<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ace Plattoform: dynamic nat in bridge mode in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895095#M36799</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dino, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How does the traffic reach your ACE? I mean, does it have to pass through VLAN 161 first ( acting like client vlan) or via VLAN 160?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is the traffic supposed to start? From the servers to the VIP to go back to the servers? Start from the servers to go to the cloud? Coming from the cloud to go the servers?, based on what you are looking is how nat should be configured and more important where it should be configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 May 2012 00:56:51 GMT</pubDate>
    <dc:creator>Jorge Bejarano</dc:creator>
    <dc:date>2012-05-22T00:56:51Z</dc:date>
    <item>
      <title>Ace Plattoform: dynamic nat in bridge mode</title>
      <link>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895090#M36794</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm working with ACE10-6500-K9 plattform (Version A2(3.0) ) and customer needs to balance SMTP Application Server....&lt;/P&gt;&lt;P&gt;the request it's not so easy: the Ace load balance are working in bridge mode and if a rserver creates a SMTP new connection (such a client) to external network, it's doesn't use rserver ip address but &lt;STRONG style="text-decoration: underline; "&gt;VIP ip address &lt;/STRONG&gt;that we are using for load balancing SMTP multimatch policy.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I attach a Network layout/ diagram flow and ace configuration&amp;nbsp; to explain better my request.&lt;/P&gt;&lt;P&gt;Regarding Cisco documentation i used dynamic NAT for this type of configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="active_link" href="http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/security/guide/nat.html#wp1087493"&gt;http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/security/guide/nat.html#wp1087493&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1.Is it possible use dynamic configuration NAT in Bridge mode enviroment?&lt;/P&gt;&lt;P&gt;2. Searching in ciscco support community, someone say that the request could be solved with DSR (direct server return) solution.What do you think ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue is that&amp;nbsp; I cannot see xlate transaction and SMTP server exposes its ip address (rserver ip address).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the txt file there are typical output that i use for troubleshooting problem (show xlate and show service policy).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Dino&lt;/P&gt;</description>
      <pubDate>Fri, 18 May 2012 08:10:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895090#M36794</guid>
      <dc:creator>dinoantonucci</dc:creator>
      <dc:date>2012-05-18T08:10:18Z</dc:date>
    </item>
    <item>
      <title>Ace Plattoform: dynamic nat in bridge mode</title>
      <link>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895091#M36795</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; just checked your config and diagram, one thing i found suspecting is nat-pool configured on wrong vlan. it should be configured on vlan 160 rather then vlan 161. you have configured NAt statement correctly but pool is created in wrong interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;also attach a "show conn" outout with detail for a server intiated connection for further troublshooting.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 May 2012 07:01:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895091#M36795</guid>
      <dc:creator>gaursin2</dc:creator>
      <dc:date>2012-05-20T07:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Ace Plattoform: dynamic nat in bridge mode</title>
      <link>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895092#M36796</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Than you for response,&lt;/P&gt;&lt;P&gt;i modify the confguration as you suggest, but nothing is change.&lt;/P&gt;&lt;P&gt;I share "configuration modified" and show conn.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Bye.&lt;/P&gt;&lt;P&gt;Dino&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 20 May 2012 16:13:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895092#M36796</guid>
      <dc:creator>dinoantonucci</dc:creator>
      <dc:date>2012-05-20T16:13:35Z</dc:date>
    </item>
    <item>
      <title>Re: Ace Plattoform: dynamic nat in bridge mode</title>
      <link>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895093#M36797</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can you again confirm from your configuration that "&lt;/P&gt;&lt;P&gt;nat-pool 199 10.161.1.199 10.161.1.199 netmask 255.255.0.0 pat" command is under vlan 160,&lt;/P&gt;&lt;P&gt; its not very clear from your updated configuration&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2012 00:45:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895093#M36797</guid>
      <dc:creator>gaursin2</dc:creator>
      <dc:date>2012-05-21T00:45:50Z</dc:date>
    </item>
    <item>
      <title>Re: Ace Plattoform: dynamic nat in bridge mode</title>
      <link>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895094#M36798</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;i confirm it. &lt;/P&gt;&lt;P&gt;What do you mean ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;Dino&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2012 12:23:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895094#M36798</guid>
      <dc:creator>dinoantonucci</dc:creator>
      <dc:date>2012-05-21T12:23:41Z</dc:date>
    </item>
    <item>
      <title>Re: Ace Plattoform: dynamic nat in bridge mode</title>
