<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACE module is dropping packets and closing connection. in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-module-is-dropping-packets-and-closing-connection/m-p/1980544#M37754</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list ALLOW-TRAFFIC line 1 extended permit ip any any &lt;BR /&gt;access-list ALLOW-TRAFFIC line 2 extended permit icmp any any &lt;BR /&gt;access-list ICMP_ACL line 10 extended permit icmp any any &lt;/P&gt;&lt;P&gt;robe http HTTP_80&lt;BR /&gt;probe icmp ICMP&lt;BR /&gt;&amp;nbsp; interval 15&lt;BR /&gt;&amp;nbsp; passdetect interval 60&lt;BR /&gt;probe tcp TCP_80&lt;BR /&gt;&amp;nbsp; interval 20&lt;BR /&gt;&amp;nbsp; passdetect count 1&lt;BR /&gt;probe http TDB-ServerAvailability-80&lt;BR /&gt;&amp;nbsp; description Probe for TDB Servers&lt;BR /&gt;&amp;nbsp; interval 5&lt;BR /&gt;&amp;nbsp; passdetect interval 5&lt;BR /&gt;&amp;nbsp; receive 5&lt;BR /&gt;&amp;nbsp; request method head url //Monitoring/Monitor.aspx&lt;BR /&gt;&amp;nbsp; expect status 200 200&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;rserver host NETMAN1LDS_TEST&lt;BR /&gt;&amp;nbsp; description test real server&lt;BR /&gt;&amp;nbsp; ip address 192.168.239.12&lt;BR /&gt;&amp;nbsp; probe TCP_80&lt;BR /&gt;&amp;nbsp; inservice&lt;BR /&gt;rserver redirect TDBWEB-Redirect&lt;BR /&gt;&amp;nbsp; description Redirect to &lt;A href="https://abc.abc.com"&gt;https://abc.abc.com&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; webhost-redirection &lt;A href="https://abc.abc.com/"&gt;https://abc.abc.com/&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; inservice&lt;BR /&gt;rserver host TDBWEB1LV&lt;BR /&gt;&amp;nbsp; description TDBWEB1LV real server&lt;BR /&gt;&amp;nbsp; ip address 192.168.225.11&lt;BR /&gt;&amp;nbsp; probe TDB-ServerAvailability-80&lt;BR /&gt;&amp;nbsp; inservice&lt;BR /&gt;rserver host TDBWEB2LV&lt;BR /&gt;&amp;nbsp; description TDBWEB1LV real server&lt;BR /&gt;&amp;nbsp; ip address 192.168.225.12&lt;BR /&gt;&amp;nbsp; probe TDB-ServerAvailability-80&lt;BR /&gt;&amp;nbsp; inservice&lt;BR /&gt;rserver host TDBWEB3LV&lt;BR /&gt;&amp;nbsp; description TDBWEB1LV real server&lt;BR /&gt;&amp;nbsp; ip address 192.168.225.13&lt;BR /&gt;&amp;nbsp; probe TDB-ServerAvailability-80&lt;BR /&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;serverfarm host TDB_SF&lt;BR /&gt;&amp;nbsp; rserver TDBWEB1LV 80&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;BR /&gt;&amp;nbsp; rserver TDBWEB2LV 80&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;BR /&gt;&amp;nbsp; rserver TDBWEB3LV 80&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;BR /&gt;serverfarm redirect TDB_SF_Redirect&lt;BR /&gt;&amp;nbsp; description http to https redirect for TDB&lt;BR /&gt;&amp;nbsp; rserver TDBWEB-Redirect&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;BR /&gt;serverfarm host TEST_SF&lt;BR /&gt;&amp;nbsp; rserver NETMAN1LDS_TEST 80&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;ssl-proxy service TDB-Web-SSL-PROXY&lt;BR /&gt;&amp;nbsp; key abc.abc.ace.pem&lt;BR /&gt;&amp;nbsp; cert abc.abc.ace.pem&lt;BR /&gt;&amp;nbsp; chaingroup TDB-chain&lt;BR /&gt;ssl-proxy service TEST_ORION_PROXY&lt;BR /&gt;&amp;nbsp; key healthspace-2048-key&lt;BR /&gt;&amp;nbsp; cert HealthspaceSignedCert-V2&lt;BR /&gt;&amp;nbsp; chaingroup Verisign-generic&lt;/P&gt;&lt;P&gt;class-map match-all ICMP_INSPECT_CLASS&lt;BR /&gt;&amp;nbsp; 2 match access-list ICMP_ACL&lt;BR /&gt;class-map match-any NAT_CLASS&lt;BR /&gt;&amp;nbsp; 2 match access-list NAT_ACCESS&lt;BR /&gt;class-map match-all TDB-Web-80&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 10.97.88.12 tcp eq www&lt;BR /&gt;class-map match-all TDB_443_CM&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 10.97.88.12 tcp eq https&lt;BR /&gt;class-map match-all TDB_CM&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 10.97.88.13 tcp eq