<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Can't Ping the VIP address in from other Vlan Server ? in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987307#M37895</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hidayat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pardon. It seems I misunderstood your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To summarize:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You cannot ping the VIP specified in:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-any L3_APROD&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; 10 match virtual-address 10.203.202.200 tcp eq www&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From real servers in VLAN 302 and VLAN 303.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your VIP specificed in class-map L3_APROD, is attached to the service-policy named "L3_BIZPROD"&lt;/P&gt;&lt;P&gt;but the service-policy is not assigned to either of those vlans, which is required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACE does not treat VIP's like the CSS, so VIP's are only reachable via a specific interface.&lt;/P&gt;&lt;P&gt;Unless, you apply the service-policy globally, which may require additional configuration as source-nat may be required.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 18 Jul 2012 12:06:21 GMT</pubDate>
    <dc:creator>sesoerensen</dc:creator>
    <dc:date>2012-07-18T12:06:21Z</dc:date>
    <item>
      <title>Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987298#M37886</link>
      <description>&lt;P&gt;Hi expert, &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I can't ping the VIP address from other vlan servers. Though VIP is showing inservice and no ACL is blocking any traffic.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list INSIDE remark ACL to open access for L-3 routing of non-LB flows&lt;/P&gt;&lt;P&gt;access-list INSIDE line 10 extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list OUTSIDE line 70 extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above ACL's are applied to all VLan's interface i.e input/output&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;===========================================================================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; class: L3_PROD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; L7 loadbalance policy: L7_PROD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VIP Route Metric&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 77&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VIP Route Advertise&amp;nbsp; : DISABLED&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VIP ICMP Reply&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : ENABLED-WHEN-ACTIVE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VIP State: INSERVICE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; curr conns&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , hit count&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 5068&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; dropped conns&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; client pkt count : 37950&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , client byte count: 5716391&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; server pkt count : 56085&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , server byte count: 60949756&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; conn-rate-limit&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , drop-count : 0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; bandwidth-rate-limit : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; , drop-count : 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;=============================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your help will be much appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 11 Jul 2012 19:08:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987298#M37886</guid>
      <dc:creator>Hidayat Khan</dc:creator>
      <dc:date>2012-07-11T19:08:02Z</dc:date>
    </item>
    <item>
      <title>Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987299#M37887</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Hidayat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can I see configuration of the multi-match policy where the VIP is put in service? Do you have the&lt;STRONG&gt; loadbalance vip icmp-reply active&lt;/STRONG&gt; command configured?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anthony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2012 11:14:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987299#M37887</guid>
      <dc:creator>answanso</dc:creator>
      <dc:date>2012-07-12T11:14:25Z</dc:date>
    </item>
    <item>
