<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACE Complex Design in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971142#M37619</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is same as you have used in client VLAN interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something like this &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Admin(config-if)# service-policy input vippolicy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case if you still have confusion attach the running config and let me know the VIP IP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards, &lt;/P&gt;&lt;P&gt;Ajay Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 24 Jun 2012 12:54:44 GMT</pubDate>
    <dc:creator>ajayku2</dc:creator>
    <dc:date>2012-06-24T12:54:44Z</dc:date>
    <item>
      <title>ACE Complex Design</title>
      <link>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971138#M37615</link>
      <description>&lt;P&gt;Guys,&lt;BR /&gt;I am facing some problems with my ACE design and would like or thoughts and feedback on this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I have an ACE with a client side and a Server Farm interface.&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;The client side layer 3 interfaces resides on the core backbone and the Server Farm layer 3 interface is behind a Firewall.&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;We have a two other servers load balanced located in the server farm and loadbalaced using Cisco ACE ( using a VIP Client Side IP).&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is what we are facing:&lt;/P&gt;&lt;P&gt;The load balancing is working correctly when traffic is coming from any other subnet other than the server farm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In other words Loadbalancing is not working with VIP IP for servers that reside in the server farm since there is a serverfarm interface on the ACE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have a clue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hesham&lt;/P&gt;</description>
      <pubDate>Sun, 24 Jun 2012 12:02:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971138#M37615</guid>
      <dc:creator>helsayed78</dc:creator>
      <dc:date>2012-06-24T12:02:24Z</dc:date>
    </item>
    <item>
      <title>ACE Complex Design</title>
      <link>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971139#M37616</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hesham, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The solution is quite easy apply multimatch policy for the VIP in the serverfarm VLAN interface. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This will fix the issue. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When traffic hit the interface it match the class map and use the policy applied on that interface for loadbalancing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Since you have not applied any policy on the server vlan interface it is not going to do any load balancing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope it helps. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards, &lt;/P&gt;&lt;P&gt;Ajay Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jun 2012 12:20:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971139#M37616</guid>
      <dc:creator>ajayku2</dc:creator>
      <dc:date>2012-06-24T12:20:27Z</dc:date>
    </item>
    <item>
      <title>ACE Complex Design</title>
      <link>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971140#M37617</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You mean under the Server Farm VLAN ??&amp;nbsp; and what is the exact syntax that should be used?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hesham&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jun 2012 12:43:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971140#M37617</guid>
      <dc:creator>helsayed78</dc:creator>
      <dc:date>2012-06-24T12:43:04Z</dc:date>
    </item>
    <item>
      <title>ACE Complex Design</title>
      <link>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971141#M37618</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Here is the configuration:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;class-map match-all Test-C1&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 172.X.X.X any&lt;BR /&gt;class-map type management match-any REMOTE-MGMT&lt;BR /&gt;&amp;nbsp; description ---------Enable remote access---------&lt;BR /&gt;&amp;nbsp; 10 match protocol ssh any&lt;BR /&gt;&amp;nbsp; 20 match protocol icmp any&lt;BR /&gt;&amp;nbsp; 30 match protocol https any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type management first-match REMOTE-ACCESS&lt;BR /&gt;&amp;nbsp; class REMOTE-MGMT&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match Test-POLICY&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm Test-Stickiness&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;policy-map multi-match SF-POLICY&lt;BR /&gt;&amp;nbsp; class Test&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy Test-POLICY&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 800&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;interface vlan 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; description ---------SERVER SIDE INTERFACE--------&lt;BR /&gt;&amp;nbsp; ip address 172.X,X,X, 255.255.255.0&lt;BR /&gt;&amp;nbsp; alias 172.X,X,X, 255.255.252.0&lt;BR /&gt;&amp;nbsp; peer ip address 172.X,X,X, 255.255.252.0&lt;BR /&gt;&amp;nbsp; no normalization&lt;BR /&gt;&amp;nbsp; mac-sticky enable&lt;BR /&gt;&amp;nbsp; no icmp-guard&lt;BR /&gt;&amp;nbsp; access-group input ACL-IN&lt;BR /&gt;&amp;nbsp; nat-pool 1 172.X,X,X,X, 172.X,X,X,X netmask 255.255.252.0 pat&lt;BR /&gt;&amp;nbsp; service-policy input REMOTE-ACCESS&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;interface vlan 200&amp;nbsp; description ---------CLIENT SIDE INTERFACE---------&lt;BR /&gt;&amp;nbsp; ip address 172.Y.Y Y. Y.255.255.255.0&lt;BR /&gt;&amp;nbsp; alias 172.Y.Y.Y.y 255.255.255.0&lt;BR /&gt;&amp;nbsp; peer ip address Y.Y.yYU 255.255.255.0&lt;BR /&gt;&amp;nbsp; no normalization&lt;BR /&gt;&amp;nbsp; no icmp-guard&lt;BR /&gt;&amp;nbsp; access-group input ACL-IN&lt;BR /&gt;&amp;nbsp; service-policy input Test-POLICY&lt;BR /&gt;&amp;nbsp; service-policy input REMOTE-ACCESS&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jun 2012 12:51:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971141#M37618</guid>
