<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACE 4710 breaks single sign-on on IE in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049237#M38802</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you try with a single server and see if it works?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Siva&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 17 Oct 2012 07:22:35 GMT</pubDate>
    <dc:creator>sivaksiv</dc:creator>
    <dc:date>2012-10-17T07:22:35Z</dc:date>
    <item>
      <title>ACE 4710 breaks single sign-on on IE</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049234#M38799</link>
      <description>&lt;P&gt;I haven't run into this before and I can't find anything in the documentation regarding it.&amp;nbsp; (Our 2 4710 were setup prior in a routed configuration although I personally see no reason for it.)&amp;nbsp; Regardless, we have 2 servers that host 4 websites on them.&amp;nbsp; We built everything on the ACE with a new VIP and matching the http header.&amp;nbsp; If we use firefox/chrome, it load balances properly and we are prompted for credentials as those browsers don't support single sign on.&amp;nbsp; We enter our credentials and are able to get to the appropriate website on the server.&lt;/P&gt;&lt;P&gt;When we use IE, it fails to open the page.&amp;nbsp; A sniffer capture shows an authentication failure packet and a reset and that's it.&amp;nbsp; We built the ACE both as sticky and non-sticky but neither worked properly with IE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there something else in the ACE we need to configure to get SSO to work?&amp;nbsp; Thanks in advance!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chris&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;**NEW CONFIGURATION**&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;probe icmp PING&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; description ICMP echo request probe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; interval 5&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; passdetect interval 5&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; passdetect count 12&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; receive 4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;probe tcp TCP-80&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; description TCP port 80 probe&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; interval 5&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; passdetect interval 5&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; passdetect count 12&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; receive 4&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; connection term forced&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; open 1&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;rserver host corp-w-sp-lab01&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; ip address 10.250.1.52&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; probe PING&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inservice&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;rserver host corp-w-sp-lab02&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; ip address 10.250.1.53&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; probe PING&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; inservice&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;serverfarm host sharepoint-test-80&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; failaction purge&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; predictor leastconns&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; probe TCP-80&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; rserver corp-w-sp-lab01 80&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; rserver corp-w-sp-lab02 80&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class-map match-any sharepoint-test-vip&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; 2 match virtual-address 10.250.89.10 tcp eq www&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class-map type http loadbalance match-any intranet-test&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&lt;SPAN&gt;&amp;nbsp; match http header Host header-value &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://intranettest"&gt;http://intranettest&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class-map type http loadbalance match-any dashboards-test&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&lt;SPAN&gt;&amp;nbsp; match http header Host header-value &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://dashboardstest"&gt;http://dashboardstest&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class-map type http loadbalance match-any odpeople-test&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&lt;SPAN&gt;&amp;nbsp; match http header Host header-value &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://odpeopletest"&gt;http://odpeopletest&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;class-map type http loadbalance match-any sandbox-test&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&lt;SPAN&gt;&amp;nbsp; match http header Host header-value &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://sandbox"&gt;http://sandbox&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;policy-map type loadbalance http first-match sharepoint-test-lb&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; class intranet-test&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm sharepoint-test-80&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; class dashboards-test&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm sharepoint-test-80&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; class odpeople-test&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm sharepoint-test-80&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; class sandbox-test&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm sharepoint-test-80&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; class class-default&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm sharepoint-test-80&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;policy-map multi-match sharepoint-test-80-pol&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; class sharepoint-test-vip&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy sharepoint-test-lb&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 92&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;!&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;interface vlan 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; service-policy input sharepoint-test-80-pol&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;***CONFIGURATION ALREADY ON INTERFACES PRIOR TO NEW CONFIG***&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;---------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;interface vlan 88&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; description Client_Connections&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; ip address 10.250.88.51 255.255.252.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; alias 10.250.88.50 255.255.252.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; peer ip address 10.250.88.52 255.255.252.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; access-group input Client&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; service-policy input remote_mgmt_allow_policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; service-policy input PM_LB_FRONTEND&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; no shutdown&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;interface vlan 92&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; description RealServer_Network&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; ip address 10.250.92.51 255.255.252.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; alias 10.250.92.50 255.255.252.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; peer ip address 10.250.92.52 255.255.252.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; nat-pool 1 10.250.93.1 10.250.93.1 netmask 255.255.255.255 pat&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; service-policy input remote_mgmt_allow_policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;&amp;nbsp; no shutdown&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-family: courier new,courier;"&gt;-------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Oct 2012 12:09:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049234#M38799</guid>
      <dc:creator>Chris Normand</dc:creator>
      <dc:date>2012-10-16T12:09:59Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 breaks single sign-on on IE</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049235#M38800</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It doesn't looks like ACE issue as it works with chrome and FF. &lt;/P&gt;&lt;P&gt;Do you see the reset coming from ACE or from server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What i would recommend is to take a working and non-working captiure and compare the differences to tune the configuration as required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Siva&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 12:18:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049235#M38800</guid>
      <dc:creator>sivaksiv</dc:creator>
      <dc:date>2012-10-16T12:18:32Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 breaks single sign-on on IE</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049236#M38801</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If we open an IE web browser to either server directly, single&amp;nbsp; sign-on works and we get right to the website.&amp;nbsp; When we go through the&amp;nbsp; ACE using the VIP, it doesn't work at all, so my feeling is something in&amp;nbsp; the ACE is causing it.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Chrome/Firefox don't support single sign-on so I suppose I&amp;nbsp; shouldn't have mentioned it but my point was that at least the ACE is&amp;nbsp; load balancing correctly to the correct website on each server so that&amp;nbsp; part of the config is correct.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The load balancer VIP was sending the packets back to the host.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 16 Oct 2012 15:56:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049236#M38801</guid>
      <dc:creator>Chris Normand</dc:creator>
      <dc:date>2012-10-16T15:56:50Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 breaks single sign-on on IE</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049237#M38802</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can you try with a single server and see if it works?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-&lt;/P&gt;&lt;P&gt;Siva&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2012 07:22:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049237#M38802</guid>
      <dc:creator>sivaksiv</dc:creator>
      <dc:date>2012-10-17T07:22:35Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 breaks single sign-on on IE</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049238#M38803</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We did also try that.&amp;nbsp; We no inservice one of the rservers in the serverfarm and tried but it had the same results on both the sniffer and the ie webpage.&amp;nbsp; Does single sign-on with IE typically work with no issues through an ACE?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2012 12:57:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049238#M38803</guid>
      <dc:creator>Chris Normand</dc:creator>
      <dc:date>2012-10-17T12:57:59Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 breaks single sign-on on IE</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049239#M38804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; I dont see why this shouldn't work. If the reset is coming from ACE then we require more information of how the flow being setup from the client. Which SSO implementation involved and how many parties are involved, is client making any additional requests (to AD server, for e.g.)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would recommend to raise a tac case and attach a sniffer capture taken on the ACE along with show tech. We can analyze further and see if any configuration tweak required to allow this traffic on ACE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 17 Oct 2012 16:56:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049239#M38804</guid>
      <dc:creator>sivaksiv</dc:creator>
      <dc:date>2012-10-17T16:56:16Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 breaks single sign-on on IE</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049240#M38805</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chris, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type http sample&lt;/P&gt;&lt;P&gt;&amp;nbsp; persistence-rebalance&lt;/P&gt;&lt;P&gt;&amp;nbsp; set header-maxparse-length 65535&lt;/P&gt;&lt;P&gt;&amp;nbsp; set content-maxparse-length 65535&lt;/P&gt;&lt;P&gt;&amp;nbsp; length-exceed continue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match sharepoint-test-80-pol&lt;/P&gt;&lt;P&gt;&amp;nbsp; class sharepoint-test-vip&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy sharepoint-test-lb&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options sample&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 92&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if you see any difference&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;--------------------- &lt;BR /&gt;Cesar R &lt;BR /&gt;ANS Team&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 18 Oct 2012 22:17:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049240#M38805</guid>
      <dc:creator>Cesar Roque</dc:creator>
      <dc:date>2012-10-18T22:17:24Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 breaks single sign-on on IE</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049241#M38806</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Did you get this resolved. We are having same issue and it results in account lockout. If someone has got this fixed please confirm what was solution. Have raised TAC case for this but still not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Aijaz&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 10:29:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049241#M38806</guid>
      <dc:creator>aijazbeigh</dc:creator>
      <dc:date>2013-02-04T10:29:40Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 breaks single sign-on on IE</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049242#M38807</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;PRE style="color: #000000; font-size: 12px;"&gt;Hi, 

