<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACE - Inter-context traffic flow. in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395417#M41318</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Martin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was thinking about it and it is like loadbalancing to a server which is a HOP away. So how to do you that by doing routing so i guess in this case also you would need a route to VIP of different through another GATEWAY and vice-versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try that and let me know how it goes. So my first reply suggestion should hold good here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 22 Nov 2013 16:55:24 GMT</pubDate>
    <dc:creator>Kanwaljeet Singh</dc:creator>
    <dc:date>2013-11-22T16:55:24Z</dc:date>
    <item>
      <title>ACE - Inter-context traffic flow.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395412#M41313</link>
      <description>&lt;P&gt;Experts , &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please guide me for a traffic-flow mentioned below ? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Connection flow: &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;client IP 192.168.240.220 == VLAN721=[&lt;STRONG&gt;VIP 10.106.108.137&lt;/STRONG&gt;] ===VLAN 537[Server 10.106.24.133]&amp;lt;=={User context test1}&lt;/PRE&gt;&lt;PRE&gt;&lt;STRONG&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/STRONG&gt;&lt;/PRE&gt;&lt;PRE&gt; &lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[Server 10.106.24.133]=== VLAN 739==[&lt;STRONG&gt;VIP 10.106.112.59&lt;/STRONG&gt;] =====VLAN343 [Server 10.106.3.8]&amp;nbsp; &amp;lt;= {User Context test2}&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are two context test1 &amp;amp; test2 on the same ACE box resides in a&amp;nbsp; CAT6k ..&amp;nbsp; Just curious to know how to redirect the server (10.106.24.133) context test1&amp;nbsp;&amp;nbsp; to VIP (10.106.112.59) context test 2 which are not in a shared vlan .. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;context test 1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver redirect OASIS-SSO-STG2_OOS_REDIRECT&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; webhost-redirection &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://eportal-stg.publix.com/content/Associate/OutagePag"&gt;https://eportal-stg.publix.com/content/Associate/OutagePag&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host SITMA21&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.106.24.133&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe PING&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host SITMA22&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.106.24.138&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe PING&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt;serverfarm host L17SVWOASIS03_FARM&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; description oasis-sso-stg2 server farm&lt;/P&gt;&lt;P&gt;&amp;nbsp; failaction purge&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe TCP-80&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver SITMA21 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver SITMA22 80&lt;/P&gt;&lt;P&gt;serverfarm redirect OASIS-SSO-STG2_OOS_REDIRECT_FARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver OASIS-SSO-STG2_OOS_REDIRECT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky ip-netmask 255.255.255.255 address both L17SVWOASIS03_STICKY&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm L17SVWOASIS03_FARM backup &lt;STRONG&gt;OASIS-SSO-STG2_OOS_REDIRECT_FARM&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; timeout 10&lt;/P&gt;&lt;P&gt;&amp;nbsp; replicate sticky&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Need to know , when the redirection will takes place here .... i feel that only if the serverfarm (&lt;SPAN style="font-size: 10pt;"&gt;L17SVWOASIS03_FARM ) goes down , then the redirect server comes into picture as per the configs attached.. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If that is the case then &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;rserver redirect OASIS-SSO-STG2_OOS_REDIRECT&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; webhost-redirection &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://"&gt;https://&lt;/A&gt;&lt;STRONG&gt;eportal-stg.publix.com&lt;/STRONG&gt;/content/Associate/OutagePag&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The highligted URL should be the VIP of the context test2 i.e 10.106.112.59 is it right ? in&amp;nbsp; this the case how send this request to the VIP , since both are in different vlan ? is it should be done with PBR (policy based routing) via CAT6k ? could anyone please share the configs? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Or this can done with a default route to the VIP&amp;nbsp; on&amp;nbsp; the contexts? &lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2013 11:55:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395412#M41313</guid>
      <dc:creator>Martin Charles</dc:creator>
      <dc:date>2013-11-20T11:55:11Z</dc:date>
    </item>
    <item>