www&lt;BR /&gt;class-map match-all TEST_ORION_443_CM&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 192.168.173.130 tcp eq https&lt;BR /&gt;class-map match-all TEST_ORION_CM&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 192.168.173.130 tcp eq www&lt;/P&gt;&lt;P&gt;policy-map type management first-match mgmt-pm&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match TDB_PM&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm TDB_SF&lt;BR /&gt;policy-map type loadbalance first-match TDB_PM-80&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm TDB_SF_Redirect&lt;BR /&gt;policy-map type loadbalance first-match TEST_ORION_PM&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm TEST_SF&lt;/P&gt;&lt;P&gt;policy-map multi-match ICMP_INSPECT_POLICY&lt;BR /&gt;&amp;nbsp; class ICMP_INSPECT_CLASS&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inspect icmp error&lt;BR /&gt;policy-map multi-match NAT_POLICY&lt;BR /&gt;&amp;nbsp; class NAT_CLASS&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 300&lt;BR /&gt;&amp;nbsp; class TEST_ORION_CM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy TEST_ORION_PM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;BR /&gt;policy-map multi-match PM_MULTI_MATCH&lt;BR /&gt;&amp;nbsp; class TEST_ORION_CM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy TEST_ORION_PM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;BR /&gt;&amp;nbsp; class TEST_ORION_443_CM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy TEST_ORION_PM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy server TEST_ORION_PROXY&lt;BR /&gt;&amp;nbsp; class TDB_CM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy TDB_PM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;BR /&gt;&amp;nbsp; class TDB_443_CM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy TDB_PM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy server TDB-Web-SSL-PROXY&lt;BR /&gt;&amp;nbsp; class TDB-Web-80&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy TDB_PM-80&lt;/P&gt;&lt;P&gt;service-policy input PM_MULTI_MATCH&lt;/P&gt;&lt;P&gt;interface vlan 300&lt;BR /&gt;&amp;nbsp; ip address 192.168.62.36 255.255.255.248&lt;BR /&gt;&amp;nbsp; alias 192.168.62.37 255.255.255.248&lt;BR /&gt;&amp;nbsp; peer ip address 192.168.62.35 255.255.255.248&lt;BR /&gt;&amp;nbsp; access-group input ALLOW-TRAFFIC&lt;BR /&gt;&amp;nbsp; nat-pool 1 192.168.62.38 192.168.62.38 netmask 255.255.255.248 pat&lt;BR /&gt;&amp;nbsp; service-policy input ICMP_INSPECT_POLICY&lt;BR /&gt;&amp;nbsp; service-policy input mgmt-pm&lt;BR /&gt;&amp;nbsp; service-policy input NAT_POLICY&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;interface vlan 301&lt;BR /&gt;&amp;nbsp; ip address 192.168.62.44 255.255.255.248&lt;BR /&gt;&amp;nbsp; alias 192.168.62.45 255.255.255.248&lt;BR /&gt;&amp;nbsp; peer ip address 192.168.62.43 255.255.255.248&lt;BR /&gt;&amp;nbsp; access-group input ALLOW-TRAFFIC&lt;BR /&gt;&amp;nbsp; service-policy input ICMP_INSPECT_POLICY&lt;BR /&gt;&amp;nbsp; service-policy input mgmt-pm&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 192.168.62.33&lt;BR /&gt;ip route 192.168.66.0 255.255.255.0 192.168.62.41&lt;BR /&gt;ip route 192.168.225.0 255.255.255.192 192.168.62.41&lt;BR /&gt;ip route 192.168.225.128 255.255.255.192 192.168.62.41&lt;BR /&gt;ip route 192.168.249.0 255.255.255.240 192.168.62.41&lt;BR /&gt;ip route 192.168.249.16 255.255.255.240 192.168.62.41&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 31 Jul 2012 09:18:52 GMT</pubDate>
    <dc:creator>Amjad Hashim</dc:creator>
    <dc:date>2012-07-31T09:18:52Z</dc:date>
    <item>
