<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Cisco ACE with F5 ASM in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/cisco-ace-with-f5-asm/m-p/2164500#M39749</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yoke, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is possible. You just have to create two ACE context. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE context 1 --&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan 10 ( Client )&amp;nbsp; ----&amp;nbsp; Vlan 11 ( Web app firewall ) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE context 2 -- VLAN 12 ( Web app firewall traffic ) --- Vlan 13 ( Serverfarm)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also read the following : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;By default, the ACE does not allow traffic from one context to another&amp;nbsp; context over a transparent firewall. &lt;/STRONG&gt;The ACE assumes that VLANs in&amp;nbsp; different contexts are in different Layer 2 domains, unless it is a&amp;nbsp; shared VLAN. The ACE allocates the same MAC address to the VLANs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1062064"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; When you are using a firewall service module (FWSM) to bridge traffic&amp;nbsp; between two contexts on the ACE, you must assign two Layer 3 VLANs to&amp;nbsp; the same bridge domain. To support this configuration, these VLAN&amp;nbsp; interfaces require different MAC addresses. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1062078"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; To enable the autogeneration of a MAC address on a VLAN interface, use the &lt;STRONG&gt;mac address autogenerate&lt;/STRONG&gt; command in interface configuration mode. The syntax of this command is as follows: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1062065"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt;mac address autogenerate &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards, &lt;/P&gt;&lt;P&gt;Ajay Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 25 Feb 2013 08:00:15 GMT</pubDate>
    <dc:creator>ajayku2</dc:creator>
    <dc:date>2013-02-25T08:00:15Z</dc:date>
    <item>
      <title>Cisco ACE with F5 ASM</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-with-f5-asm/m-p/2164497#M39746</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How can i divert traffic to F5 ASM (Web Application Firewall) before reach the real server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ANYONE line 8 extended permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;probe icmp ICMP&lt;BR /&gt;&amp;nbsp; interval 2&lt;BR /&gt;&amp;nbsp; faildetect 4&lt;BR /&gt;&amp;nbsp; passdetect interval 4&lt;BR /&gt;&amp;nbsp; passdetect count 4&lt;BR /&gt;probe tcp TCP_80&lt;BR /&gt;&amp;nbsp; interval 2&lt;BR /&gt;&amp;nbsp; faildetect 4&lt;BR /&gt;&amp;nbsp; passdetect interval 4&lt;BR /&gt;&amp;nbsp; passdetect count 4&lt;/P&gt;&lt;P&gt;rserver host F5_ASM_01&lt;BR /&gt;&amp;nbsp; ip address 10.25.245.4&lt;BR /&gt;&amp;nbsp; inservice&lt;BR /&gt;rserver host SSCP_01&lt;BR /&gt;&amp;nbsp; ip address 10.26.74.21&lt;BR /&gt;&amp;nbsp; inservice&lt;BR /&gt;rserver host SSCP_02&lt;BR /&gt;&amp;nbsp; ip address 10.26.74.22&lt;BR /&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;serverfarm host F5_ASM&lt;BR /&gt;&amp;nbsp; transparent&lt;BR /&gt;&amp;nbsp; failaction purge&lt;BR /&gt;&amp;nbsp; predictor hash address source&lt;BR /&gt;&amp;nbsp; probe ICMP&lt;BR /&gt;&amp;nbsp; rserver F5_ASM_01&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;BR /&gt;serverfarm host Web_farm&lt;BR /&gt;&amp;nbsp; failaction purge&lt;BR /&gt;&amp;nbsp; predictor hash address source&lt;BR /&gt;&amp;nbsp; probe TCP_80&lt;BR /&gt;&amp;nbsp; rserver SSCP_01&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;BR /&gt;&amp;nbsp; rserver SSCP_02&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;class-map match-all F5_VIP&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 10.25.245.1 tcp eq www&lt;BR /&gt;class-map type management match-any Mgmt_class&lt;BR /&gt;&amp;nbsp; 2 match protocol icmp any&lt;BR /&gt;&amp;nbsp; 3 match protocol snmp any&lt;BR /&gt;&amp;nbsp; 4 match protocol telnet any&lt;BR /&gt;&amp;nbsp; 5 match protocol ssh any&lt;BR /&gt;class-map match-all Web_80_class&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 172.20.133.100 tcp eq www&lt;/P&gt;&lt;P&gt;policy-map type management first-match Mgmt_policy&lt;BR /&gt;&amp;nbsp; class Mgmt_class&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match F5_ASM_policy&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm F5_ASM backup Web_farm&lt;BR /&gt;policy-map type loadbalance first-match Web_policy&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm Web_farm&lt;/P&gt;&lt;P&gt;policy-map multi-match Accel_SLB_policy&lt;BR /&gt;&amp;nbsp; class Web_80_class&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy F5_ASM_policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;BR /&gt;policy-map multi-match Web_SLB_policy&lt;BR /&gt;&amp;nbsp; class F5_VIP&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy Web_policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;service-policy input Mgmt_policy&lt;BR /&gt;access-group input ANYONE&lt;/P&gt;&lt;P&gt;interface vlan 271&lt;BR /&gt;&amp;nbsp; description ### Client side ###&lt;BR /&gt;&amp;nbsp; ip address 172.20.133.27 255.255.255.0&lt;BR /&gt;&amp;nbsp; no normalization&lt;BR /&gt;&amp;nbsp; mac-sticky enable&lt;BR /&gt;&amp;nbsp; service-policy input Accel_SLB_policy&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;interface vlan 281&lt;BR /&gt;&amp;nbsp; description ### F5 ASM side ###&lt;BR /&gt;&amp;nbsp; ip address 10.25.245.10 255.255.255.0&lt;BR /&gt;&amp;nbsp; no normalization&lt;BR /&gt;&amp;nbsp; mac-sticky enable&lt;BR /&gt;&amp;nbsp; service-policy input Web_SLB_policy&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;interface vlan 291&lt;BR /&gt;&amp;nbsp; description ### Server side ###&lt;BR /&gt;&amp;nbsp; ip address 10.26.74.2 255.255.255.0&lt;BR /&gt;&amp;nbsp; no normalization&lt;BR /&gt;&amp;nbsp; mac-sticky enable&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DR-ACE-01/PORTAL-TIER1# &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DR-ACE-01/PORTAL-TIER1# sh conn address 172.20.133.88 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;conn-id&amp;nbsp;&amp;nbsp;&amp;nbsp; np dir proto vlan source&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; destination&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; state &lt;BR /&gt;----------+--+---+-----+----+---------------------+---------------------+------+&lt;BR /&gt;36750&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; in&amp;nbsp; TCP&amp;nbsp;&amp;nbsp; 271&amp;nbsp; 172.20.133.88:61234&amp;nbsp;&amp;nbsp; 172.20.133.100:80&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ESTAB &lt;BR /&gt;35100&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1&amp;nbsp; out TCP&amp;nbsp;&amp;nbsp; 281&amp;nbsp; 172.20.133.100:80&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.20.133.88:61234&amp;nbsp;&amp;nbsp; ESTAB &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Missing&amp;nbsp; in TCP 281 to out TCP 291....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;F5 ASM point 10.25.245.1 (ACE VIP) as gateway.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;YokeChuan&lt;/P&gt;</description>
      <pubDate>Fri, 22 Feb 2013 06:18:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-with-f5-asm/m-p/2164497#M39746</guid>
      <dc:creator>chenyokechuan</dc:creator>
      <dc:date>2013-02-22T06:18:01Z</dc:date>
    </item>
    <item>
      <title>Cisco ACE with F5 ASM</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-with-f5-asm/m-p/2164498#M39747</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest to pass the traffic to F5 first and then to ACE. Why would you need to pass traffic from ACE twice. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I would suggest this way : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client traffic on VLAN 10 &amp;gt;&amp;gt; Web application firewall VLAN 10&amp;nbsp; &amp;gt;&amp;gt;&amp;gt;&amp;gt; screens the traffic &amp;gt;&amp;gt;&amp;gt;&amp;gt; Pass it to Vlan 11 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;&amp;gt;&amp;gt; VLAN 11 is forwarded to ACE &amp;gt;&amp;gt;&amp;gt; ACE load balance the traffic &amp;gt;&amp;gt;&amp;gt;&amp;gt; Pass it to vlan 12 ( server vlan) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards, &lt;/P&gt;&lt;P&gt;Ajay Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2013 08:58:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-with-f5-asm/m-p/2164498#M39747</guid>
      <dc:creator>ajayku2</dc:creator>
      <dc:date>2013-02-22T08:58:41Z</dc:date>
    </item>
    <item>
      <title>Cisco ACE with F5 ASM</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-with-f5-asm/m-p/2164499#M39748</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ajay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply and suggestion.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Current client production network, ACE are perform VIP loadbalance for existing server farm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client don't plan to modify current network setup. That why F5 ASM are setup to attach with ACE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are ACE able to handle this kind setup? (traffic pass ACE twice)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;YokeChuan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Feb 2013 05:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-with-f5-asm/m-p/2164499#M39748</guid>