      <title>ACE - Inter-context traffic flow.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395413#M41314</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Martin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your understanding regarding redirect server is correct. When serverfarm L17SVWOASIS03_FARM, any requests coming for that VIP which corresponded to L17SVWOASIS03_FARM will be redirected to a different URL and client must now come on a different VIP. That shouldn't be a problem because ACE here is not routing the traffic to a different context. It is just telling the client to come on a different URL which resolves to a different VIP in a different context. So client should come to that VIP and that is like any other request to that VIP which i assume is already working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regarding your question of inter -context routing ACE does not allow intercontext communication. This is the behavior.&lt;/P&gt;&lt;P&gt;However, you can still achieve communication by going through an external gateway.&lt;/P&gt;&lt;P&gt; &lt;BR /&gt;If a rserver S in vlan 10 of context A wants to communicate with vlan 20, VIP-B, you should configure context A with a static host route, pointing VIP-B to the default gateway.&amp;nbsp; This default gateway will then forward the traffic to context B and for ACE it is like the connection comes from outside and not another context. Same for response. You need on context B a route for vlan 10&amp;nbsp; via the gateway&lt;/P&gt;&lt;P&gt;.&lt;/P&gt;&lt;P&gt;Logically this should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Give it a try and let me know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Nov 2013 16:00:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395413#M41314</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2013-11-20T16:00:58Z</dc:date>
    </item>
    <item>
      <title>ACE - Inter-context traffic flow.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395414#M41315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kanwal ... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gr8!!! ... Cool its works!!! Many thanks mate... It's happening even without a route!!! ( Not sure) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; I now undestand how server redirect works , however i have seen some configuration&amp;nbsp; as below &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Client ---&amp;gt; VIP (20)-----Rserver (30) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;But the &lt;/SPAN&gt;&lt;STRONG style="font-size: 10pt;"&gt;same Rserver has been configured as a VIP&lt;/STRONG&gt;&lt;SPAN style="font-size: 10pt;"&gt; in the other context , also both the context where in the same ACE box.. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;please let me know , how to make this work ? ASAIK the the first request which we send will get loadbalnced and it hits the rserver , but how the request goes to the VIP ( rserver ) in the other context , Will it traverse by default ?&amp;nbsp; or as you said above we need to add static route? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you have sample config to do the above can u please share ? Many thanks in Advance... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 07:18:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395414#M41315</guid>
      <dc:creator>Martin Charles</dc:creator>
      <dc:date>2013-11-21T07:18:24Z</dc:date>
    </item>
    <item>
      <title>ACE - Inter-context traffic flow.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395415#M41316</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Martin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hmm. I am not sure but what i am not understanding is why you want the request to be loadbalanced to a Rserver in one context and then same Rserver is VIP in another context in same ACE. I have seen that a VIP of another ACE is Rserver in another and of course that is a different and simple scenario.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So what you are saying is client comes to Vip(20) in context A and gets loadbalanced to Rserver(30) but Rserver 30 is actually a VIP in another context which loadbalances the traffic to another serverfarm. Never done that:)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why don't you send the request to Rserver(vip in another context) directly. Why do you need to go to VIP20 and get it LB to Rserver(30)? Honestly i am not sure. May be someone else has better ideas.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 13:07:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395415#M41316</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2013-11-21T13:07:15Z</dc:date>
    </item>
    <item>
      <title>ACE - Inter-context traffic flow.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395416#M41317</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kanwal, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your time &amp;amp; reply ... Yes the topology is bit complex , but i have seen a&amp;nbsp; customer configuration , which exactly states above... Not sure whether i can attach the same in the forum...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hoping to see other views on this ... Thanks Again .. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Martin Charles A.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 02:03:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395416#M41317</guid>