      <title>Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987300#M37888</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi answanso, &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I have omitted some of irrelevant config to make it more specific, see below. What I want is to ping the VIP address (shown in this config in bold) be pingable from other Vlan 302/303 shown below, but I can't, though I can ping/telnet the real IP address of the Serversi.e ping/telnet to 10.203.193.120/121 from 10.203.194.164/165, but the requirment is to ping/telnet the VIP address?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list INSMU remark ACL to open access for L-3 routing of non-LB flows&lt;/P&gt;&lt;P&gt;access-list INSMU line 10 extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list PRODACL line 20 extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host APROD1&lt;/P&gt;&lt;P&gt; ip address 10.203.193.120&lt;/P&gt;&lt;P&gt; probe GETPROBE1&lt;/P&gt;&lt;P&gt; probe PINGPROBE1&lt;/P&gt;&lt;P&gt; inservice&lt;/P&gt;&lt;P&gt;rserver host APROD2&lt;/P&gt;&lt;P&gt; ip address 10.203.193.121&lt;/P&gt;&lt;P&gt; probe GETPROBE1&lt;/P&gt;&lt;P&gt; probe PINGPROBE1&lt;/P&gt;&lt;P&gt; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host APROD&lt;/P&gt;&lt;P&gt; description AWD Services PROD Server Farm&lt;/P&gt;&lt;P&gt; rserver APROD1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt; rserver APROD2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type management match-any HTTP&lt;/P&gt;&lt;P&gt; 10 match protocol http source-address 10.203.114.0 255.255.255.0&lt;/P&gt;&lt;P&gt; 20 match protocol http source-address 10.203.115.0 255.255.255.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type management match-any ICMP&lt;/P&gt;&lt;P&gt; 10 match protocol icmp source-address 10.203.114.0 255.255.255.0&lt;/P&gt;&lt;P&gt; 20 match protocol icmp source-address 10.203.115.0 255.255.255.0&lt;/P&gt;&lt;P&gt; 30 match protocol icmp source-address 10.203.204.65 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-any L3_APROD&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; 10 match virtual-address 10.203.202.200 tcp eq www&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type management match-any SERVERICMP&lt;/P&gt;&lt;P&gt; description Permitted ICMP traffic for server VLANs&lt;/P&gt;&lt;P&gt; 10 match protocol icmp source-address 10.203.193.0 255.255.255.128&lt;/P&gt;&lt;P&gt; 20 match protocol icmp source-address 10.203.194.0 255.255.255.128&lt;/P&gt;&lt;P&gt; 30 match protocol icmp source-address 10.203.193.128 255.255.255.128&lt;/P&gt;&lt;P&gt; 40 match protocol icmp source-address 10.203.194.128 255.255.255.128&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type management first-match SMUREMOTEMGMT&lt;/P&gt;&lt;P&gt; description Remote management Access Policy&lt;/P&gt;&lt;P&gt; class TELNET&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt; class SSH&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt; class HTTP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt; class ICMP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type management first-match SMUSVRPINGT&lt;/P&gt;&lt;P&gt; description Allowed Server Ping Traffic&lt;/P&gt;&lt;P&gt; class SERVERICMP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match L7_APROD&lt;/P&gt;&lt;P&gt; description Layer-7 Policy Map defining AWD Production Load Balancing Destination&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; serverfarm APROD&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match L3_BIZPROD&lt;/P&gt;&lt;P&gt; description Load Balancing Policy For Production BizTalk Originated traffic to WebServices &amp;amp; WAS to BizTalk&lt;/P&gt;&lt;P&gt; class TCP-CITRIX&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; connection advanced-options TCP-TTLCITRIXAWD10&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; class L3_APROD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; loadbalance policy L7_APROD&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface vlan 300&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; description SMU WebServices Production VLAN&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;ip address 10.203.193.2 255.255.255.128&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; alias 10.203.193.1 255.255.255.128&lt;/P&gt;&lt;P&gt; peer ip address 10.203.193.3 255.255.255.128&lt;/P&gt;&lt;P&gt; access-group input INSMU&lt;/P&gt;&lt;P&gt; access-group output PRODACL&lt;/P&gt;&lt;P&gt; service-policy input SMUSVRPINGT&lt;/P&gt;&lt;P&gt; service-policy input L3_WEBSVCSBAL&lt;/P&gt;&lt;P&gt; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface vlan 301&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; description SMU Business Logic Production VLAN&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; ip address 10.203.193.130 255.255.255.128&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; alias 10.203.193.129 255.255.255.128&lt;/P&gt;&lt;P&gt; peer ip address 10.203.193.131 255.255.255.128&lt;/P&gt;&lt;P&gt; access-group input INSMU&lt;/P&gt;&lt;P&gt; access-group output PRODACL&lt;/P&gt;&lt;P&gt; nat-pool 2 10.203.193.150 10.203.193.159 netmask 255.255.255.128&lt;/P&gt;&lt;P&gt; service-policy input SMUSVRPINGT&lt;/P&gt;&lt;P&gt; service-policy input L3_BIZPROD&lt;/P&gt;&lt;P&gt; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface vlan 302&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; description SMU WebServices UAT