<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic SNA Enterprise Extender through ACE in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/sna-enterprise-extender-through-ace/m-p/1811219#M35803</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Best to open a case and we can take a close look. If you can email me the case number (&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:mwinnett@cisco.com"&gt;mwinnett@cisco.com&lt;/A&gt;&lt;SPAN&gt;), I'll pick it up.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 30 Jan 2012 15:35:32 GMT</pubDate>
    <dc:creator>mwinnett</dc:creator>
    <dc:date>2012-01-30T15:35:32Z</dc:date>
    <item>
      <title>SNA Enterprise Extender through ACE</title>
      <link>https://community.cisco.com/t5/application-networking/sna-enterprise-extender-through-ace/m-p/1811214#M35798</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any experience configuring ACE to NAT and forward SNA Enterprise Extender traffic?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Dec 2011 11:52:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/sna-enterprise-extender-through-ace/m-p/1811214#M35798</guid>
      <dc:creator>Fernando Sacristan Navarro</dc:creator>
      <dc:date>2011-12-28T11:52:48Z</dc:date>
    </item>
    <item>
      <title>SNA Enterprise Extender through ACE</title>
      <link>https://community.cisco.com/t5/application-networking/sna-enterprise-extender-through-ace/m-p/1811215#M35799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Fernando&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I set this up in the lab and I can't get the EE peers to connect. EE uses UDP 12000-12005. The initial XID exchange uses UDP 12000. Connecting from the EE client to the vip, you can see that the ACE NATs the dest-ip towards the rserver, it also takes a source port from the ephemeral range. Client is 1.2.1.1, vip 1.9.1.209, rserver 1.3.1.5. Note that the EE server responds to port 12000 (not 28192)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cdn-ace-1/mwinnett# cap msw start&lt;/P&gt;&lt;P&gt;17:17:31.733579 0:13:60:30:fe:89 0:b:fc:fe:1b:cc 0800 45: 1.2.1.1.12000 &amp;gt; 1.9.1.209.12000:&amp;nbsp; [udp sum ok] udp 3 [tos 0xc0]&amp;nbsp; (ttl 254, id 43876, len 31)&lt;/P&gt;&lt;P&gt;17:17:31.733751 0:b:fc:fe:1b:cc 0:13:60:30:fe:89 0800 45: 1.2.1.1.28192 &amp;gt; 1.3.1.5.12000:&amp;nbsp; [bad udp cksum c191!] udp 3 [tos 0xc0]&amp;nbsp; (ttl 254, id 43876, len 31, bad cksum bcd!)&lt;/P&gt;&lt;P&gt;17:17:31.736979 0:13:60:30:fe:89 0:b:fc:fe:1b:cc 0800 45: 1.3.1.5.12000 &amp;gt; 1.2.1.1.12000:&amp;nbsp; [udp sum ok] udp 3 [tos 0xc0]&amp;nbsp; (ttl 254, id 1815, len 31)&lt;/P&gt;&lt;P&gt;17:17:31.737134 0:b:fc:fe:1b:cc 0:13:60:30:fe:89 0800 45: 1.3.1.5.12000 &amp;gt; 1.2.1.1.12000:&amp;nbsp; [udp sum ok] udp 3 [tos 0xc0]&amp;nbsp; (ttl 254, id 1815, len 31)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, when I check back at the EE client, you can see that the source IP address is not natted&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;*Jan 13 17:25:30.407 METDST: IP: tableid=0, s=1.3.1.5 (Tunnel99), d=1.2.1.1 (Tunnel99), routed via RIB&lt;/P&gt;&lt;P&gt;*Jan 13 17:25:30.411 METDST: IP: s=1.3.1.5 (Tunnel99), d=1.2.1.1 (Tunnel99), len 31, rcvd 3&lt;/P&gt;&lt;P&gt;4420A410: 45C0001F 08160000 FC11B1ED 01030105&amp;nbsp; E@......|.1m....&lt;/P&gt;&lt;P&gt;4420A420: 01020101 2EE02EE0 000BDB07 0405BF&amp;nbsp;&amp;nbsp;&amp;nbsp; .....`.`..[...? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is that the EE server does not respect the incoming source port and uses 12000 instead. This means that the ACE will not NAT the response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you give more details of what you are trying to achieve ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matthew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 13 Jan 2012 16:36:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/sna-enterprise-extender-through-ace/m-p/1811215#M35799</guid>
      <dc:creator>mwinnett</dc:creator>
      <dc:date>2012-01-13T16:36:14Z</dc:date>
    </item>
    <item>
      <title>SNA Enterprise Extender through ACE</title>
      <link>https://community.cisco.com/t5/application-networking/sna-enterprise-extender-through-ace/m-p/1811216#M35800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Matthew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your answer. Could you send me the configuration you used on your lab?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fernando&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jan 2012 11:45:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/sna-enterprise-extender-through-ace/m-p/1811216#M35800</guid>