      <link>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895095#M36799</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dino, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How does the traffic reach your ACE? I mean, does it have to pass through VLAN 161 first ( acting like client vlan) or via VLAN 160?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Where is the traffic supposed to start? From the servers to the VIP to go back to the servers? Start from the servers to go to the cloud? Coming from the cloud to go the servers?, based on what you are looking is how nat should be configured and more important where it should be configured.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2012 00:56:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895095#M36799</guid>
      <dc:creator>Jorge Bejarano</dc:creator>
      <dc:date>2012-05-22T00:56:51Z</dc:date>
    </item>
    <item>
      <title>Re: Ace Plattoform: dynamic nat in bridge mode</title>
      <link>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895096#M36800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jorge,&lt;/P&gt;&lt;P&gt;as described in sequence number process, i'm working on outside flow: server smtp to cloud for sending notification mail.&lt;/P&gt;&lt;P&gt;So Customer requirements needs to nat rserver with VIP address when SMTP server send an email to internet client!&lt;/P&gt;&lt;P&gt;In summary there are two different type of flow:&lt;/P&gt;&lt;P&gt;1. Load balancing SMTP services : internet client to VIP STMP (we have no problem)!!!!&lt;/P&gt;&lt;P&gt;2. STMP Server (like a client) send an email notification to internet client. In this case outside&amp;nbsp; server request must be nat with VIP Address. (here there is the issue)!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dino&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2012 07:43:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895096#M36800</guid>
      <dc:creator>dinoantonucci</dc:creator>
      <dc:date>2012-05-22T07:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: Ace Plattoform: dynamic nat in bridge mode</title>
      <link>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895097#M36801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Dino,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From connection table and from your topolgy also, we can see server intiated connection comes in via vlan 161 and goes out via 160.&amp;nbsp; Also you nat policy saying "&lt;SPAN style="font-size: 12pt;"&gt;nat dynamic 199 vlan 160", t&lt;/SPAN&gt;hats why i asked for applying nat pool statement "nat-pool 199 10.161.1.199 10.161.1.199 netmask 255.255.0.0 pat" on vlan 160 rather then 161.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you have said that this has been done and added the modified configuration, but still there i couldn't see the same. thats why&amp;nbsp; i ask for your confirmation whether same has been done or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also attach one more output for desire show service-policy detail.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2012 08:30:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895097#M36801</guid>
      <dc:creator>gaursin2</dc:creator>
      <dc:date>2012-05-22T08:30:03Z</dc:date>
    </item>
    <item>
      <title>Re: Ace Plattoform: dynamic nat in bridge mode</title>
      <link>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895098#M36802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here you have a sample of servers initiation:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all REAL_SERVERS&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match source-address 192.168.1.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all VIP-30&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 172.16.51.30 tcp eq www&lt;/P&gt;&lt;P&gt;=====================================&lt;/P&gt;&lt;P&gt;policy-map multi-match CLIENT_VIPS&lt;/P&gt;&lt;P&gt;&amp;nbsp; class VIP-30&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy SLB_LOGIC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp; class REAL_SERVERS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 10 vlan 251&lt;/P&gt;&lt;P&gt;=====================================&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match SLB_LOGIC&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm REAL_SERVERS&lt;/P&gt;&lt;P&gt;=====================================&lt;/P&gt;&lt;P&gt;serverfarm host REAL_SERVERS&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver SERVER_01&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver SERVER_02&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver SERVER_03&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;=====================================&lt;/P&gt;&lt;P&gt;rserver host SERVER_01&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 192.168.1.11&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host SERVER_02&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 192.168.1.12&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host SERVER_03&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 192.168.1.13&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;=====================================&lt;/P&gt;&lt;P&gt;interface vlan 251&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Client vlan&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 172.16.51.11 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input ANYONE&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input REMOTE_MGT&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input CLIENT_VIPS&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 10 172.16.51.10 172.16.51.10 netmask 255.255.255.0 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;=====================================&lt;/P&gt;&lt;P&gt;interface vlan 451&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Servers vlan&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 192.168.1.1 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input ANYONE&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input CLIENT_VIPS&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 1 192.168.1.10 192.168.1.10 netmask 255.255.255.0 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 May 2012 00:18:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-plattoform-dynamic-nat-in-bridge-mode/m-p/1895098#M36802</guid>
      <dc:creator>Jorge Bejarano</dc:creator>
      <dc:date>2012-05-24T00:18:35Z</dc:date>
    </item>
  </channel>
</rss>

