<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic No sticky database entries seen with end-to-end SSL and cookie i in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/no-sticky-database-entries-seen-with-end-to-end-ssl-and-cookie/m-p/2023525#M38464</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kurt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your configuration looks good. You will not see anything in sticky database since ACE is not learning the cookies dynamically here. It is inserting it so you should see the entries in show sticky cookie-insert group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can see total active sticky entries as well in stats. You need to test using one client and take a pcap to see what exactly is going on. May be client is closing the browser which is deleting the cookie and hence client is going to a different server. Not sure just assuming. Pcaps should clear things here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 12 Sep 2012 00:41:52 GMT</pubDate>
    <dc:creator>Kanwaljeet Singh</dc:creator>
    <dc:date>2012-09-12T00:41:52Z</dc:date>
    <item>
      <title>No sticky database entries seen with end-to-end SSL and cookie insertion</title>
      <link>https://community.cisco.com/t5/application-networking/no-sticky-database-entries-seen-with-end-to-end-ssl-and-cookie/m-p/2023523#M38462</link>
      <description>&lt;P&gt;We've got ACE30s (active/standby) running A5(1.2), and a context that's front-ending one of our major applications, doing SSL termination on the client side and SSL initiation on the back side:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;parameter-map type ssl FrontEndSSL-Param&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp; rehandshake enabled&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;parameter-map type ssl BackendSSL-param&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp; authentication-failure ignore&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;parameter-map type http UP-ContentParseLength&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp; persistence-rebalance&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp; set header-maxparse-length 32767&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp; set content-maxparse-length 32767&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;parameter-map type connection WEBAPPS_TCP_P&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp; set timeout inactivity 180&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp; set tcp timeout half-closed 180&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier;"&gt;ssl-proxy service SSL_PSRVICE_CTOOLS&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp; key ctools.key&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp; cert ctools.crt&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp; chaingroup COMODO-INSTANTSSL&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp; ssl advanced-options FrontEndSSL-Param&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;ssl-proxy service backend-ssl&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp; ssl advanced-options BackendSSL-param&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;class-map match-any ctools-https&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp; 3 match virtual-address 192.168.234.10 tcp eq https&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;policy-map type loadbalance first-match ctools_l7_policy&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp; class class-default&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy client backend-ssl&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;policy-map multi-match ctools_ssl_l4_policy&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp; class ctools-https&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 72 vlan 72&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options UP-ContentParseLength&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy server SSL_PSRVICE_CTOOLS&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options WEBAPPS_TCP_P&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;(It's running in one-arm mode with source NAT, and using RHI to inject a host route for the VIP so we can do IP anycast across multiple data centers for high availability; but we do this for other services that are working OK so I don't think this is the problem...)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We need to stick clients to the back-end server that they initially connect to, but don't want to do it based on client IP address (we sometimes have many clients sitting behind a single NAT address); and we know that stickiness based on SSL session ID isn't a good idea.&amp;nbsp; So we've set this up to use cookie insertion:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;serverfarm host CTOOLS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; predictor response app-req-to-resp&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; probe HTTPS_PROBE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; rserver tahoe 443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; conn-limit max 500 min 490 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; rserver tavera 443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; conn-limit max 500 min 490 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; :&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;sticky http-cookie CTcookie CTOOLS-sticky&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; cookie insert browser-expire&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; replicate sticky&lt;/STRONG&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; serverfarm CTOOLS backup Outage&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="padding: 0pt; margin: 0pt;"&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;policy-map type loadbalance first-match ctools_l7_policy&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; class class-default&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm CTOOLS-sticky&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; insert-http DEST_Port header-value "%pd"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; insert-http DEST_IP header-value "%id"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; insert-http SRC_Port header-value "%ps"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; insert-http I_AM header-value "SSL_INIT"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; insert-http X-Client-IP header-value "%is"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy client backend-ssl&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;policy-map multi-match ctools_ssl_l4_policy&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; class ctools-https&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy ctools_l7_policy&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip advertise active&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 72 vlan 72&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options UP-ContentParseLength&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy server SSL_PSRVICE_CTOOLS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options WEBAPPS_TCP_P&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The ACE shows cookies for this group:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;ACE30-ASBDC-1/TL-PROD-ASB# show sticky cookie-insert &lt;/SPAN&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;group CTOOLS-sticky&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Cookie&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; HashKey&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; rserver-instance&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; ------------+----------------------+----------------------------------------+&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; R2536245497 | 5183849923197467535&amp;nbsp; | CTOOLS/tahoe:443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; R2274919243 | 1819252748455616984&amp;nbsp; | CTOOLS/tavera:443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; R3735812906 | 4189234711381892064&amp;nbsp; | CTOOLS/tempest:443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; R2985606557 | 13173125335060717162 | CTOOLS/terrain:443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; R3002567455 | 9439662962898967148&amp;nbsp; | CTOOLS/tigra:443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; R1961897160 | 14710369893090908424 | CTOOLS/titan:443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; R499081919&amp;nbsp; | 6217826711974382744&amp;nbsp; | CTOOLS/tornado:443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; R442350102&amp;nbsp; | 16043823351255228140 | CTOOLS/torrent:443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; R3040870402 | 15912262023226993721 | CTOOLS/tosca:443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; R508933855&amp;nbsp; | 4513105838401809319&amp;nbsp; | CTOOLS/townsman:443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; R1259946260 | 3311717765801371676&amp;nbsp; | CTOOLS/tracker:443&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp; R3378012421 | 4759463036538773497&amp;nbsp; | Outage/RedirectOutage:0&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And we've got lots of connections:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;ACE30-ASBDC-1/TL-PROD-ASB# show serverfarm CTOOLS&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt; serverfarm&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : CTOOLS, type: HOST&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt; total rservers : 11&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt; state&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : ACTIVE&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt; DWS state&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : DISABLED&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt; ---------------------------------&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----------connections-----------&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; real&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; weight state&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; current&amp;nbsp;&amp;nbsp;&amp;nbsp; total&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; failures &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp; ---+---------------------+------+------------+----------+----------+---------&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp; rserver: tahoe&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.0.201:443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8&amp;nbsp;&amp;nbsp; OPERATIONAL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 93&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1999973&amp;nbsp;&amp;nbsp;&amp;nbsp; 126183&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp; rserver: tavera&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;192.168.0&lt;/STRONG&gt;.135:443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8&amp;nbsp;&amp;nbsp; OPERATIONAL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 115&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1954862&amp;nbsp;&amp;nbsp;&amp;nbsp; 115132&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp; rserver: tempest&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;192.168.0&lt;/STRONG&gt;.207:443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8&amp;nbsp;&amp;nbsp; OPERATIONAL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 94&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 342550&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 17205&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp; rserver: terrain&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;192.168.0&lt;/STRONG&gt;.209:443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8&amp;nbsp;&amp;nbsp; OPERATIONAL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 91&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 337468&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 18796&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp; rserver: tigra&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;192.168.0&lt;/STRONG&gt;.202:443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8&amp;nbsp;&amp;nbsp; OPERATIONAL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 91&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2074019&amp;nbsp;&amp;nbsp;&amp;nbsp; 125814&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp; rserver: titan&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;192.168.0&lt;/STRONG&gt;.155:443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8&amp;nbsp;&amp;nbsp; OPERATIONAL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 97&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 