<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Ask the Expert: Configuration and Troubleshooting the Cisco Appl in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213713#M40140</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your explanation and detailed config sample. I helped a lot for me to understand the concept but it might not be applicable to our environment. We have a multi-tenant load balancing setup and multiple class-maps are applied. Futhermore, class-default has already been used for some other servers, which is a different sticky server farm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to set a uri redirect, similar to an iRule in F5 to force client browser to go to /project/ if they are coming without a / (force /project to /project/) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The current setup is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 match http url /project.*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which works fine for /project/ but it does not respond to /project&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your explanation on the access-group and policy-map is very clear. Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Wishes,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James Ren&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 23 Jul 2013 15:41:49 GMT</pubDate>
    <dc:creator>Jing Ren</dc:creator>
    <dc:date>2013-07-23T15:41:49Z</dc:date>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Application Control Engine (ACE) load balancer</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213702#M40129</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;STRONG&gt;With Ajay Kumar &lt;/STRONG&gt;&lt;STRONG&gt;and Telmo Pereira&amp;nbsp; &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;IMG align="left" alt="Ajay Kumar " border="0" height="99" hspace="10" src="https://community.cisco.com/legacyfs/online/legacy/9/7/9/144979-ajayku2.jpeg" style="padding-bottom: 20px; padding-right: 10px;" width="84" /&gt;&lt;IMG align="left" alt="Telmo Pereira" border="0" height="104" hspace="10" src="https://community.cisco.com/legacyfs/online/legacy/3/1/5/145513-tepereir.jpeg" style="padding-bottom: 20px; padding-right: 10px;" width="94" /&gt;Welcome to the Cisco Support Community Ask the Expert conversation. This is an opportunity to learn and ask questions about configuration and troubleshooting the Cisco Application Control Engine (ACE) load balancer with Cisco expert Ajay Kumar and Telmo Pereira. The Cisco ACE Application Control Engine Module for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers is a next-generation load-balancing and application-delivery solution. A member of the Cisco family of Data Center 3.0 solutions, the module: Helps ensure business continuity by increasing application availability Improves business productivity by accelerating application and server performance Reduces data center power, space, and cooling needs through a virtualized architecture Helps lower operational costs associated with application provisioning and scaling&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Ajay Kumar&amp;nbsp; &lt;/STRONG&gt;is a customer support engineer in the Cisco Technical Assistance Center in Brussels, covering content delivery network technologies including Cisco Application Control Engine, Cisco Wide Area Application Services, Cisco Content Switching Module, Cisco Content Services Switches, and others. He has been with Cisco for more than four years, working with major customers to help resolve their issues related to content products. He holds DCASI and VCP certifications.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Telmo Pereira &lt;/STRONG&gt;is a customer support engineer in the Cisco Technical Assistance Center in Brussels, where he covers all Cisco content delivery network technologies including Cisco Application Control Engine (ACE), Cisco Wide Area Application Services (WAAS), and Digital Media Suite. He has worked with multiple customers around the globe, helping them solve interesting and often highly complex issues. Pereira has worked in the networking field for more than 7 years. He holds a computer science degree as well as multiple certifications including CCNP, DCASI, DCUCI, and VCP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Remember to use the rating system to let Ajay know if you have received an adequate response.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Ajay and Telmo might not be able to answer each question due to the volume expected during this event. Remember that you can continue the conversation on the Data Center sub-community discussion forum &lt;A _jive_internal="true" href="https://community.cisco.com/community/netpro/data-center/application-network" rel="nofollow"&gt;Application Networking&lt;/A&gt; shortly after the event. &lt;STRONG&gt; &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;This event lasts through July 26, 2013.&lt;/STRONG&gt; Visit this forum often to view responses to your questions and the questions of other community members.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Mon, 15 Jul 2013 08:30:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213702#M40129</guid>
      <dc:creator>ciscomoderator</dc:creator>
      <dc:date>2013-07-15T08:30:25Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213703#M40130</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am planning to upgrade my ACE and would like to know the best practices for the same? &lt;/P&gt;&lt;P&gt;Will there be a downtime or it can be a hitless upgrade. I think it should be simple but need your opinion. I think I can start with upgrade of standby.&amp;nbsp; If for some reason ACE doesn’t boot up what would be the recovery steps. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate your quick response.&lt;/P&gt;&lt;P&gt;-John&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 04:14:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213703#M40130</guid>
      <dc:creator>John Ventura</dc:creator>
