<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSS11051 balancing services behind a firewall in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/css11051-balancing-services-behind-a-firewall/m-p/271279#M4031</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are these new connections? or Do you see the CSS forwarding  new SYNs to the old MAC? What version?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; CSCdy46189 When a Gratuitous ARP (GARP) was received the CSS would not update existing flows with the new MAC and thus existing flows would be sent from the CSS would the incorrect MAC and be dropped. Only new flows and new keepalive requests were using the 	updated ARP information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fixed by 5.00.2.04.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Feb 2004 09:16:53 GMT</pubDate>
    <dc:creator>mvoight</dc:creator>
    <dc:date>2004-02-12T09:16:53Z</dc:date>
    <item>
      <title>CSS11051 balancing services behind a firewall</title>
      <link>https://community.cisco.com/t5/application-networking/css11051-balancing-services-behind-a-firewall/m-p/271278#M4030</link>
      <description>&lt;P&gt;Is it possible to configure the CSS11051 to balance http servers behind a firewall cluster?&lt;/P&gt;&lt;P&gt;We put the CSS in a proxy zone of our Symantec Enterprise Firewall Cluster to balance our direct attached SSL Terminators. Now we want to balance the webservers on the internal LAN of the firewall cluster based on Rainwall. It works, but if we shut down the firewall with the virtual IP something strange happens:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. The services are up and I can see the keepalives going through the other firewall but the packets with the payload still going to the MAC Address of the broken firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is the service designed to use MAC Adresses and not to look in the ARP Table and why work keepalives different ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any Idea how to change this ??&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Carsten &lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2004 08:58:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css11051-balancing-services-behind-a-firewall/m-p/271278#M4030</guid>
      <dc:creator>carsten.otto</dc:creator>
      <dc:date>2004-02-12T08:58:36Z</dc:date>
    </item>
    <item>
      <title>Re: CSS11051 balancing services behind a firewall</title>
      <link>https://community.cisco.com/t5/application-networking/css11051-balancing-services-behind-a-firewall/m-p/271279#M4031</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are these new connections? or Do you see the CSS forwarding  new SYNs to the old MAC? What version?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could be:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; CSCdy46189 When a Gratuitous ARP (GARP) was received the CSS would not update existing flows with the new MAC and thus existing flows would be sent from the CSS would the incorrect MAC and be dropped. Only new flows and new keepalive requests were using the 	updated ARP information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fixed by 5.00.2.04.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2004 09:16:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css11051-balancing-services-behind-a-firewall/m-p/271279#M4031</guid>
      <dc:creator>mvoight</dc:creator>
      <dc:date>2004-02-12T09:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: CSS11051 balancing services behind a firewall</title>
      <link>https://community.cisco.com/t5/application-networking/css11051-balancing-services-behind-a-firewall/m-p/271280#M4032</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for the quick response !!!&lt;/P&gt;&lt;P&gt;We are using ap0500045 and I assume that an update will fix our problem. Indeed I can see SYN's to the old MAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BTW:Where can I have a look on the notes e.g. CSCdy46189 you send me ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks &lt;/P&gt;&lt;P&gt;Carsten&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2004 09:30:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css11051-balancing-services-behind-a-firewall/m-p/271280#M4032</guid>
      <dc:creator>carsten.otto</dc:creator>
      <dc:date>2004-02-12T09:30:55Z</dc:date>
    </item>
    <item>
      <title>Re: CSS11051 balancing services behind a firewall</title>
      <link>https://community.cisco.com/t5/application-networking/css11051-balancing-services-behind-a-firewall/m-p/271281#M4033</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Carsten, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You can see release note info in Bug Toolkit&lt;/P&gt;&lt;P&gt;This is located at &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/kobayashi/support/tac/tools.shtml" target="_blank"&gt;http://www.cisco.com/kobayashi/support/tac/tools.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Go there and select the link for "Software Bug Toolkit" under the "Troubleshooting Tools" section.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is the public release note:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CSS forwards packets to the wrong MAC after receiving gratuitous ARP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The updated MAC address of a service or next hop used to reach the&lt;/P&gt;&lt;P&gt;service or client is used for new flows only. The existing flows&lt;/P&gt;&lt;P&gt;are not modified and packets are sent to previous MAC address and lost.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Feb 2004 09:47:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css11051-balancing-services-behind-a-firewall/m-p/271281#M4033</guid>
      <dc:creator>mvoight</dc:creator>
      <dc:date>2004-02-12T09:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: CSS11051 balancing services behind a firewall</title>
      <link>https://community.cisco.com/t5/application-networking/css11051-balancing-services-behind-a-firewall/m-p/271282#M4034</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;nice try but&lt;/P&gt;&lt;P&gt;after updating the IOS I can still see the old Mac-Address in the requests to the firewall. Also new connections to the content use the old Mac but the Arptable is up to date and the service checks are positiv. Why are the services alive while connects to the service fail, using the old Mac. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is my config for the servicve:&lt;/P&gt;&lt;P&gt;service 1&lt;/P&gt;&lt;P&gt;  keepalive type http&lt;/P&gt;&lt;P&gt;  port 7777&lt;/P&gt;&lt;P&gt;  ip address 10.11.70.11&lt;/P&gt;&lt;P&gt;  active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service 2&lt;/P&gt;&lt;P&gt;  keepalive type http&lt;/P&gt;&lt;P&gt;  port 7777&lt;/P&gt;&lt;P&gt;  ip address 10.11.70.12&lt;/P&gt;&lt;P&gt;  active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service SSL1&lt;/P&gt;&lt;P&gt;  port 443&lt;/P&gt;&lt;P&gt;  ip address 10.11.64.11&lt;/P&gt;&lt;P&gt;  keepalive type tcp&lt;/P&gt;&lt;P&gt;  keepalive port 443&lt;/P&gt;&lt;P&gt;  active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service SSL2&lt;/P&gt;&lt;P&gt;  port 443&lt;/P&gt;&lt;P&gt;  ip address 10.11.64.30&lt;/P&gt;&lt;P&gt;  keepalive type tcp&lt;/P&gt;&lt;P&gt;  keepalive port 443&lt;/P&gt;&lt;P&gt;  active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;owner http-server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  content http&lt;/P&gt;&lt;P&gt;    add service 2&lt;/P&gt;&lt;P&gt;    add service 1&lt;/P&gt;&lt;P&gt;    vip address 10.11.64.100&lt;/P&gt;&lt;P&gt;    balance leastconn&lt;/P&gt;&lt;P&gt;    protocol tcp&lt;/P&gt;&lt;P&gt;    port 7777&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;owner SSL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  content SSL-Accelerator&lt;/P&gt;&lt;P&gt;    balance aca&lt;/P&gt;&lt;P&gt;    protocol tcp&lt;/P&gt;&lt;P&gt;    port 443&lt;/P&gt;&lt;P&gt;    url "/*"&lt;/P&gt;&lt;P&gt;    advanced-balance ssl&lt;/P&gt;&lt;P&gt;    application ssl&lt;/P&gt;&lt;P&gt;    add service SSL1&lt;/P&gt;&lt;P&gt;    add service SSL2&lt;/P&gt;&lt;P&gt;    vip address 10.11.70.200&lt;/P&gt;&lt;P&gt;    active&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I miss something in my config  ?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Carsten&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 17 Feb 2004 15:59:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css11051-balancing-services-behind-a-firewall/m-p/271282#M4034</guid>
      <dc:creator>carsten.otto</dc:creator>
      <dc:date>2004-02-17T15:59:14Z</dc:date>
    </item>
  </channel>
</rss>