629418&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 36974&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp; rserver: tornado&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;192.168.0&lt;/STRONG&gt;.203:443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8&amp;nbsp;&amp;nbsp; OPERATIONAL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 111&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2084020&amp;nbsp;&amp;nbsp;&amp;nbsp; 121127&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp; rserver: torrent&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;192.168.0&lt;/STRONG&gt;.208:443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8&amp;nbsp;&amp;nbsp; OPERATIONAL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 102&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 357320&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 19392&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp; rserver: tosca&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;192.168.0&lt;/STRONG&gt;.136:443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8&amp;nbsp;&amp;nbsp; OPERATIONAL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 125&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2145770&amp;nbsp;&amp;nbsp;&amp;nbsp; 126751&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp; rserver: townsman&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;192.168.0&lt;/STRONG&gt;.204:443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8&amp;nbsp;&amp;nbsp; OPERATIONAL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 101&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2111449&amp;nbsp;&amp;nbsp;&amp;nbsp; 128722&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp; rserver: tracker&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt;192.168.0&lt;/STRONG&gt;.205:443&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8&amp;nbsp;&amp;nbsp; OPERATIONAL&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 95&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1980421&amp;nbsp;&amp;nbsp;&amp;nbsp; 120746&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But the sticky database for group CTOOLS-sticky is empty:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;ACE30-ASBDC-1/TL-PROD-ASB# show sticky database group CTOOLS-sticky &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier; "&gt;ACE30-ASBDC-1/TL-PROD-ASB# &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the Apache logs on the back-end servers are showing that clients are *not* getting stuck.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What am I missing here?&lt;/P&gt;</description>
      <pubDate>Tue, 11 Sep 2012 21:49:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/no-sticky-database-entries-seen-with-end-to-end-ssl-and-cookie/m-p/2023523#M38462</guid>
      <dc:creator>KURT HILLIG</dc:creator>
      <dc:date>2012-09-11T21:49:05Z</dc:date>
    </item>
    <item>
      <title>No sticky database entries seen with end-to-end SSL and cookie i</title>
      <link>https://community.cisco.com/t5/application-networking/no-sticky-database-entries-seen-with-end-to-end-ssl-and-cookie/m-p/2023524#M38463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;...I forgot to include this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: 'courier new', courier;"&gt;&lt;STRONG&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;ACE30-ASBDC-1/TL-PROD-ASB# show stats sticky&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;+------------------------------------------+&lt;/P&gt;&lt;P&gt;+----------- Sticky statistics ------------+&lt;/P&gt;&lt;P&gt;+------------------------------------------+&lt;/P&gt;&lt;P&gt; Total sticky entries reused&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;P&gt; prior to expiry&lt;/P&gt;&lt;P&gt; Total active sticky entries&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 21&lt;/P&gt;&lt;P&gt; Total active reverse sticky entries&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;P&gt; Total active sticky conns&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;P&gt; Total static sticky entries&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 21&lt;/P&gt;&lt;P&gt; Total sticky entries from Global Pool&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;P&gt; Total insertion failures due to lack of resources&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 11 Sep 2012 22:05:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/no-sticky-database-entries-seen-with-end-to-end-ssl-and-cookie/m-p/2023524#M38463</guid>
      <dc:creator>KURT HILLIG</dc:creator>
      <dc:date>2012-09-11T22:05:09Z</dc:date>
    </item>
    <item>
      <title>No sticky database entries seen with end-to-end SSL and cookie i</title>
      <link>https://community.cisco.com/t5/application-networking/no-sticky-database-entries-seen-with-end-to-end-ssl-and-cookie/m-p/2023525#M38464</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kurt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your configuration looks good. You will not see anything in sticky database since ACE is not learning the cookies dynamically here. It is inserting it so you should see the entries in show sticky cookie-insert group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can see total active sticky entries as well in stats. You need to test using one client and take a pcap to see what exactly is going on. May be client is closing the browser which is deleting the cookie and hence client is going to a different server. Not sure just assuming. Pcaps should clear things here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 00:41:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/no-sticky-database-entries-seen-with-end-to-end-ssl-and-cookie/m-p/2023525#M38464</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2012-09-12T00:41:52Z</dc:date>
    </item>
    <item>
      <title>No sticky database entries seen with end-to-end SSL and cookie i</title>