      <dc:date>2013-07-22T04:14:56Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213704#M40131</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi John, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will there be a downtime or it can be a hitless upgrade.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;You dont need downtime to upgrade ACE. It can be a hitless upgrade. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;You can follow the procedure as described in link below: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/vA5_1_x/release/note/ACE_mod_rn_A51x.html#wp791479"&gt;http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/vA5_1_x/release/note/ACE_mod_rn_A51x.html#wp791479&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;From the above link :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Note&amp;nbsp; : &lt;/SPAN&gt;&lt;STRONG style="font-size: 10pt; "&gt;Ensure that the preempt command is disabled before the upgrade procedure begins.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt;It is also true that you first upgrade standby and then Primary. The above mentioned link is the best way to upgrade ACE. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;------------------------------------------------------------&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt;If for some reason ACE does not boot up. Below is the recovery procedure: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt;Usually it get stuck in rommon mode: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can refer the following link :&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://docwiki.cisco.com/wiki/Cisco_Application_Control_Engine_(ACE)_Troubleshooting_Guide_--_Troubleshooting_ACE_Boot_Issues"&gt;http://docwiki.cisco.com/wiki/Cisco_Application_Control_Engine_(ACE)_Troubleshooting_Guide_--_Troubleshooting_ACE_Boot_Issues&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;refer topic : " &lt;STRONG&gt;Booting the ACE from the ROMMON Prompt"&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt;In the above you can mention the old image and ACE should boot properly with the old ACE image. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if that answer your question. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards, &lt;/P&gt;&lt;P&gt;Ajay Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 07:18:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213704#M40131</guid>
      <dc:creator>ajayku2</dc:creator>
      <dc:date>2013-07-22T07:18:23Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213705#M40132</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello John!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the first post on this session! Just to add some additional information to what Ajay has shared. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We do have a hitless upgrade, but refers to L4 connections which can be replicated (if you do have connection replication enabled on your system). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However be aware that there will be a &lt;SPAN style="font-size: 10pt;"&gt;hit on L7 connections (SSL offload, TCP Reuse, Inspect, &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;etc). Meaning those connections will have to be reestablished on the secondary ACE. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;In that sense, if you do have any contexts with layer 7 configuration, or even if do have only L4, the g&lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;eneral recommendation for that matter is to schedule a maintenance window for the upgrade operation. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Also as per best practice we recommend: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. To disable preemption (as Ajay mentioned) and upgrade the standby box for the Admin context&lt;/P&gt;&lt;P&gt;2. Then you reboot the standby box on the new version of code and you do a failover of the contexts to that box. &lt;/P&gt;&lt;P&gt;You will see how the system behaves. If there are any issues, you can simply fallback to the other ACE that will still be on the old version of code. &lt;/P&gt;&lt;P&gt;3. Assuming everything goes well on 2, you will go ahead and upgrade the other ACE and once if comes back, you can failover the traffic to it again and reenabe preempt. &lt;/P&gt;&lt;P&gt;This is documented, on a step by step basis on the link provided by Ajay. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Telmo &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 07:24:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213705#M40132</guid>
      <dc:creator>Telmo Pereira</dc:creator>
      <dc:date>2013-07-22T07:24:51Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213706#M40133</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Ajay.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 09:55:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213706#M40133</guid>
      <dc:creator>John Ventura</dc:creator>
      <dc:date>2013-07-22T09:55:38Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213707#M40134</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Telmo.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 09:59:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213707#M40134</guid>
      <dc:creator>John Ventura</dc:creator>
      <dc:date>2013-07-22T09:59:44Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213708#M40135</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear AJay and Telmo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for your time to look at this. We have a pair of ACE4710 running in active/standby. We've setup a web services to load balance &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://www.mydomain.com/project/"&gt;https://www.mydomain.com/project/&lt;/A&gt;&lt;SPAN&gt; to 6 backend servers. The servers could accept uri path of /project/ and /project (with or without a /).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What are the steps to configure on ACE to be able to accept traffic for both / and without /?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my second question is, do I need to configure both access-group and service-policy on all the interfaces to pass the traffic? What are the differences betweeen an access-group and a service-policy?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you in advance,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James Ren&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 11:57:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213708#M40135</guid>