      <dc:creator>chenyokechuan</dc:creator>
      <dc:date>2013-02-25T05:54:51Z</dc:date>
    </item>
    <item>
      <title>Cisco ACE with F5 ASM</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-with-f5-asm/m-p/2164500#M39749</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Yoke, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is possible. You just have to create two ACE context. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE context 1 --&amp;nbsp;&amp;nbsp;&amp;nbsp; Vlan 10 ( Client )&amp;nbsp; ----&amp;nbsp; Vlan 11 ( Web app firewall ) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE context 2 -- VLAN 12 ( Web app firewall traffic ) --- Vlan 13 ( Serverfarm)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also read the following : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;STRONG&gt;By default, the ACE does not allow traffic from one context to another&amp;nbsp; context over a transparent firewall. &lt;/STRONG&gt;The ACE assumes that VLANs in&amp;nbsp; different contexts are in different Layer 2 domains, unless it is a&amp;nbsp; shared VLAN. The ACE allocates the same MAC address to the VLANs. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1062064"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; When you are using a firewall service module (FWSM) to bridge traffic&amp;nbsp; between two contexts on the ACE, you must assign two Layer 3 VLANs to&amp;nbsp; the same bridge domain. To support this configuration, these VLAN&amp;nbsp; interfaces require different MAC addresses. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1062078"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; To enable the autogeneration of a MAC address on a VLAN interface, use the &lt;STRONG&gt;mac address autogenerate&lt;/STRONG&gt; command in interface configuration mode. The syntax of this command is as follows: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1062065"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt;mac address autogenerate &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards, &lt;/P&gt;&lt;P&gt;Ajay Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Feb 2013 08:00:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-with-f5-asm/m-p/2164500#M39749</guid>
      <dc:creator>ajayku2</dc:creator>
      <dc:date>2013-02-25T08:00:15Z</dc:date>
    </item>
    <item>
      <title>Cisco ACE with F5 ASM</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-with-f5-asm/m-p/2164501#M39750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Ajay,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have create 2 context as suggested, but i still confuse on WAF routing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below are configuration file for Portal-Teir1 and Web-Server context.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DR-ACE-01/PORTAL-TIER1# sh run&lt;BR /&gt;Generating configuration....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;access-list ANYONE line 8 extended permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;probe icmp ICMP&lt;BR /&gt;&amp;nbsp; interval 2&lt;BR /&gt;&amp;nbsp; faildetect 4&lt;BR /&gt;&amp;nbsp; passdetect interval 4&lt;BR /&gt;&amp;nbsp; passdetect count 4&lt;/P&gt;&lt;P&gt;rserver host F5_ASM_01&lt;BR /&gt;&amp;nbsp; ip address 10.25.245.4&lt;BR /&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;serverfarm host F5_ASM&lt;BR /&gt;&amp;nbsp; transparent&lt;BR /&gt;&amp;nbsp; failaction purge&lt;BR /&gt;&amp;nbsp; predictor hash address source&lt;BR /&gt;&amp;nbsp; probe ICMP&lt;BR /&gt;&amp;nbsp; rserver F5_ASM_01&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;class-map type management match-any Mgmt_class&lt;BR /&gt;&amp;nbsp; 2 match protocol icmp any&lt;BR /&gt;&amp;nbsp; 3 match protocol snmp any&lt;BR /&gt;&amp;nbsp; 4 match protocol telnet any&lt;BR /&gt;&amp;nbsp; 5 match protocol ssh any&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;class-map match-all Web_80_class&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 172.20.133.100 tcp eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type management first-match Mgmt_policy&lt;BR /&gt;&amp;nbsp; class Mgmt_class&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match F5_ASM_policy&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm F5_ASM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match Accel_SLB_policy&lt;BR /&gt;&amp;nbsp; class Web_80_class&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy F5_ASM_policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-policy input Mgmt_policy&lt;BR /&gt;access-group input ANYONE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 