      <title>ACE module is dropping packets and closing connection.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-module-is-dropping-packets-and-closing-connection/m-p/1980539#M37749</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;I have a ACE module A2(3.5) installed, I am having a connectivity problem between two servers in my network. I have captured some traffic on different points in my network and from capture it seems like the problem is with this ACE module or somehow it is closing the connection. I have attached the syslog messages plus capture messages from ACE device, please keep in mind source ip address is 192.168.249.21 and destination is 192.168.249.69 when you check the log messages.&lt;/P&gt;&lt;P&gt;I am not good with ACE at all so any help will be really appriciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad Hashim.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;</description>
      <pubDate>Fri, 27 Jul 2012 10:19:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-module-is-dropping-packets-and-closing-connection/m-p/1980539#M37749</guid>
      <dc:creator>Amjad Hashim</dc:creator>
      <dc:date>2012-07-27T10:19:09Z</dc:date>
    </item>
    <item>
      <title>ACE module is dropping packets and closing connection.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-module-is-dropping-packets-and-closing-connection/m-p/1980540#M37750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Amjad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please upload the configuration related to the issue or the #show run and specify the VIP in question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please get new capture like this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Admin# show running-config access-list&lt;/P&gt;&lt;P&gt;access-list ACCESS-ANS line 8 extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;# capture CAPTURE-TAC all access-list ACCESS-ANS&lt;/P&gt;&lt;P&gt;# capture CAPTURE-TAC start&lt;/P&gt;&lt;P&gt;# capture CAPTURE-TAC stop&lt;/P&gt;&lt;P&gt;# copy capture CAPTURE-TAC disk0: CAPTURE-TAC&lt;/P&gt;&lt;P&gt;# copy disk0:CAPTURE-TAC ftp:&lt;/P&gt;&lt;P&gt;Enter Address for the ftp server[]? 10.198.16.93&lt;/P&gt;&lt;P&gt;Enter the destination filename[]? [CAPTURE-TAC]&lt;/P&gt;&lt;P&gt;Enter username[]? css&lt;/P&gt;&lt;P&gt;Enter the file transfer mode[bin/ascii]: [bin]&lt;/P&gt;&lt;P&gt;Enable Passive mode[Yes/No]: [Yes]&lt;/P&gt;&lt;P&gt;Password:&lt;/P&gt;&lt;P&gt;Passive mode on.&lt;/P&gt;&lt;P&gt;Hash mark printing on (1024 bytes/hash mark).&lt;/P&gt;&lt;P&gt;################&lt;/P&gt;&lt;P&gt;Admin#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here you have a link about the entire process:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://docwiki.cisco.com/wiki/Cisco_Application_Control_Engine_%28ACE%29_Troubleshooting_Guide_--_Overview_of_ACE_Troubleshooting#Capturing_Packets_in_Real_Time"&gt;http://docwiki.cisco.com/wiki/Cisco_Application_Control_Engine_%28ACE%29_Troubleshooting_Guide_--_Overview_of_ACE_Troubleshooting#Capturing_Packets_in_Real_Time&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this happening during peak? How often do you experience this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 27 Jul 2012 17:04:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-module-is-dropping-packets-and-closing-connection/m-p/1980540#M37750</guid>
      <dc:creator>Jorge Bejarano</dc:creator>
      <dc:date>2012-07-27T17:04:01Z</dc:date>
    </item>
    <item>
      <title>ACE module is dropping packets and closing connection.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-module-is-dropping-packets-and-closing-connection/m-p/1980541#M37751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jorge,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply, the issue is that the traffic is not for a VIP on the ACE itself. The ACE module has routes in it to pass the traffic through, in my case we have two firewall contexts and in between these two contexts in the ACE device.