      <dc:creator>Jing Ren</dc:creator>
      <dc:date>2013-07-22T11:57:00Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213709#M40136</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jing, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for posting! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In order to meet your requirements you would have a similar configuration to the one below:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the requested URL is /project, then send to the PROJECT-FARM, otherwise send to web farm.&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;-- CONF snippet -- &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ANYONE line 10 extended permit tcp any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;rserver host WWW_SERVER_01&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.10.10.10&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host WWW_SERVER_02&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.10.10.11&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host WWW_SERVER_03&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.10.10.12&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host LOGIN_SERVER_04&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.10.10.15&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host WWW-FARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe TCP&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver WWW_SERVER_01&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver WWW_SERVER_02&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver WWW_SERVER_03&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host PROJECT-FARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe TCP&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver LOGIN_SERVER_04&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all WWW-VIP&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 20.20.20.10 tcp eq www&lt;/P&gt;&lt;P&gt;class-map type http loadbalance match-any CLASS-PROJECT&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match http url /project.*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match SLB_LOGIC&lt;/P&gt;&lt;P&gt;&amp;nbsp; class CLASS-PROJECT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm PROJECT-FARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm WWW-FARM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match CLIENT_VIPS&lt;/P&gt;&lt;P&gt;&amp;nbsp; class WWW-VIP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy SLB_LOGIC&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 10&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Servers vlan&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN style="font-size: 10pt;"&gt;access-group input ANYONE&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp; ip address 10.10.10.5 255.255.255.0&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;interface vlan 20&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Client vlan&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 20.20.20.9 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input ANYONE&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input CLIENT_VIPS&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 20.20.20.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the second query, you just need to be aware that by default ACE will not pass any traffic (will deny everything), unless we permit it.&lt;/P&gt;&lt;P&gt;The access-group will be used to tie the access-list to an interface and this is normally needed on all interfaces if you are going to pass any sort of traffic on them. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The service-policy may or not be needed on all interfaces. In the example I gave you, I only apply service-policy on the client vlan as I will only have hits for the VIP on that side. &lt;/P&gt;&lt;P&gt;If on the other hand, servers could also initiate connections to the VIP, you would have to apply the service policy on that other interface also. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if this makes things clearer, if not I can provide more details. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Telmo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 12:14:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213709#M40136</guid>
      <dc:creator>Telmo Pereira</dc:creator>
      <dc:date>2013-07-22T12:14:02Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213710#M40137</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Jing, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just to add a bit on Telmo's reply. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What are the differences betweeen an access-group and a service-policy?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;We apply access group to any interface to define what traffic should be allowed or dropped when hitting a interface. Similar to any firewall access list/access group. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Service policy is like a set of instruction to match the interesting traffic based on defined associated class match and to define how to load balance the traffic. So I would say that load balancing decisions are based on service policy. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;regards, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Ajay Kumar&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 Jul 2013 12:57:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213710#M40137</guid>
      <dc:creator>ajayku2</dc:creator>
      <dc:date>2013-07-22T12:57:31Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213711#M40138</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello, Expert.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In the case that two servers are on the each end sides of firewall (one on DMZ and another on INSIDE), is there a way to load-balance the traffic from one to another server between firewall A and B, using the ACE 4710? Or, there is a way to load-balance the traffic using source port number?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for reading it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 07:48:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213711#M40138</guid>