VLAN&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;ip address 10.203.194.2 255.255.255.128&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; alias 10.203.194.1 255.255.255.128&lt;/P&gt;&lt;P&gt; peer ip address 10.203.194.3 255.255.255.128&lt;/P&gt;&lt;P&gt; access-group input INSMU&lt;/P&gt;&lt;P&gt; service-policy input SMUSVRPINGT&lt;/P&gt;&lt;P&gt; service-policy input L3_WEBSVCSBAL&lt;/P&gt;&lt;P&gt; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;interface vlan 303&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; description SMU Business Logic UAT VLAN&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;ip address 10.203.194.130 255.255.255.128&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt; alias 10.203.194.129 255.255.255.128&lt;/P&gt;&lt;P&gt; peer ip address 10.203.194.131 255.255.255.128&lt;/P&gt;&lt;P&gt; access-group input INSMU&lt;/P&gt;&lt;P&gt; nat-pool 1 10.203.194.150 10.203.194.159 netmask 255.255.255.128&lt;/P&gt;&lt;P&gt; service-policy input SMUSVRPINGT&lt;/P&gt;&lt;P&gt; service-policy input L3_BIZUAT&lt;/P&gt;&lt;P&gt; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope the above config is clear to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Jul 2012 11:56:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987300#M37888</guid>
      <dc:creator>Hidayat Khan</dc:creator>
      <dc:date>2012-07-12T11:56:14Z</dc:date>
    </item>
    <item>
      <title>Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987301#M37889</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hidayat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is the default gateway of your servers, is it pointing toward the alias on the VLAN interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Anthony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2012 10:35:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987301#M37889</guid>
      <dc:creator>answanso</dc:creator>
      <dc:date>2012-07-16T10:35:08Z</dc:date>
    </item>
    <item>
      <title>Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987302#M37890</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes the default gateway is towards the alias on the Vlan Interface, thats correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Hidayat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 16 Jul 2012 11:27:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987302#M37890</guid>
      <dc:creator>Hidayat Khan</dc:creator>
      <dc:date>2012-07-16T11:27:33Z</dc:date>
    </item>
    <item>
      <title>Re: Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987303#M37891</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hidayat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Its a really annoying security 'gotcha' feature:&lt;/P&gt;&lt;P&gt;two or more contexts cannot communicate using a shared vlan on the ACE platform.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Easist ways out:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Assign two different vlans to the "client-side" of the ACE, if you're VIP's are attached to that interface.&lt;/P&gt;&lt;P&gt;One VLAN per context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Creating an additional vlan interface on each context (example: 201, and 202) and assign SVI's within a VRF,&lt;/P&gt;&lt;P&gt;attach your service-policies to those interfaces as well. You may also need NAT to ensure traffic is routed correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From the "Routing and Bridging" configuration Guide:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/v3.00_A2/configuration/rtg_brdg/guide/vlansif.html" rel="nofollow"&gt;http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/v3.00_A2/configuration/rtg_brdg/guide/vlansif.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACE also supports shared VLANs, which are&amp;nbsp; multiple interfaces in different contexts on the same VLAN within the&amp;nbsp; same subnet. Only routed interfaces can share VLANs. Note that there is&amp;nbsp; no routing across contexts even when shared VLANs are configured. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers mate,&lt;/P&gt;&lt;P&gt;Søren Elleby Sørensen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 00:21:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987303#M37891</guid>
      <dc:creator>sesoerensen</dc:creator>
      <dc:date>2012-07-17T00:21:24Z</dc:date>
    </item>
    <item>
      <title>Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987304#M37892</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Søren Elleby Sørensen,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks for your reply. In my case, the Vlan's are in the same context. I am not trying to ping from other context! I can ping the real server ip address between two vlan's, but when I ping the vip address then it can't! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Hidayat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 09:11:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987304#M37892</guid>
      <dc:creator>Hidayat Khan</dc:creator>
      <dc:date>2012-07-17T09:11:47Z</dc:date>
