<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ACE 4710 no real ip in header with referer in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396886#M41337</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you try using X-forwarded-for instead of X-real-ip?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;insert-http X-Forwarded-For header-value "%is. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above ensures that you see the client IP&amp;nbsp; in HTTP header and server should have some sort of script enable to catch this for reporting purpose.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen this working flawlessly and would suggest using this and see if&amp;nbsp; that resolves your problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 11 Nov 2013 23:48:56 GMT</pubDate>
    <dc:creator>Kanwaljeet Singh</dc:creator>
    <dc:date>2013-11-11T23:48:56Z</dc:date>
    <item>
      <title>ACE 4710 no real ip in header with referer</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396885#M41336</link>
      <description>&lt;P&gt;Hello everybody. I need help with ACE 4710. We use one-arm PAT config to round robin load balance scheme with ssl terminate and trying to insert x-real-ip in all http-headers. But some packets with referer inside arrive with ACE ip in header, no real ip of clients. Any ideas, please?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Config ACE:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface gigabitEthernet 1/1&lt;/P&gt;&lt;P&gt;&amp;nbsp; channel-group 1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;interface gigabitEthernet 1/2&lt;/P&gt;&lt;P&gt;&amp;nbsp; channel-group 1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;interface gigabitEthernet 1/3&lt;/P&gt;&lt;P&gt;&amp;nbsp; channel-group 1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;interface gigabitEthernet 1/4&lt;/P&gt;&lt;P&gt;&amp;nbsp; channel-group 1&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;interface port-channel 1&lt;/P&gt;&lt;P&gt;&amp;nbsp; switchport trunk native vlan 1&lt;/P&gt;&lt;P&gt;&amp;nbsp; switchport trunk allowed vlan 2-200&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto chaingroup intercert&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list ALL line 8 extended permit ip any any&lt;/P&gt;&lt;P&gt;access-list ALL line 9 extended permit icmp any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;probe icmp ICMP_PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp; interval 10&lt;/P&gt;&lt;P&gt;&amp;nbsp; passdetect count 4&lt;/P&gt;&lt;P&gt;&amp;nbsp; receive 1&lt;/P&gt;&lt;P&gt;probe http http_probe&lt;/P&gt;&lt;P&gt;&amp;nbsp; interval 5&lt;/P&gt;&lt;P&gt;&amp;nbsp; passdetect interval 10&lt;/P&gt;&lt;P&gt;&amp;nbsp; passdetect count 2&lt;/P&gt;&lt;P&gt;&amp;nbsp; expect status 200 210&lt;/P&gt;&lt;P&gt;&amp;nbsp; header User-Agent header-value "LoadBalance"&lt;/P&gt;&lt;P&gt;probe http http_probe_443&lt;/P&gt;&lt;P&gt;&amp;nbsp; port 443&lt;/P&gt;&lt;P&gt;&amp;nbsp; interval 5&lt;/P&gt;&lt;P&gt;&amp;nbsp; passdetect interval 10&lt;/P&gt;&lt;P&gt;&amp;nbsp; passdetect count 2&lt;/P&gt;&lt;P&gt;&amp;nbsp; expect status 200 210&lt;/P&gt;&lt;P&gt;&amp;nbsp; header User-Agent header-value "LoadBalance"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host nginx-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.99.1.11&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host nginx-2&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.99.1.12&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host nginx-3&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.99.1.13&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host nginx-4&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.99.1.14&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host nginx-5&lt;BR /&gt;&amp;nbsp; ip address 10.99.1.15&lt;BR /&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host nginx-6&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.99.1.16&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host nginx-7&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.99.1.17&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host nginx-8&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.99.1.18&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host NGINX-FARM-443&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe ICMP_PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe http_probe_443&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver nginx-5&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;serverfarm host NGINX-FARM-80&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe ICMP_PROBE&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe http_probe&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver nginx-1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver nginx-2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type http HTTP&lt;/P&gt;&lt;P&gt;&amp;nbsp; case-insensitive&lt;/P&gt;&lt;P&gt;&amp;nbsp; persistence-rebalance&lt;/P&gt;&lt;P&gt;&amp;nbsp; header modify per-request&lt;/P&gt;&lt;P&gt;&amp;nbsp; set header-maxparse-length 16384&lt;/P&gt;&lt;P&gt;&amp;nbsp; length-exceed continue&lt;/P&gt;&lt;P&gt;parameter-map type http HTTPS&lt;/P&gt;&lt;P&gt;&amp;nbsp; persistence-rebalance&lt;/P&gt;&lt;P&gt;&amp;nbsp; header modify per-request&lt;/P&gt;&lt;P&gt;&amp;nbsp; set header-maxparse-length 16384&lt;/P&gt;&lt;P&gt;&amp;nbsp; length-exceed continue&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky ip-netmask 255.255.255.255 address source STUCK&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm NGINX-FARM-80&lt;/P&gt;&lt;P&gt;&amp;nbsp; timeout 60&lt;/P&gt;&lt;P&gt;&amp;nbsp; replicate sticky&lt;/P&gt;&lt;P&gt;sticky ip-netmask 255.255.255.255 address source STUCK443&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm NGINX-FARM-443&lt;/P&gt;&lt;P&gt;&amp;nbsp; timeout 60&lt;/P&gt;&lt;P&gt;&amp;nbsp; replicate sticky&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;action-list type modify http SERVER&lt;/P&gt;&lt;P&gt;&amp;nbsp; header rewrite response server header-value "nginx" replace "hamster"&lt;/P&gt;&lt;P&gt;action-list type modify http REAL-SSL&lt;/P&gt;&lt;P&gt;&amp;nbsp; header insert request x-real-ip header-value "%is"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl-proxy service SSL-PROXY&lt;/P&gt;&lt;P&gt;&amp;nbsp; key xxx.em&lt;/P&gt;&lt;P&gt;&amp;nbsp; cert xxx.pem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all NGINX-443-VIP&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 10.99.1.4 tcp eq https&lt;/P&gt;&lt;P&gt;class-map match-all NGINX-80-VIP&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 10.99.1.2 tcp eq www&lt;/P&gt;&lt;P&gt;class-map type management match-any remote_access&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match protocol xml-https any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 3 match protocol