      <dc:creator>jeongdae.lee</dc:creator>
      <dc:date>2013-07-23T07:48:49Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213712#M40139</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jeongdae, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the question. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As per my understanding you want to load balance in the following way : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall DMZ ( Server in DMZ zone acting as client ) &amp;gt;&amp;gt; Cisco ACE &amp;gt;&amp;gt; Firewall Inside ( Server in INSIDE zone )&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is usual load balancing scenerio in routing mode. This can be achieved by simple routing mode config: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please refer following link for routing mode config. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://docwiki.cisco.com/wiki/Basic_Load_Balancing_Using_Routed_Mode_on_the_Cisco_Application_Control_Engine_Configuration_Example"&gt;http://docwiki.cisco.com/wiki/Basic_Load_Balancing_Using_Routed_Mode_on_the_Cisco_Application_Control_Engine_Configuration_Example&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is possible to load balance using source IP address. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sample config : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;class-map match-any TEST-VIP&lt;BR /&gt;&amp;nbsp; 3 match virtual-address x.x.x.x eq any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;serverfarm SF1&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&amp;nbsp; rserver A&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&amp;nbsp; rserver B&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;class-map type http loadbalance match-any SRC-IP-MATCH&lt;BR /&gt;&amp;nbsp; 2 match source-address a.a.a.a 255.255.255.255&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;policy-map type loadbalance first-match Policy1&lt;BR /&gt;&amp;nbsp; class SRC-IP-MATCH&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm SF1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;policy-map multi-match Mpolicy1&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&amp;nbsp; class &lt;SPAN style="font-family: arial, helvetica, sans-serif; font-size: 10pt;"&gt;TEST-VIP&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy Policy1&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip advertise&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;interface vlan yyy&lt;/P&gt;&lt;P style="background-color: #f7fafb; border-collapse: collapse; font-size: 12px; list-style: none; font-family: Arial, verdana, sans-serif;"&gt;service-pilicy .....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if that helps. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards, &lt;/P&gt;&lt;P&gt;Ajay Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 11:01:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213712#M40139</guid>
      <dc:creator>ajayku2</dc:creator>
      <dc:date>2013-07-23T11:01:15Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213713#M40140</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your explanation and detailed config sample. I helped a lot for me to understand the concept but it might not be applicable to our environment. We have a multi-tenant load balancing setup and multiple class-maps are applied. Futhermore, class-default has already been used for some other servers, which is a different sticky server farm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it possible to set a uri redirect, similar to an iRule in F5 to force client browser to go to /project/ if they are coming without a / (force /project to /project/) ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The current setup is &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2 match http url /project.*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;which works fine for /project/ but it does not respond to /project&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your explanation on the access-group and policy-map is very clear. Thank you!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best Wishes,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;James Ren&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 15:41:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213713#M40140</guid>
      <dc:creator>Jing Ren</dc:creator>
      <dc:date>2013-07-23T15:41:49Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213714#M40141</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;James, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The pleasure is all mine! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is possible to configure URL redirection on ACE, but it seems this would purely polute your configuration unnecessarily. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match http url /project.*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Should match both /project and /project/. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Actually it should also match URLs like /project/anythingelse.something&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.* is an expression that is supposed to match zero or more characters. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It would come as a suprise if it is not matching the request for /project. Is the request HTTP/1.1? What ACE version do you have? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, to give you an example of what a redirection would look like on ACE here it goes: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type http loadbalance match-any redirect-l7&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match http url /project&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match redirect-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; class redirect-l7&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm redirect-sf&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm redirect redirect-sf&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver redirect-sf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver redirect redirect-sf&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; webhost-redirection &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/"&gt;http://%h/project/&lt;/A&gt;&lt;SPAN&gt; 301&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;%h represents the hostname. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This has been documented here:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/v3.00_A2/configuration/slb/guide/rsfarms.html#wp1013201"&gt;http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/v3.00_A2/configuration/slb/guide/rsfarms.html#wp1013201&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Still, as mentioned, I don't see a need to apply redirection on this case. If &lt;SPAN style="font-size: 10pt;"&gt; "match http url /project.*" is not working for some reason just let me know and I will advise on next steps. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Regards, &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Telmo&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 19:30:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213714#M40141</guid>
      <dc:creator>Telmo Pereira</dc:creator>
      <dc:date>2013-07-23T19:30:55Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213715#M40142</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear Experts,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd like to ask you about configuration amendments for using sorry serverfarm (sorry page when primary sfarm fails) with regard to this specific example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host REAL_PRIMARY_1&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.1&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host REAL_PRIMARY_2&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.2&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host REAL_BACKUP_1&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.11&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host REAL_BACKUP_2&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.12&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host SFARM_PRIMARY&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;STRONG&gt;failaction reassign&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; predictor leastconns slowstart 30&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe PROBE_HTTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver REAL_PRIMARY_1 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; conn-limit max 10000 min 9900&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver REAL_PRIMARY_2 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; conn-limit max 10000 min 9900&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host SFARM_BACKUP&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;STRONG&gt;failaction reassign&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; predictor leastconns slowstart 30&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe PROBE_HTTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver REAL_BACKUP_1 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver REAL_BACKUP_2 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky ip-netmask 255.255.255.255 address source STICKY_PRIMARY&lt;/P&gt;&lt;P&gt;&amp;nbsp; timeout 120&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm SFARM_PRIMARY &lt;STRONG&gt;backup SFARM_BACKUP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;sticky http-cookie BACKUP_ID STICKY_BACKUP&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; cookie insert&lt;/P&gt;&lt;P&gt;&amp;nbsp; timeout 60&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm SFARM_BACKUP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;action-list type modify http ACT_LIST_RW&lt;/P&gt;&lt;P&gt;&amp;nbsp; ssl url rewrite location ".*"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match PM_L7_PRIMARY&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm STICKY_PRIMARY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; action ACT_LIST_RW&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match PM_L7_BACKUP&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm STICKY_BACKUP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all CM_L3L4_PRIMARY&lt;/P&gt;&lt;P&gt;&amp;nbsp; 10 match virtual-address 10.0.0.100 tcp eq https&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all CM_L3L4_BACKUP&lt;/P&gt;&lt;P&gt;&amp;nbsp; 10 match virtual-address 10.0.0.200 tcp eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type connection PARA_MAP_CONN_TIMEOUT_120&lt;/P&gt;&lt;P&gt;&amp;nbsp; set timeout inactivity 120&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type http PARA_MAP_PERSIST_REBAL&lt;/P&gt;&lt;P&gt;&amp;nbsp; persistence-rebalance&lt;/P&gt;&lt;P&gt;&amp;nbsp; header modify per-request&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match PM_L3L4_PRIMARY&lt;/P&gt;&lt;P&gt;&amp;nbsp; class CM_L3L4_PRIMARY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy PM_L7_PRIMARY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options PARA_MAP_PERSIST_REBAL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy server SSL_PROXY_PRIMARY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options PARA_MAP_CONN_TIMEOUT_120&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match PM_L3L4_BACKUP&lt;/P&gt;&lt;P&gt;&amp;nbsp; class CM_L3L4_BACKUP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy PM_L7_BACKUP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options PARA_MAP_PERSIST_REBAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Client-side VLAN&lt;/P&gt;&lt;P&gt;&amp;nbsp; bridge-group 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; mac-sticky enable&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input ACL_ALLOW_BPDU&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input ACL_ALL_IP&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group output ACL_ALL_IP&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input PM_L3L4_PRIMARY&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input PM_L3L4_BACKUP&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 200&lt;/P&gt;&lt;P&gt;&amp;nbsp; description Server-side VLAN&lt;/P&gt;&lt;P&gt;&amp;nbsp; bridge-group 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; mac-sticky enable&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input ACL_ALLOW_BPDU&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input ACL_ALL_IP&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group output ACL_ALL_IP&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface bvi 100&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.0.0.252 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; alias 10.0.0.254 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; peer ip address 10.0.0.253 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My questions for the above example:&lt;/P&gt;&lt;P&gt;1) After making the first test, it seems that users who want to connect to a&amp;nbsp; failed primary page, then they see the sorry page. However, after&amp;nbsp; the primary sfarm is up, the users still see sorry page. What can cause that behaviour? Should I remove http cookie for the backup sfarm?