    </item>
    <item>
      <title>Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987305#M37893</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This sounds expected based on this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;''For security reasons, the ACE does not allow pings&amp;nbsp; from an interface on a VLAN on one side of the ACE through the module&amp;nbsp; to an interface on a different VLAN on the other side of the module. For&amp;nbsp; example, a host can ping the ACE address that is on the IP subnet using&amp;nbsp; the same VLAN as the host, but cannot ping IP addresses configured on&amp;nbsp; other VLANs on the ACE. '' &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cesar R&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Jul 2012 20:23:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987305#M37893</guid>
      <dc:creator>Cesar Roque</dc:creator>
      <dc:date>2012-07-17T20:23:57Z</dc:date>
    </item>
    <item>
      <title>Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987306#M37894</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Cesar, &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks for your reply. In the above config, the servers in Vlan 300 can ping the real IP's in Vlan 303 or vice versa, but the requirment is to ping/telnet the VIP of 303, which is 10.203.202.200 from vlan 300 or 301.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regds&lt;/P&gt;&lt;P&gt;Hidayat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 09:23:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987306#M37894</guid>
      <dc:creator>Hidayat Khan</dc:creator>
      <dc:date>2012-07-18T09:23:31Z</dc:date>
    </item>
    <item>
      <title>Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987307#M37895</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hidayat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pardon. It seems I misunderstood your question.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To summarize:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You cannot ping the VIP specified in:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-any L3_APROD&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt; 10 match virtual-address 10.203.202.200 tcp eq www&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From real servers in VLAN 302 and VLAN 303.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your VIP specificed in class-map L3_APROD, is attached to the service-policy named "L3_BIZPROD"&lt;/P&gt;&lt;P&gt;but the service-policy is not assigned to either of those vlans, which is required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACE does not treat VIP's like the CSS, so VIP's are only reachable via a specific interface.&lt;/P&gt;&lt;P&gt;Unless, you apply the service-policy globally, which may require additional configuration as source-nat may be required.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 12:06:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987307#M37895</guid>
      <dc:creator>sesoerensen</dc:creator>
      <dc:date>2012-07-18T12:06:21Z</dc:date>
    </item>
    <item>
      <title>Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987308#M37896</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sesoerensen, &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks for your reply, I can give it a try and apply the service-policy to Vlan 302 and 303. i.e &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Int vlan 302&lt;/P&gt;&lt;P&gt;service-policy input L3_BIZPROD&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;amp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Int vlan 303&lt;/P&gt;&lt;P&gt;service-policy input L3_BIZPROD&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will let you know of the above changes and results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regds&lt;/P&gt;&lt;P&gt;Hidayat &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 18 Jul 2012 13:01:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987308#M37896</guid>
      <dc:creator>Hidayat Khan</dc:creator>
      <dc:date>2012-07-18T13:01:00Z</dc:date>
    </item>
    <item>
      <title>Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987309#M37897</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Sesoerensen,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; I applied the service policy on vlan 302 &amp;amp; 303, which worked fine both ping/telnet. I wanted to allow few servers in from Vlan 303 to be able to ping/telnet to vip 10.203.202.200, and applied the acl's,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;e.g&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list PRODACL line 40 extended permit ip 10.203.194.128 255.255.255.128 host 10.203.202.200&lt;/P&gt;&lt;P&gt;access-list PRODACL line 50 extended deny ip 10.203.194.0 255.255.255.128 host 10.203.202.200 &lt;/P&gt;&lt;P&gt;access-list PRODACL line 60 extended permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Int vlan 300&lt;/P&gt;&lt;P&gt;access-group output PRODACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Int vlan 301&lt;/P&gt;&lt;P&gt;access-group output PRODACL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the above acl did not work, all server's from 10.203.194.0 and 195.0 subnet were able to ping/telnet the VIP address. &lt;/P&gt;&lt;P&gt;Reverted back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Hid &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 12:03:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987309#M37897</guid>