      <dc:creator>Fernando Sacristan Navarro</dc:creator>
      <dc:date>2012-01-23T11:45:44Z</dc:date>
    </item>
    <item>
      <title>SNA Enterprise Extender through ACE</title>
      <link>https://community.cisco.com/t5/application-networking/sna-enterprise-extender-through-ace/m-p/1811217#M35801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Fernando&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nothing really magic here. I uses Cisco snasw routers as client and server and the issues that I encountered relating to port usage are probably specific to how we implement EE. Bearing mind that the basis of our Snasw implementation is the same as that used by the MS Sna server, its likely that any other implementation will have the same issues.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want to share more details of what you are trying to achieve, maybe I can help further.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matthew&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list anyany line 10 extended permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;probe icmp ping-test&lt;/P&gt;&lt;P&gt;&amp;nbsp; interval 20&lt;/P&gt;&lt;P&gt;&amp;nbsp; faildetect 2&lt;/P&gt;&lt;P&gt;&amp;nbsp; passdetect interval 20&lt;/P&gt;&lt;P&gt;&amp;nbsp; passdetect count 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host dymock&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 1.3.1.5&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host kilcot&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 1.3.1.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host snas-serverfarm&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe ping-test&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver dymock&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver kilcot&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type management match-any remote-mgmt&lt;/P&gt;&lt;P&gt;&amp;nbsp; 10 match protocol ssh any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 20 match protocol telnet any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 30 match protocol icmp any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 40 match protocol http any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 50 match protocol https any&lt;/P&gt;&lt;P&gt;class-map match-all snasw-class&lt;/P&gt;&lt;P&gt;&amp;nbsp; 10 match virtual-address 1.9.1.209 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type management first-match remote-access&lt;/P&gt;&lt;P&gt;&amp;nbsp; class remote-mgmt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match round-robin-snasw&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm snas-serverfarm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match lb-vip&lt;/P&gt;&lt;P&gt;&amp;nbsp; class snasw-class&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy round-robin-snasw&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 468&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Server vlan&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 1.8.1.201 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; alias 1.8.1.200 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; peer ip address 1.8.1.202 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input anyany&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input remote-access&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;interface vlan 469&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Client vlan&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 1.9.1.201 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; alias 1.9.1.200 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; peer ip address 1.9.1.202 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input anyany&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input remote-access&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input lb-vip&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 1.2.1.0 255.255.255.0 1.9.1.211&lt;/P&gt;&lt;P&gt;ip route 1.3.1.0 255.255.255.0 1.8.1.211&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jan 2012 12:32:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/sna-enterprise-extender-through-ace/m-p/1811217#M35801</guid>
      <dc:creator>mwinnett</dc:creator>
      <dc:date>2012-01-23T12:32:54Z</dc:date>
    </item>
    <item>
      <title>SNA Enterprise Extender through ACE</title>