271&lt;BR /&gt;&amp;nbsp; description ### Client side ###&lt;BR /&gt;&amp;nbsp; ip address 172.20.133.27 255.255.255.0&lt;BR /&gt;&amp;nbsp; no normalization&lt;BR /&gt;&amp;nbsp; mac-sticky enable&lt;BR /&gt;&amp;nbsp; service-policy input Accel_SLB_policy&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;interface vlan 281&lt;BR /&gt;&amp;nbsp; description ### F5 ASM side ###&lt;BR /&gt;&amp;nbsp; ip address 10.25.245.10 255.255.255.0&lt;BR /&gt;&amp;nbsp; no normalization&lt;BR /&gt;&amp;nbsp; mac-sticky enable&lt;BR /&gt;&amp;nbsp; mac-address autogenerate&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DR-ACE-01/PORTAL-TIER1# &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DR-ACE-01/WEB-Server# sh run&lt;BR /&gt;Generating configuration....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ANYONE line 8 extended permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;probe tcp TCP_80&lt;BR /&gt;&amp;nbsp; interval 2&lt;BR /&gt;&amp;nbsp; faildetect 4&lt;BR /&gt;&amp;nbsp; passdetect interval 4&lt;BR /&gt;&amp;nbsp; passdetect count 4&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host SSCP_01&lt;BR /&gt;&amp;nbsp; ip address 10.26.74.21&lt;BR /&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;rserver host SSCP_02&lt;BR /&gt;&amp;nbsp; ip address 10.26.74.22&lt;BR /&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host Web_farm&lt;BR /&gt;&amp;nbsp; failaction purge&lt;BR /&gt;&amp;nbsp; predictor hash address source&lt;BR /&gt;&amp;nbsp; probe TCP_80&lt;BR /&gt;&amp;nbsp; rserver SSCP_01&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;BR /&gt;&amp;nbsp; rserver SSCP_02&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;class-map type management match-any Mgmt_class&lt;BR /&gt;&amp;nbsp; 2 match protocol icmp any&lt;BR /&gt;&amp;nbsp; 3 match protocol snmp any&lt;BR /&gt;&amp;nbsp; 4 match protocol telnet any&lt;BR /&gt;&amp;nbsp; 5 match protocol ssh any&lt;/P&gt;&lt;P&gt;class-map match-all Web_80_class&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 10.26.75.100 tcp eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type management first-match Mgmt_policy&lt;BR /&gt;&amp;nbsp; class Mgmt_class&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match Web_policy&lt;BR /&gt;&amp;nbsp; class class-default&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm Web_farm&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match Web_SLB_policy&lt;BR /&gt;&amp;nbsp; class Web_80_class&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy Web_policy&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service-policy input Mgmt_policy&lt;BR /&gt;access-group input ANYONE&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 291&lt;BR /&gt;&amp;nbsp; ip address 10.26.74.2 255.255.255.0&lt;BR /&gt;&amp;nbsp; no normalization&lt;BR /&gt;&amp;nbsp; no shutdown&lt;BR /&gt;interface vlan 292&lt;BR /&gt;&amp;nbsp; ip address 10.26.75.2 255.255.255.0&lt;BR /&gt;&amp;nbsp; no normalization&lt;BR /&gt;&amp;nbsp; mac-sticky enable&lt;BR /&gt;&amp;nbsp; service-policy input Web_SLB_policy&lt;BR /&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;DR-ACE-01/WEB-Server# &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do i still need a VIP for VLAN 292? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;WAF should route to VLAN 292 VIP or just a normal routing to interface?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have any sample for reference? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advanced.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;YokeChuan&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/4/7/130743-ACE.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2013 09:23:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-with-f5-asm/m-p/2164501#M39750</guid>
      <dc:creator>chenyokechuan</dc:creator>
      <dc:date>2013-02-27T09:23:46Z</dc:date>
    </item>
    <item>
      <title>Cisco ACE with F5 ASM</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-with-f5-asm/m-p/2164502#M39751</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This should help you. The only thing which is different is you are not doing firewall load balancing. Rest everything will help you to configure in right way. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA1_7_/configuration/slb/guide/fwldbal.html"&gt;http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA1_7_/configuration/slb/guide/fwldbal.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards, &lt;/P&gt;&lt;P&gt;Ajay Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Feb 2013 10:16:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-with-f5-asm/m-p/2164502#M39751</guid>
      <dc:creator>ajayku2</dc:creator>
      <dc:date>2013-02-27T10:16:04Z</dc:date>
    </item>
  </channel>
</rss>