      <dc:creator>helsayed78</dc:creator>
      <dc:date>2012-06-24T12:51:32Z</dc:date>
    </item>
    <item>
      <title>ACE Complex Design</title>
      <link>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971142#M37619</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is same as you have used in client VLAN interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something like this &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Admin(config-if)# service-policy input vippolicy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case if you still have confusion attach the running config and let me know the VIP IP. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards, &lt;/P&gt;&lt;P&gt;Ajay Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jun 2012 12:54:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971142#M37619</guid>
      <dc:creator>ajayku2</dc:creator>
      <dc:date>2012-06-24T12:54:44Z</dc:date>
    </item>
    <item>
      <title>ACE Complex Design</title>
      <link>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971143#M37620</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am not sure why you have applied only &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-policy input Test-POLICY&amp;nbsp; &amp;lt;&amp;lt;&amp;lt; You should have applied mutimatch policy SF-POLICY &amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Something like this: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; service-policy input SF-POLICY&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So the solution is to apply: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 100&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-policy input SF-POLICY&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check and let me know if it helps. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards, &lt;/P&gt;&lt;P&gt;Ajay Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jun 2012 13:02:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971143#M37620</guid>
      <dc:creator>ajayku2</dc:creator>
      <dc:date>2012-06-24T13:02:50Z</dc:date>
    </item>
    <item>
      <title>ACE Complex Design</title>
      <link>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971144#M37621</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; could you send me your private email so I can send you the config file&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jun 2012 15:39:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971144#M37621</guid>
      <dc:creator>helsayed78</dc:creator>
      <dc:date>2012-06-24T15:39:33Z</dc:date>
    </item>
    <item>
      <title>ACE Complex Design</title>
      <link>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971145#M37622</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have seen your config in the above. I am trying to say that you should apply this line in following interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; description ---------SERVER SIDE INTERFACE--------&lt;BR /&gt;&amp;nbsp; ip address 172.X,X,X, 255.255.255.0&lt;BR /&gt;&amp;nbsp; alias 172.X,X,X, 255.255.252.0&lt;BR /&gt;&amp;nbsp; peer ip address 172.X,X,X, 255.255.252.0&lt;BR /&gt;&amp;nbsp; no normalization&lt;BR /&gt;&amp;nbsp; mac-sticky enable&lt;BR /&gt;&amp;nbsp; no icmp-guard&lt;BR /&gt;&amp;nbsp; access-group input ACL-IN&lt;BR /&gt;&amp;nbsp; nat-pool 1 172.X,X,X,X, 172.X,X,X,X netmask 255.255.252.0 pat&lt;BR /&gt;&amp;nbsp; service-policy input REMOTE-ACCESS&amp;nbsp; &lt;/P&gt;&lt;P&gt; &lt;STRONG&gt; service-policy input SF-POLICY&lt;/STRONG&gt;&amp;nbsp; &amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt;&amp;lt; Type this line by going to interface 100 &amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&lt;/P&gt;&lt;P&gt;no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do the testing and let me know if it works for you. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 24 Jun 2012 16:28:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971145#M37622</guid>
      <dc:creator>ajayku2</dc:creator>
      <dc:date>2012-06-24T16:28:41Z</dc:date>
    </item>
    <item>
      <title>ACE Complex Design</title>
      <link>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971146#M37623</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did so and didn't work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2012 05:32:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971146#M37623</guid>
      <dc:creator>helsayed78</dc:creator>
      <dc:date>2012-06-25T05:32:08Z</dc:date>
    </item>
    <item>
      <title>ACE Complex Design</title>
      <link>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971147#M37624</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Two things to check: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Default gateway should point to ACE for this to work. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) The return traffic from real server may be going to the server directly. Adding a NAT should fix this issue. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can check the symptoms as shown below: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;show conn | in ip address of server ( Acting as client) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;See if connection is going to ACE or not. &lt;/P&gt;&lt;P&gt;See if the connection is getting load balanced or not. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it is load balancing then the issue is real server is responding directly to server ( Client) and hence the connection is getting dropped. So add a NAT to fix the issue. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2012 06:55:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971147#M37624</guid>
      <dc:creator>ajayku2</dc:creator>
      <dc:date>2012-06-25T06:55:15Z</dc:date>
    </item>
    <item>
      <title>ACE Complex Design</title>
      <link>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971148#M37625</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hesham, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You probably need a nat-pool to make it work, please send me the running config or showtech of the Context where you have this setup&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Jun 2012 19:45:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-complex-design/m-p/1971148#M37625</guid>
      <dc:creator>Cesar Roque</dc:creator>
      <dc:date>2012-06-25T19:45:08Z</dc:date>
    </item>
  </channel>
</rss>