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The two firewall contexts are called front end and back end and traffic for all the backend servers go through ACE module, module simply has routes in it for BE firewall subnets and thats it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And there is an access-list on ACE interface to allow any any traffic. This ACE has some VIPs on it for some services but it is also a layer 3 hop between FE and BE firewalls. If u want me to capture anything else please let me know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Amjad Hashim.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 11:17:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-module-is-dropping-packets-and-closing-connection/m-p/1980541#M37751</guid>
      <dc:creator>Amjad Hashim</dc:creator>
      <dc:date>2012-07-30T11:17:46Z</dc:date>
    </item>
    <item>
      <title>ACE module is dropping packets and closing connection.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-module-is-dropping-packets-and-closing-connection/m-p/1980542#M37752</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Amjad,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;I understand you just have traffic passing through the ACE, do you have a specific configuration which is matching that traffic?&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;How did you determine the ACE is dropping the connections?&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;Is this a new implementation? Has this ever worked before?&lt;BR /&gt;&lt;/LI&gt;&lt;LI&gt;Do you get the same behavior if you bypass the ACE?&lt;BR /&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 22:41:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-module-is-dropping-packets-and-closing-connection/m-p/1980542#M37752</guid>
      <dc:creator>Jorge Bejarano</dc:creator>
      <dc:date>2012-07-30T22:41:32Z</dc:date>
    </item>
    <item>
      <title>ACE module is dropping packets and closing connection.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-module-is-dropping-packets-and-closing-connection/m-p/1980543#M37753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jorge,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply, We have an access-list to allow traffic to come into the ACE from 192.168.249.69 and a route to send it to BE firewall. &lt;/P&gt;&lt;P&gt;I have attached some logs in my first post if u can spare some time to look into it. the file called "ace detail capture" is showing ACE having message type CON_CLOSE and PKT_DROP etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find attached my config from ACE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2012 09:17:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-module-is-dropping-packets-and-closing-connection/m-p/1980543#M37753</guid>
      <dc:creator>Amjad Hashim</dc:creator>
      <dc:date>2012-07-31T09:17:16Z</dc:date>
    </item>
    <item>
      <title>ACE module is dropping packets and closing connection.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-module-is-dropping-packets-and-closing-connection/m-p/1980544#M37754</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;access-list ALLOW-TRAFFIC line 1 extended permit ip any any &lt;BR /&gt;access-list ALLOW-TRAFFIC line 2 extended permit icmp any any &lt;BR /&gt;access-list ICMP_ACL line 10 extended permit icmp any any &lt;/P&gt;&lt;P&gt;robe http HTTP_80&lt;BR /&gt;probe icmp ICMP&lt;BR /&gt;&amp;nbsp; interval 15&lt;BR /&gt;&amp;nbsp; passdetect interval 60&lt;BR /&gt;probe tcp TCP_80&lt;BR /&gt;&amp;nbsp; interval 20&lt;BR /&gt;&amp;nbsp; passdetect count 1&lt;BR /&gt;probe http TDB-ServerAvailability-80&lt;BR /&gt;&amp;nbsp; description Probe for TDB Servers&lt;BR /&gt;&amp;nbsp; interval 5&lt;BR /&gt;&amp;nbsp; passdetect interval 5&lt;BR /&gt;&amp;nbsp; receive 5&lt;BR /&gt;&amp;nbsp; request method head url //Monitoring/Monitor.aspx&lt;BR /&gt;&amp;nbsp; expect status 200 200&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;rserver host NETMAN1LDS_TEST&lt;BR /&gt;&amp;nbsp; description test real server&lt;BR /&gt;&amp;nbsp; ip address 192.168.239.12&lt;BR /&gt;&amp;nbsp; probe TCP_80&lt;BR /&gt;&amp;nbsp; inservice&lt;BR /&gt;rserver redirect TDBWEB-Redirect&lt;BR /&gt;&amp;nbsp; description Redirect to &lt;A href="https://abc.abc.com"&gt;https://abc.abc.com&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; webhost-redirection &lt;A href="https://abc.abc.com/"&gt;https://abc.abc.com/&lt;/A&gt;&lt;BR /&gt;&amp;nbsp; inservice&lt;BR /&gt;rserver host TDBWEB1LV&lt;BR /&gt;&amp;nbsp; description TDBWEB1LV real server&lt;BR /&gt;&amp;nbsp; ip address 192.168.225.11&lt;BR /&gt;&amp;nbsp; probe TDB-ServerAvailability-80&lt;BR /&gt;&amp;nbsp; inservice&lt;BR /&gt;rserver host TDBWEB2LV&lt;BR /&gt;&amp;nbsp; description TDBWEB1LV real server&lt;BR /&gt;&amp;nbsp; ip address 192.168.225.12&lt;BR /&gt;&amp;nbsp; probe TDB-ServerAvailability-80&lt;BR /&gt;&amp;nbsp; inservice&lt;BR /&gt;rserver host TDBWEB3LV&lt;BR /&gt;&amp;nbsp; description TDBWEB1LV real server&lt;BR /&gt;&amp;nbsp; ip address 192.168.225.13&lt;BR /&gt;&amp;nbsp; probe TDB-ServerAvailability-80&lt;BR /&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;serverfarm host TDB_SF&lt;BR /&gt;&amp;nbsp; rserver TDBWEB1LV 80&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;BR /&gt;&amp;nbsp; rserver TDBWEB2LV 80&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;BR /&gt;&amp;nbsp; rserver TDBWEB3LV 80&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;BR /&gt;serverfarm redirect TDB_SF_Redirect&lt;BR /&gt;&amp;nbsp; description http to https redirect for TDB&lt;BR /&gt;&amp;nbsp; rserver TDBWEB-Redirect&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;BR /&gt;serverfarm host TEST_SF&lt;BR /&gt;&amp;nbsp; rserver NETMAN1LDS_TEST 80&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;ssl-proxy service TDB-Web-SSL-PROXY&lt;BR /&gt;&amp;nbsp; key abc.abc.ace.pem&lt;BR /&gt;&amp;nbsp; cert abc.abc.ace.pem&lt;BR /&gt;&amp;nbsp; chaingroup TDB-chain&lt;BR /&gt;ssl-proxy service TEST_ORION_PROXY&lt;BR /&gt;&amp;nbsp; key healthspace-2048-key&lt;BR /&gt;&amp;nbsp; cert HealthspaceSignedCert-V2&lt;BR /&gt;&amp;nbsp; chaingroup Verisign-generic&lt;/P&gt;&lt;P&gt;class-map match-all ICMP_INSPECT_CLASS&lt;BR /&gt;&amp;nbsp; 2 match access-list ICMP_ACL&lt;BR /&gt;class-map match-any NAT_CLASS&lt;BR /&gt;&amp;nbsp; 2 match access-list NAT_ACCESS&lt;BR /&gt;class-map match-all TDB-Web-80&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 10.97.88.12 tcp eq www&lt;BR /&gt;class-map match-all TDB_443_CM&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 10.97.88.12 tcp eq https&lt;BR /&gt;class-map match-all TDB_CM&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 10.97.88.13 tcp eq www&lt;BR /&gt;class-map match-all TEST_ORION_443_CM&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 192.168.173.130 tcp eq https&lt;BR /&gt;class-map match-all TEST_ORION_CM&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 192.168.173.130 tcp eq www&lt;/P&gt;&lt;P&gt;policy-map type management first-match mgmt-pm&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match TDB_PM&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm TDB_SF&lt;BR /&gt;policy-map type loadbalance first-match TDB_PM-80&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm TDB_SF_Redirect&lt;BR /&gt;policy-map type loadbalance first-match TEST_ORION_PM&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm TEST_SF&lt;/P&gt;&lt;P&gt;policy-map multi-match ICMP_INSPECT_POLICY&lt;BR /&gt;&amp;nbsp; class ICMP_INSPECT_CLASS&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inspect icmp error&lt;BR /&gt;policy-map multi-match NAT_POLICY&lt;BR /&gt;&amp;nbsp; class NAT_CLASS&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 300&lt;BR /&gt;&amp;nbsp; class TEST_ORION_CM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy TEST_ORION_PM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;BR /&gt;policy-map multi-match PM_MULTI_MATCH&lt;BR /&gt;&amp;nbsp; class TEST_ORION_CM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy TEST_ORION_PM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;BR /&gt;&amp;nbsp; class TEST_ORION_443_CM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy TEST_ORION_PM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy server TEST_ORION_PROXY&lt;BR /&gt;&amp;nbsp; class TDB_CM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy TDB_PM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;BR /&gt;&amp;nbsp; class TDB_443_CM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy TDB_PM&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy server TDB-Web-SSL-PROXY&lt;BR /&gt;&amp;nbsp; class TDB-Web-80&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy TDB_PM-80&lt;/P&gt;&lt;P&gt;service-policy input PM_MULTI_MATCH&lt;/P&gt;&lt;P&gt;interface vlan 300&lt;BR /&gt;&amp;nbsp; ip address 192.168.62.36 255.255.255.248&lt;BR /&gt;&amp;nbsp; alias 192.168.62.37 255.255.255.248&lt;BR /&gt;&amp;nbsp; peer ip address 192.168.62.35 255.255.255.248&lt;BR /&gt;&amp;nbsp; access-group input ALLOW-TRAFFIC&lt;BR /&gt;&amp;nbsp; nat-pool 1 192.168.62.38 192.168.62.38 netmask 255.255.255.248 pat&lt;BR /&gt;&amp;nbsp; service-policy input ICMP_INSPECT_POLICY&lt;BR /&gt;&amp;nbsp; service-policy input mgmt-pm&lt;BR /&gt;&amp;nbsp; service-policy input NAT_POLICY&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;interface vlan 301&lt;BR /&gt;&amp;nbsp; ip address 192.168.62.44 255.255.255.248&lt;BR /&gt;&amp;nbsp; alias 192.168.62.45 255.255.255.248&lt;BR /&gt;&amp;nbsp; peer ip address 192.168.62.43 255.255.255.248&lt;BR /&gt;&amp;nbsp; access-group input ALLOW-TRAFFIC&lt;BR /&gt;&amp;nbsp; service-policy input ICMP_INSPECT_POLICY&lt;BR /&gt;&amp;nbsp; service-policy input mgmt-pm&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 192.168.62.33&lt;BR /&gt;ip route 192.168.66.0 255.255.255.0 192.168.62.41&lt;BR /&gt;ip route 192.168.225.0 255.255.255.192 192.168.62.41&lt;BR /&gt;ip route 192.168.225.128 255.255.255.192 192.168.62.41&lt;BR /&gt;ip route 192.168.249.0 255.255.255.240 192.168.62.41&lt;BR /&gt;ip route 192.168.249.16 255.255.255.240 192.168.62.41&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2012 09:18:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-module-is-dropping-packets-and-closing-connection/m-p/1980544#M37754</guid>
      <dc:creator>Amjad Hashim</dc:creator>
      <dc:date>2012-07-31T09:18:52Z</dc:date>
    </item>
    <item>
      <title>ACE module is dropping packets and closing connection.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-module-is-dropping-packets-and-closing-connection/m-p/1980545#M37755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;you can verify if your traffic will&amp;nbsp; be permitted with the following command :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; show np 1 access-list trace vlan 301 in proto 6 source 192.168.249.21 0 des 192.168.249.69 80&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should see something like :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;action_flag 0x3 (permit yes ...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, get a show tech before and after a connection failure and send it to us so we can check the drop counters.&lt;/P&gt;&lt;P&gt;Could you also clarify if the connection works and then stops suddenly or the connection is never established ?&lt;/P&gt;&lt;P&gt;Could you export the sniffer trace in pcap format and not text so that we can analyse it with wireshark.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2012 12:42:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-module-is-dropping-packets-and-closing-connection/m-p/1980545#M37755</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2012-07-31T12:42:50Z</dc:date>
    </item>
  </channel>
</rss>