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) How will failaction reassign work, when the primary sfarm will go down reaching the MAXCONN state?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) How will the ACE behave, when backup sfarm is configured under sticky of primary sfarm? Connections only for backup sfarm will be added into the sticky database?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) Is there something else to configure for sorry sfarm if the requirement is to configure backup sfarm as host not as a redirect sfarm (from cisco.com - there is an example for configuring sorry sfarm as redirect)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind of regards,&lt;/P&gt;&lt;P&gt;Krzysztof&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 20:25:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213715#M40142</guid>
      <dc:creator>Krzysztof Obara</dc:creator>
      <dc:date>2013-07-23T20:25:36Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213716#M40143</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Krzysztof, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here it goes the answers to your queries: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) This is expected behavior. Once the connections are on the backup serverfarm, they will stay there until they complete. But as you are suspecting stickiness also plays a role here. So assuming you have sticky for the backup serverfarm this is the behavior you should see: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;–All new sticky connections that match existing sticky table entries for the real servers in the backup server farm are stuck to the same real servers in the backup server farm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;–All new non-sticky connections and those sticky connections that do not have an entry in the sticky table are load balanced to the real servers in the primary server farm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hopefully this is what you are seeing &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) When you reach the MAXCONN threshold, you can expect that new connections will be sent to the backup farm. Depending on the platform you are using, this threshold value may be divided by the amount of IXPs (Network processors). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3) That is normally what we see customers doing, so in spite of having: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky ip-netmask 255.255.255.255 address source STICKY_PRIMARY&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt;timeout 120&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt;serverfarm SFARM_PRIMARY backup SFARM_BACKUP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky http-cookie BACKUP_ID STICKY_BACKUP&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN style="font-size: 10pt;"&gt;cookie insert&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; timeout 60&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; serverfarm SFARM_BACKUP&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You would simply do (note the sticky keyword after the backup farm): &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky ip-netmask 255.255.255.255 address source STICKY_PRIMARY&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN style="font-size: 10pt;"&gt;timeout 120&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN style="font-size: 10pt;"&gt;serverfarm SFARM_PRIMARY backup SFARM_BACKUP sticky&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And the behavior is exactly the same. If all the servers in the primary server farm go down, the ACE sends all new requests to the backup server farm. When the primary server farm comes back up (at least one server becomes active):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;•If the &lt;STRONG&gt;sticky&lt;/STRONG&gt; option is enabled, then:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;–All new sticky connections that match existing sticky table entries for the real servers in the backup server farm are stuck to the same real servers in the backup server farm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;–All new non-sticky connections and those sticky connections that do not have an entry in the sticky table are load balanced to the real servers in the primary server farm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;•If the &lt;STRONG&gt;sticky&lt;/STRONG&gt; option is not enabled, then the ACE load balances all new connections to the real servers in the primary server farm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;•Existing non-sticky connections to the servers in the backup server farm are allowed to complete in the backup server farm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This has been documented here:&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/slb/guide/sticky.html#wp1137791"&gt;http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/slb/guide/sticky.html#wp1137791&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) No, at first sight your configuration looks fine. However if I understood you correctly, you would need to remove sticky for the backup farm to meet your requirements. Or at least to achieve a behavior close to what you are expecting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Telmo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 21:55:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213716#M40143</guid>
      <dc:creator>Telmo Pereira</dc:creator>