      <link>https://community.cisco.com/t5/application-networking/no-sticky-database-entries-seen-with-end-to-end-ssl-and-cookie/m-p/2023526#M38465</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Interesting; sure would be nice if some of this explanation made it into the config guide...&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't have packet captures, but the apache logs (as explained to me - I'm a router monkey, not a webmaster) show traffic that looks to me like it's misdirected.&amp;nbsp; For example, for one user over a 10-second period we saw this (anonymized - sorry about the lengthy excerpt) on the server "tigra":&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:39 -0400] "GET /access/require?ref=/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf&amp;amp;url=/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf HTTP/1.1" 416 391 66466718-3e38-4997-8394-ad9875fa280e.tigra Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:42 -0400] "GET /access/require?ref=/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf&amp;amp;url=/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf HTTP/1.1" 416 391 6933ba51-14a9-4483-8255-b7687453a1f5.tahoe Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:42 -0400] "GET /access/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf HTTP/1.1" 302 - 6933ba51-14a9-4483-8255-b7687453a1f5.tahoe Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:42 -0400] "GET /sakai-login-tool/container HTTP/1.1" 302 - 63c77009-9ced-493c-ac88-02f776cbc503.tigra Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:42 -0400] "GET /access/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf HTTP/1.1" 302 - 63c77009-9ced-493c-ac88-02f776cbc503.tigra Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:42 -0400] "GET /access/require?ref=/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf&amp;amp;url=/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf HTTP/1.1" 416 391 63c77009-9ced-493c-ac88-02f776cbc503.tigra Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:45 -0400] "GET /access/require?ref=/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf&amp;amp;url=/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf HTTP/1.1" 416 391 a76046e0-0796-47b3-94f9-96c79726ecc3.tosca Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:46 -0400] "GET /access/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf HTTP/1.1" 302 - a76046e0-0796-47b3-94f9-96c79726ecc3.tosca Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:46 -0400] "GET /sakai-login-tool/container HTTP/1.1" 302 - bc76df11-0446-499c-b58a-cf975d8950cb.tigra Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:46 -0400] "GET /access/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf HTTP/1.1" 302 - bc76df11-0446-499c-b58a-cf975d8950cb.tigra Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:46 -0400] "GET /access/require?ref=/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf&amp;amp;url=/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf HTTP/1.1" 416 391 bc76df11-0446-499c-b58a-cf975d8950cb.tigra Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:49 -0400] "GET /access/require?ref=/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf&amp;amp;url=/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf HTTP/1.1" 416 391 53dd9763-0ef2-47b0-9de2-fb28b26dbba5.townsman Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:49 -0400] "GET /access/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf HTTP/1.1" 302 - 53dd9763-0ef2-47b0-9de2-fb28b26dbba5.townsman Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:49 -0400] "GET /sakai-login-tool/container HTTP/1.1" 302 - 875a9afe-e830-4811-95d9-a074aed71217.tigra Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:49 -0400] "GET /access/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf HTTP/1.1" 302 - 875a9afe-e830-4811-95d9-a074aed71217.tigra Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;141.211.14.186 - USERNAME [09/Sep/2012:21:50:49 -0400] "GET /access/require?ref=/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf&amp;amp;url=/content/group/594942ee-15be-4705-9e90-e5252110fd0e/Lecture%20Slides/F12-Chem-260-L03_Classical_Waves.pdf HTTP/1.1" 416 391 875a9afe-e830-4811-95d9-a074aed71217.tigra Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.1 (KHTML, like Gecko) Chrome/21.0.1180.89 Safari/537.1 71.238.68.166&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you look at the text right before the "Mozilla" on each line, you'll see the names of several other servers - townsman, tahoe, tosca, maybe a few others.&amp;nbsp; Also, in none of these do I see anything that looks like one of the cookies that the ACE should be inserting ("Rnnnnnnnnn"); but as I said this isn't my area of expertise.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The folks running this application have had a number of complaints about this ever since classes started and load picked way up; it may be that it was just not noticed before, or wasn't reproducible enough to be diagnosed.&amp;nbsp; But they say that they haven't identified any obvious commonalities among the users having this problem.&amp;nbsp; Which doesn't mean that it isn't a client/browser problem, just that I don't know either way...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And how do we extract cookies from a pcap when the traffic is encrypted?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 02:12:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/no-sticky-database-entries-seen-with-end-to-end-ssl-and-cookie/m-p/2023526#M38465</guid>
      <dc:creator>KURT HILLIG</dc:creator>
      <dc:date>2012-09-12T02:12:04Z</dc:date>
    </item>
    <item>
      <title>No sticky database entries seen with end-to-end SSL and cookie i</title>
      <link>https://community.cisco.com/t5/application-networking/no-sticky-database-entries-seen-with-end-to-end-ssl-and-cookie/m-p/2023527#M38466</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Kurt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To check the pcaps you will have to decrypt them using private keys and that is normally done to troubleshoot issues where SSL is involved. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to check if client came with cookie or not since after the cookie has been inserted by ACE, the client should come up with that cookie in next request and ACE will use that cookie value to stick it to the same server. I just verified in lab that ACE will forward the cookie as it is to the server which makes me believe that in above requests client didn't come with cookie. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2012 03:22:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/no-sticky-database-entries-seen-with-end-to-end-ssl-and-cookie/m-p/2023527#M38466</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2012-09-12T03:22:48Z</dc:date>
    </item>
  </channel>
</rss>

