<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CSS11503 config problems in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/css11503-config-problems/m-p/273752#M4095</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon, a quick suggestion : post your config and network diagram so we can better understand what you are doing.&lt;/P&gt;&lt;P&gt;Then, explain us exactly the problem. &lt;/P&gt;&lt;P&gt;This is not clear to me.&lt;/P&gt;&lt;P&gt;You first ask if there is a better way to achive this - with the limitation that You have I don't think so.&lt;/P&gt;&lt;P&gt;Unless you are ready to change the ip addressing scheme, which I would suggest you to do.&lt;/P&gt;&lt;P&gt;Then you mention some problems with HTTPS traffic, but nowhere else in your explanation did you talk about https.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, send us config and diagram and an explanation of the problem - one at a time - so start with the most important first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Jun 2004 08:58:24 GMT</pubDate>
    <dc:creator>Gilles Dufour</dc:creator>
    <dc:date>2004-06-23T08:58:24Z</dc:date>
    <item>
      <title>CSS11503 config problems</title>
      <link>https://community.cisco.com/t5/application-networking/css11503-config-problems/m-p/273751#M4094</link>
      <description>&lt;P&gt;Hello all &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am new to the 11503 switches and would appreciate some help with the config. We are replacing our LD417G's with these switches and because of our current DMZ setup &amp;amp; ip addressing i cannot setup the 11503's in router mode. What i have done is: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Create 2 vlan's (10 &amp;amp; 11) using the same ip subnet&lt;/P&gt;&lt;P&gt;2) On the 11503 i have only one circuit for vlan 1.&lt;/P&gt;&lt;P&gt;3) I have connected the reverse proxies to vlan 11 and one of the 11503 interfaces.&lt;/P&gt;&lt;P&gt;4) on vlan 10 is the default gateway ( a pix dmz interface ), none loadbalanced servers and another interface from the 11503. &lt;/P&gt;&lt;P&gt;5) All servers ( loadbalanced and non-loadbalanced have their default gateway set as the pix dmz interface ). &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Consequently all client traffic to the reverse proxies go through the 11503. Only real problem is when the reverse proxies talk to their server counterparts (as oppose to the clients ) they have to through the 11503. We tested it by checking the proxy logs and it does seem to be load balancing the client requests ( altho "sh flows" doesn't seem to show much ).  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My questions:- &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) Is there a better way of trying to achieve this. I am unfortunatley limited to one ip subnet for the loadbalancer, the reverse proxies and the non-loadbalanced servers. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Would this setup be affecting the operation of the SSL module. I packet sniffed the https connection and saw a full tcp handshake, packets being sent from the client but no responses from the 11503. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help / advice would be very much appreciated&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2004 17:44:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css11503-config-problems/m-p/273751#M4094</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2004-06-22T17:44:28Z</dc:date>
    </item>
    <item>
      <title>Re: CSS11503 config problems</title>
      <link>https://community.cisco.com/t5/application-networking/css11503-config-problems/m-p/273752#M4095</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jon, a quick suggestion : post your config and network diagram so we can better understand what you are doing.&lt;/P&gt;&lt;P&gt;Then, explain us exactly the problem. &lt;/P&gt;&lt;P&gt;This is not clear to me.&lt;/P&gt;&lt;P&gt;You first ask if there is a better way to achive this - with the limitation that You have I don't think so.&lt;/P&gt;&lt;P&gt;Unless you are ready to change the ip addressing scheme, which I would suggest you to do.&lt;/P&gt;&lt;P&gt;Then you mention some problems with HTTPS traffic, but nowhere else in your explanation did you talk about https.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So, send us config and diagram and an explanation of the problem - one at a time - so start with the most important first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jun 2004 08:58:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css11503-config-problems/m-p/273752#M4095</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2004-06-23T08:58:24Z</dc:date>
    </item>
  </channel>
</rss>

