amp;nbsp;&amp;nbsp;&amp;nbsp; ESTAB&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The condition here is that the ACE is not the default gateway of the servers.&amp;nbsp; There is another L3 device that routes the traffic to the VIP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cesar R&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Sep 2011 14:39:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802470#M35662</guid>
      <dc:creator>Cesar Roque</dc:creator>
      <dc:date>2011-09-14T14:39:52Z</dc:date>
    </item>
    <item>
      <title>ACE Multi-Context Shared VLAN?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802471#M35663</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Got it, thanks Cesar.&amp;nbsp; The difference is that you are running One-Arm Mode on both contexts.&amp;nbsp; I will be in-line routed mode, so if I understand properly I will need to have separate client VLANS for both contexts in order to avoid this problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 14 Sep 2011 16:58:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802471#M35663</guid>
      <dc:creator>davemit</dc:creator>
      <dc:date>2011-09-14T16:58:10Z</dc:date>
    </item>
    <item>
      <title>ACE Multi-Context Shared VLAN?</title>
      <link>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802472#M35664</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can add a host route for the VIP of the other context via the upstream router on the context you want access from - it works (but its a bodge that relies on redirects and chews bandwidth!). Also if you run one context on one appliance in a HA pair, and the other context on another is another even bigger bodge that also works. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Re-address to non shared client VLAN is really the only solid way as you say.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Dec 2011 03:32:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-multi-context-shared-vlan/m-p/1802472#M35664</guid>
      <dc:creator>nickjacobs</dc:creator>
      <dc:date>2011-12-21T03:32:39Z</dc:date>
    </item>
  </channel>
</rss>