      <dc:creator>Martin Charles</dc:creator>
      <dc:date>2013-11-22T02:03:21Z</dc:date>
    </item>
    <item>
      <title>ACE - Inter-context traffic flow.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395417#M41318</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Martin,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was thinking about it and it is like loadbalancing to a server which is a HOP away. So how to do you that by doing routing so i guess in this case also you would need a route to VIP of different through another GATEWAY and vice-versa.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you try that and let me know how it goes. So my first reply suggestion should hold good here.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 16:55:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395417#M41318</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2013-11-22T16:55:24Z</dc:date>
    </item>
    <item>
      <title>ACE - Inter-context traffic flow.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395418#M41319</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kanwal ... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt;First of all thanks for your time and suggestion on this case.. Yes&amp;nbsp; i tried with the route , but the customer is in One-Arm mode and already a default route has been added , &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;which is pointing to the CAT6k , since routing decision has been done by CAT6k ... &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt;Here we go .. The customer config doesn't stop @ the place whether rserver of one context is the VIP in other context , it continues...&amp;nbsp; &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&amp;nbsp; &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif"&gt;&lt;/SPAN&gt;&amp;nbsp; .. Let me explain you with what i &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;understood so far.... &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;CSS - Context 1&amp;nbsp;&amp;nbsp; -------&amp;gt; SCA - Context 2&amp;nbsp; ---&amp;gt; CSS - Context 1 &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. A connection hitting from a firewall to&lt;STRONG&gt; CSS - Context 1 VIP i.e 10.99.1.76&lt;/STRONG&gt; (https) which will get load-balanced to Rservers (10.99.0.13 &amp;amp; 10.99.0.14) Port 475 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. The above mentioned two rserver were the &lt;STRONG&gt;VIP in SCA Context 2&lt;/STRONG&gt; ,&amp;nbsp; which will get loadbalanced to &lt;STRONG&gt;10.99.1.76 Port 8080&lt;/STRONG&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt;My head started to Spin when i found d third... &lt;/SPAN&gt;&lt;SPAN __jive_emoticon_name="shocked" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/tiny_mce3/plugins/jiveemoticons/images/spacer.gif" style="font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; 3. The above mentioned Rserver &lt;STRONG&gt;10.99.1.76 8080&lt;/STRONG&gt; is the VIP again &lt;STRONG&gt;CSS - Context 1 , &lt;/STRONG&gt;which gets finally loadbalanced into &lt;/P&gt;&lt;P&gt;10.99.1.217&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I made this config up and running in my lab , and the VIP and rservers are up .... Since its one-arm mode i have given the static route to CAT6k , but still i am unable to fetch the page as required ... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Will post the configs on the next thread.. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Martin&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Nov 2013 12:53:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395418#M41319</guid>
      <dc:creator>Martin Charles</dc:creator>
      <dc:date>2013-11-25T12:53:50Z</dc:date>
    </item>
    <item>
      <title>ACE - Inter-context traffic flow.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395419#M41320</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Configs&lt;/P&gt;&lt;P&gt;=====&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS - Context 1 &lt;/P&gt;&lt;P&gt;============&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;probe tcp qaahmapp1-ssl-475_PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp; port 475&lt;/P&gt;&lt;P&gt;&amp;nbsp; interval 5&lt;/P&gt;&lt;P&gt;&amp;nbsp; passdetect interval 5&lt;/P&gt;&lt;P&gt;&amp;nbsp; connection term forced&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host HS_PROD.sanovia_447-ssl-a&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.99.0.13&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host HS_PROD.sanovia_447-ssl-b&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.99.0.14&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host sanovia.qaahm.ssl&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe qaahmapp1-ssl-475_PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver HS_PROD.sanovia_447-ssl-a 475&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; conn-limit max 4000000 min 4000000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver HS_PROD.sanovia_447-ssl-b 