      <dc:creator>Hidayat Khan</dc:creator>
      <dc:date>2012-07-19T12:03:22Z</dc:date>
    </item>
    <item>
      <title>Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987310#M37898</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hidayat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are using output access-lists, but you are trying to match the VIP which is in the "input" direction of an interface.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;do something like:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list SEC_VLAN302_IN ext deny icmp any host 10.203.202.200&lt;/P&gt;&lt;P&gt;access-list SEC_VLAN302_IN ext deny ip any host 10.203.202.200&lt;/P&gt;&lt;P&gt;access-list SEC_VLAN303_IN permit icmp any any&lt;/P&gt;&lt;P&gt;access-list SEC_VLAN303_IN permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int vlan 302&lt;/P&gt;&lt;P&gt;access-group &lt;STRONG&gt;input&lt;/STRONG&gt; SEC_VLAN302_IN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list SEC_VLAN303_IN ext perm icmp 10.203.194.128 255.255.255.128 host 10.203.202.200&lt;/P&gt;&lt;P&gt;access-list SEC_VLAN303_IN ext perm ip 10.203.194.128 255.255.255.128 host 10.203.202.200&lt;/P&gt;&lt;P&gt;access-list SEC_VLAN303_IN ext deny icmp any host 10.203.202.200&lt;/P&gt;&lt;P&gt;access-list SEC_VLAN303_IN ext deny ip any host 10.203.202.200&lt;/P&gt;&lt;P&gt;access-list SEC_VLAN303_IN permit icmp any any&lt;/P&gt;&lt;P&gt;access-list SEC_VLAN303_IN permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int vlan 303&lt;/P&gt;&lt;P&gt;access-group &lt;STRONG&gt;input&lt;/STRONG&gt; SEC_VLAN303_IN&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers mate,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Søren Elleby Sørensen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 12:40:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987310#M37898</guid>
      <dc:creator>sesoerensen</dc:creator>
      <dc:date>2012-07-19T12:40:26Z</dc:date>
    </item>
    <item>
      <title>Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987311#M37899</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I have an acl applied on the vlan 302/303 input. see the orignal config, but I will give it a try again and will let you know. Thanks for your great help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list INSMU remark ACL to open access for L-3 routing of non-LB flows&lt;/P&gt;&lt;P&gt;access-list INSMU line 10 extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Hid &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 13:55:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987311#M37899</guid>
      <dc:creator>Hidayat Khan</dc:creator>
      <dc:date>2012-07-19T13:55:42Z</dc:date>
    </item>
    <item>
      <title>Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987312#M37900</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hidayat,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Lets try and source NAT the server traffic to the VIP IP address and see if that allows you to ping the VIP:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-any NAT_TEST&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match source-address 10.203.194.164 255.255.255.255&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4 match source-address 10.203.194.165 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match SOURCE_NAT&lt;/P&gt;&lt;P&gt;&amp;nbsp; class NAT_TEST&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 2 vlan 303&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 303&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 2 10.203.202.200 10.203.202.200 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input NAT_TEST&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Anthony&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Jul 2012 14:51:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987312#M37900</guid>
      <dc:creator>answanso</dc:creator>
      <dc:date>2012-07-19T14:51:07Z</dc:date>
    </item>
    <item>
      <title>Can't Ping the VIP address in from other Vlan Server ?</title>
      <link>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987313#M37901</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi&amp;nbsp; Sørensen, &lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Thanks for your help, yes it worked perfect. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Hidayat&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Sep 2012 13:18:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/can-t-ping-the-vip-address-in-from-other-vlan-server/m-p/1987313#M37901</guid>
      <dc:creator>Hidayat Khan</dc:creator>
      <dc:date>2012-09-07T13:18:26Z</dc:date>
    </item>
  </channel>
</rss>