      <link>https://community.cisco.com/t5/application-networking/sna-enterprise-extender-through-ace/m-p/1811218#M35802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Matthew,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below you can see our configuration. As you can see, we perform a NAT for the connections exiting vlans 61 and 150.&lt;/P&gt;&lt;P&gt;The SNA traffic is load balanaced, bu it's extremely slow, making impossible to work with the application:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;probe icmp ICMP_SARA&lt;BR /&gt;&amp;nbsp; interval 20&lt;BR /&gt;&amp;nbsp; faildetect 2&lt;BR /&gt;&amp;nbsp; passdetect interval 20&lt;BR /&gt;&amp;nbsp; passdetect count 2&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host ls60ca&lt;BR /&gt;&amp;nbsp; ip address 172.20.1.221&lt;BR /&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host CL4_udp_SARA&lt;BR /&gt; probe ICMP_SARA &lt;BR /&gt;&amp;nbsp; rserver ls60ca&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;BR /&gt;&amp;nbsp; &lt;BR /&gt;class-map match-any sal_ls60ca&lt;BR /&gt;&amp;nbsp; 2 match source-address 172.20.1.221 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-any vip_CL4_udp_SARA&lt;BR /&gt;&amp;nbsp; 4 match virtual-address 10.25.23.221 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match LB_CL4_udp_SARA&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm CL4_udp_SARA&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match INT_150&lt;BR /&gt;class vip_CL4_udp_SARA insert-before FW1_SEC_VIP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy LB_CL4_udp_SARA&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip advertise active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match INT_61&lt;BR /&gt;class vip_CL4_udp_SARA insert-before FW1_SEC_VIP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy LB_CL4_udp_SARA&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip advertise active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match SNATS_150&lt;BR /&gt; class sal_ls60ca&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 73 vlan 61&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 75 vlan 150&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 61&lt;/P&gt;&lt;P&gt;service-policy input INT_61&lt;BR /&gt;nat-pool 73 10.25.23.221 10.25.23.221 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 150&lt;/P&gt;&lt;P&gt;service-policy input INT_150&lt;BR /&gt;nat-pool 75 10.25.23.221 10.25.23.221 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any suggestions,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Nando&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 23 Jan 2012 14:39:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/sna-enterprise-extender-through-ace/m-p/1811218#M35802</guid>
      <dc:creator>Fernando Sacristan Navarro</dc:creator>
      <dc:date>2012-01-23T14:39:42Z</dc:date>
    </item>
    <item>
      <title>SNA Enterprise Extender through ACE</title>
      <link>https://community.cisco.com/t5/application-networking/sna-enterprise-extender-through-ace/m-p/1811219#M35803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN&gt;Best to open a case and we can take a close look. If you can email me the case number (&lt;/SPAN&gt;&lt;A class="jive-link-email-small" href="mailto:mwinnett@cisco.com"&gt;mwinnett@cisco.com&lt;/A&gt;&lt;SPAN&gt;), I'll pick it up.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jan 2012 15:35:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/sna-enterprise-extender-through-ace/m-p/1811219#M35803</guid>
      <dc:creator>mwinnett</dc:creator>
      <dc:date>2012-01-30T15:35:32Z</dc:date>
    </item>
    <item>
      <title>SNA Enterprise Extender through ACE</title>
      <link>https://community.cisco.com/t5/application-networking/sna-enterprise-extender-through-ace/m-p/1811220#M35804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Matthew,&lt;/P&gt;&lt;P&gt; Nowadays, the contract that we have with our Cisco supplier&amp;nbsp; do not includes this kind of issues, it's just a hardware replacement contract. Anyway, I'm gonna try to convince them to open the case.&lt;/P&gt;&lt;P&gt;As soon as I have any feedback, I'll inform you. &lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jan 2012 16:43:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/sna-enterprise-extender-through-ace/m-p/1811220#M35804</guid>
      <dc:creator>Fernando Sacristan Navarro</dc:creator>
      <dc:date>2012-01-30T16:43:10Z</dc:date>
    </item>
  </channel>
</rss>