475&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; conn-limit max 4000000 min 4000000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type http cisco_avs_parametermap&lt;/P&gt;&lt;P&gt;&amp;nbsp; case-insensitive&lt;/P&gt;&lt;P&gt;&amp;nbsp; persistence-rebalance&lt;/P&gt;&lt;P&gt;&amp;nbsp; parsing non-strict&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;action-list type optimization http cisco_avs_bandwidth_and_latency&lt;/P&gt;&lt;P&gt;&amp;nbsp; delta&lt;/P&gt;&lt;P&gt;&amp;nbsp; flashforward&lt;/P&gt;&lt;P&gt;action-list type optimization http cisco_avs_img_latency&lt;/P&gt;&lt;P&gt;&amp;nbsp; flashforward-object&lt;/P&gt;&lt;P&gt;action-list type optimization http cisco_avs_obj_latency&lt;/P&gt;&lt;P&gt;&amp;nbsp; flashforward-object&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type http loadbalance match-all cisco_avs_bandwidth_and_latency&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match http url .*&lt;/P&gt;&lt;P&gt;class-map type http loadbalance match-any cisco_avs_img_latency&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match http url .*jpg&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3 match http url .*jpeg&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4 match http url .*jpe&lt;/P&gt;&lt;P&gt;&amp;nbsp; 5 match http url .*png&lt;/P&gt;&lt;P&gt;class-map type http loadbalance match-any cisco_avs_obj_latency&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match http url .*gif&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3 match http url .*css&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4 match http url .*js&lt;/P&gt;&lt;P&gt;&amp;nbsp; 5 match http url .*class&lt;/P&gt;&lt;P&gt;&amp;nbsp; 6 match http url .*jar&lt;/P&gt;&lt;P&gt;&amp;nbsp; 7 match http url .*cab&lt;/P&gt;&lt;P&gt;&amp;nbsp; 8 match http url .*txt&lt;/P&gt;&lt;P&gt;&amp;nbsp; 9 match http url .*ps&lt;/P&gt;&lt;P&gt;&amp;nbsp; 10 match http url .*vbs&lt;/P&gt;&lt;P&gt;&amp;nbsp; 11 match http url .*xsl&lt;/P&gt;&lt;P&gt;&amp;nbsp; 12 match http url .*xml&lt;/P&gt;&lt;P&gt;&amp;nbsp; 13 match http url .*pdf&lt;/P&gt;&lt;P&gt;&amp;nbsp; 14 match http url .*swf&lt;/P&gt;&lt;P&gt;class-map match-all sanovia.qaahm.ssl_CLASS&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 10.99.1.76 tcp eq https&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match sanovia.qaahm.ssl_CLASS-l7slb&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm sanovia.qaahm.ssl&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; insert-http x-forward header-value "%is"&lt;/P&gt;&lt;P&gt;policy-map type optimization http first-match sanovia.qaahm.ssl_CLASS-l7opt&lt;/P&gt;&lt;P&gt;&amp;nbsp; class cisco_avs_obj_latency&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; action cisco_avs_obj_latency&lt;/P&gt;&lt;P&gt;&amp;nbsp; class cisco_avs_img_latency&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; action cisco_avs_img_latency&lt;/P&gt;&lt;P&gt;&amp;nbsp; class cisco_avs_bandwidth_and_latency&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; action cisco_avs_bandwidth_and_latency&lt;/P&gt;&lt;P&gt;policy-map multi-match POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; class sanovia.qaahm.ssl_CLASS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy sanovia.qaahm.ssl_CLASS-l7slb&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; optimize http policy sanovia.qaahm.ssl_CLASS-l7opt&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 2 vlan 20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options cisco_avs_parametermap&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 20&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.99.1.240 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; alias 10.99.1.241 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 1 10.99.1.221 10.99.1.221 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 2 10.99.1.220 10.99.1.220 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.99.1.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;========================================================================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;SCA - Context 2 &lt;/P&gt;&lt;P&gt;============&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto chaingroup GoDaddy&lt;/P&gt;&lt;P&gt;&amp;nbsp; cert cisco-sample-cert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;probe tcp AHM_QA-PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp; port 8080&lt;/P&gt;&lt;P&gt;&amp;nbsp; interval 5&lt;/P&gt;&lt;P&gt;&amp;nbsp; passdetect interval 5&lt;/P&gt;&lt;P&gt;&amp;nbsp; connection term forced&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host AHM_QA&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.99.1.76&lt;/P&gt;&lt;P&gt;&amp;nbsp; conn-limit max 4000000 min 4000000&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host AHM_QA&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver AHM_QA 8080&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; conn-limit max 4000000 min 4000000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; probe AHM_QA-PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type ssl sanovia-ssl-parms&lt;/P&gt;&lt;P&gt;&amp;nbsp; description This is where you tweak your SSL parms, cert, etc.