      <dc:date>2013-07-23T21:55:05Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213717#M40144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Telmo,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you very much for your answers &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here are my conclusions:&lt;/P&gt;&lt;P&gt;1) &amp;amp; 3) As suspected, the stickiness caused the problem with users when the sorry page was triggered by them. I am about to remove the sticky http-cookie from the backup sfarm but what about this sentence from the link that you provided (the last paragraph under that section):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If you want to configure sorry servers and you&amp;nbsp; want existing connections to revert to the primary server farm after it&amp;nbsp; comes back up, do not use stickiness.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does it mean to not use stickiness for primary and backup sfarm or only for backup sfarm?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) I'm using ACE module on Cisco 6500 switch, IOS ver: A2(3.5) and there are 2 NP's. When using sorry sfarm, should I also remove failaction reassign? This action is rather used for passing traffic to stateful firewalls (as backups). Please correct me if I'm wrong &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) Regardless of understanding the above sentence from ACE config guide (I guess, they had in mind backup sfarm only), removing sticky from backup sfarm will solve the problem &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Much appreciated for your help,&lt;/P&gt;&lt;P&gt;Krzysztof&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 23 Jul 2013 23:29:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213717#M40144</guid>
      <dc:creator>Krzysztof Obara</dc:creator>
      <dc:date>2013-07-23T23:29:32Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213718#M40145</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Ajay. &lt;/P&gt;&lt;P&gt;Thanks for reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My network diagram is the following :&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Server1----&amp;gt;ACE1 ----&amp;gt; ASA1-----&amp;gt;ACE2-----&amp;gt;Server2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; | ------&amp;gt;ASA2----------|&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "DMZ"&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; |&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; "INSIDE"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Two servers are communicating with each other via specific tcp port numbers.&lt;/P&gt;&lt;P&gt;My problem is how to load-balance the traffic from server1 to server2 and vice versa through both ASA1 and ASA2.&lt;/P&gt;&lt;P&gt;Currently, the ASA1 only has the connections from server1 to server2.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for reading.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 01:22:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213718#M40145</guid>
      <dc:creator>jeongdae.lee</dc:creator>
      <dc:date>2013-07-24T01:22:59Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213719#M40146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jeongdae,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I understand it now. You can refer the following link to do firewall load balancing. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA3_1_0/configuration/slb/guide/fwldbal.html"&gt;http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA3_1_0/configuration/slb/guide/fwldbal.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;mac-sticky enable command is the one which does the trick here. It keeps the session with the same firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me know if you some specific question related to this setup. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;regards, &lt;/P&gt;&lt;P&gt;Ajay Kumar&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 07:02:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213719#M40146</guid>
      <dc:creator>ajayku2</dc:creator>
      <dc:date>2013-07-24T07:02:52Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213720#M40147</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;1) &amp;amp; 3) That sentence is only in reference to the backup farm. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) You are correct. &lt;SPAN style="font-size: 10pt;"&gt;Failaction reassign will simply begin sending packets to the &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;remaining/backup rserver.&amp;nbsp; There must be some logic to sync the state on &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;the OS/App across all of the rservers for this to work properly or the &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;new server will simply drop the connection, since it never saw the &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;handshake.&amp;nbsp; Typically you see this feature used with firewall load&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;balancing because firewalls are replicating their connection &lt;SPAN style="font-size: 10pt;"&gt;state tables.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4) Correct. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pleasure is all mine, hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Telmo&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 07:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213720#M40147</guid>
      <dc:creator>Telmo Pereira</dc:creator>
      <dc:date>2013-07-24T07:14:00Z</dc:date>
    </item>
    <item>
      <title>Ask the Expert: Configuration and Troubleshooting the Cisco Appl</title>
      <link>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213721#M40148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Telmo.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It really helped me &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 24 Jul 2013 15:28:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ask-the-expert-configuration-and-troubleshooting-the-cisco/m-p/2213721#M40148</guid>
      <dc:creator>Krzysztof Obara</dc:creator>
      <dc:date>2013-07-24T15:28:24Z</dc:date>
    </item>
  </channel>
</rss>