In some cases what I have seen is "The single sign-on app was putting the 'client's' destination URL
IP addr inside the HTTP header."

This IP was used on back-end to validate against authorized list of IP's. 

Resolution was to add all the VIP IP address space (from ACE) to the allowed and authorized IP range on the AD server. &lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards, &lt;/P&gt;&lt;P&gt;Ajay Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 04 Feb 2013 19:57:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049242#M38807</guid>
      <dc:creator>ajayku2</dc:creator>
      <dc:date>2013-02-04T19:57:20Z</dc:date>
    </item>
    <item>
      <title>Re:ACE 4710 breaks single sign-on on IE</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049243#M38808</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Shouldn't stickiness be configured? For me it seems you authenticate on one realserver, but your next request lands on another server.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Sent from Cisco Technical Support Android App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2013 17:38:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049243#M38808</guid>
      <dc:creator>Andras Dosztal</dc:creator>
      <dc:date>2013-02-05T17:38:12Z</dc:date>
    </item>
    <item>
      <title>Re:ACE 4710 breaks single sign-on on IE</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049244#M38809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; We fixed it by removing connection reuse.&lt;/P&gt;&lt;P&gt;But we have horrible performace issues. all works but response times via ACE are very bad about 30-40 times worst.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2013 17:50:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-breaks-single-sign-on-on-ie/m-p/2049244#M38809</guid>
      <dc:creator>aijazbeigh</dc:creator>
      <dc:date>2013-02-05T17:50:02Z</dc:date>
    </item>
  </channel>
</rss>