&lt;/P&gt;&lt;P&gt;&amp;nbsp; cipher RSA_WITH_RC4_128_MD5 priority 4&lt;/P&gt;&lt;P&gt;&amp;nbsp; cipher RSA_WITH_RC4_128_SHA priority 5&lt;/P&gt;&lt;P&gt;&amp;nbsp; cipher RSA_WITH_DES_CBC_SHA priority 3&lt;/P&gt;&lt;P&gt;&amp;nbsp; cipher RSA_WITH_3DES_EDE_CBC_SHA priority 6&lt;/P&gt;&lt;P&gt;&amp;nbsp; cipher RSA_WITH_AES_128_CBC_SHA priority 7&lt;/P&gt;&lt;P&gt;&amp;nbsp; cipher RSA_WITH_AES_256_CBC_SHA priority 8&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl-proxy service sanovia-ssl-proxy&lt;/P&gt;&lt;P&gt;&amp;nbsp; key cisco-sample-key&lt;/P&gt;&lt;P&gt;&amp;nbsp; cert cisco-sample-cert&lt;/P&gt;&lt;P&gt;&amp;nbsp; chaingroup GoDaddy&lt;/P&gt;&lt;P&gt;&amp;nbsp; ssl advanced-options sanovia-ssl-parms&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-any AHM_QA-CLASS&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 10.99.0.13 tcp eq 475&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3 match virtual-address 10.99.0.14 tcp eq 475&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match AHM_QA-CLASS-l7slb&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm AHM_QA&lt;/P&gt;&lt;P&gt;policy-map multi-match POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; class AHM_QA-CLASS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy AHM_QA-CLASS-l7slb&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy server sanovia-ssl-proxy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 10&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.99.0.17 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; peer ip address 10.99.0.11 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 1 10.99.0.13 10.99.0.13 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip route 0.0.0.0 0.0.0.0 10.99.0.1&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;========================================================================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSS - Context 1 ( another VIP) &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;=======================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host qaahmapp1-8080&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.99.1.217&lt;/P&gt;&lt;P&gt;&amp;nbsp; conn-limit max 4000000 min 4000000&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host sanovia.qaahm.postssl&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver qaahmapp1-8080 8080&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; conn-limit max 4000000 min 4000000&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type http HTTP_PARAMETER_MAP&lt;/P&gt;&lt;P&gt;&amp;nbsp; persistence-rebalance&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky http-cookie ACE_Cookie qanovia.qaahm.postssl-STICKY&lt;/P&gt;&lt;P&gt;&amp;nbsp; cookie insert&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm sanovia.qaahm.postssl&lt;/P&gt;&lt;P&gt;&amp;nbsp; timeout 45&lt;/P&gt;&lt;P&gt;&amp;nbsp; replicate sticky&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all sanovia.qaahm.postssl_CLASS&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 10.99.1.76 tcp eq 8080&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match sanovia.qaahm.postssl_CLASS-l7slb&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm qanovia.qaahm.postssl-STICKY&lt;/P&gt;&lt;P&gt;policy-map multi-match POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; class sanovia.qaahm.postssl_CLASS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy sanovia.qaahm.postssl_CLASS-l7slb&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 2 vlan 20&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options HTTP_PARAMETER_MAP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 20&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.99.1.240 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; alias 10.99.1.241 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 1 10.99.1.221 10.99.1.221 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 2 10.99.1.220 10.99.1.220 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;=============================================================================&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured two vlans in CAT6k i.e vlan 10&amp;nbsp; &amp;amp; vlan 20 with the following ip's as mentioned in the route of ACE &lt;/P&gt;&lt;P&gt; 10.99.0.1 &amp;amp; 10.99.1.1 &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also configured only the final rserver 10.99.1.217 under vlan 20 .... this made all the vip and rserver up .. but still couldnt get the required page...&amp;nbsp; there is small confusion in the first context as the vip is shown as https , but i dont see any cert and key in the customer config , so i made it as http for my test... but the second context vip is https , where i have added the certs n key as requied.... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if i am missing anything here.... Many thanks in advance... &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;Martin &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Nov 2013 13:01:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-inter-context-traffic-flow/m-p/2395419#M41320</guid>
      <dc:creator>Martin Charles</dc:creator>
      <dc:date>2013-11-25T13:01:54Z</dc:date>
    </item>
  </channel>
</rss>