icmp any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 4 match protocol telnet any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 5 match protocol ssh any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 6 match protocol http any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 7 match protocol https any&lt;/P&gt;&lt;P&gt;&amp;nbsp; 8 match protocol snmp any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type management first-match remote_mgmt_allow_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; class remote_access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance http first-match NGINX-443-POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm STUCK443&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; insert-http X-Real-IP header-value "%is"&lt;/P&gt;&lt;P&gt;policy-map type loadbalance http first-match NGINX-80-POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm STUCK&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; action SERVER&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; insert-http X-Real-IP header-value "%is"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match PM-443&lt;/P&gt;&lt;P&gt;&amp;nbsp; class NGINX-443-VIP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy NGINX-443-POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 443 vlan 99&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options HTTPS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy server SSL-PROXY&lt;/P&gt;&lt;P&gt;policy-map multi-match PM-80&lt;/P&gt;&lt;P&gt;&amp;nbsp; class NGINX-80-VIP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy NGINX-80-POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 99 vlan 99&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options HTTP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 99&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.99.1.3 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; peer ip address 10.99.1.5 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input ALL&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group output ALL&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 443 10.99.1.4 10.99.1.4 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 99 10.99.1.2 10.99.1.2 netmask 255.255.255.255 pat&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input remote_mgmt_allow_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input PM-80&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input PM-443&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;interface vlan 172&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 172.16.1.6 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; peer ip address 172.16.1.12 255.255.255.0&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input ALL&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input remote_mgmt_allow_policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;DIV class="mcePaste" id="_mcePaste" style="position: absolute; left: -10000px; top: 0px; width: 1px; height: 1px; overflow: hidden;"&gt; &lt;/DIV&gt;</description>
      <pubDate>Mon, 11 Nov 2013 19:31:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396885#M41336</guid>
      <dc:creator>Vladimir Buyalsky</dc:creator>
      <dc:date>2013-11-11T19:31:28Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 no real ip in header with referer</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396886#M41337</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you try using X-forwarded-for instead of X-real-ip?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;insert-http X-Forwarded-For header-value "%is. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The above ensures that you see the client IP&amp;nbsp; in HTTP header and server should have some sort of script enable to catch this for reporting purpose.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have seen this working flawlessly and would suggest using this and see if&amp;nbsp; that resolves your problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Nov 2013 23:48:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396886#M41337</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2013-11-11T23:48:56Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 no real ip in header with referer</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396887#M41338</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; HI Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also see in application parameter that you are using header modify per request as well as persistence rebalance so you should see client IP in request forwarded by ACE. I have not particularly used x-real-ip but i have used x-forwarded-for and it works absolutely fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 11 Nov 2013 23:53:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396887#M41338</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2013-11-11T23:53:01Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 no real ip in header with referer</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396888#M41339</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for reply, Fnu!&lt;/P&gt;&lt;P&gt;Unfortunately, I can't to test your advice in near time &lt;SPAN __jive_emoticon_name="sad"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Commonly, does Ace support header "x-real-ip"? Could be another reason?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 19:29:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396888#M41339</guid>
      <dc:creator>Vladimir Buyalsky</dc:creator>
      <dc:date>2013-11-12T19:29:19Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 no real ip in header with referer</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396889#M41340</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; HI Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I checked and ACE should support x-real-ip. The header insertion can be anything but the value should be standard and you are using the right one. So it should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So coming to the problem, you say that you see some connections with ACE fowarding it's own IP, rather than client, is that correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are those connections part of the same policy to which you have applied insert-http action?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Nov 2013 20:16:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396889#M41340</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2013-11-12T20:16:08Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 no real ip in header with referer</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396890#M41341</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Fnu.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes, i have only one policy in the config and all connections belong it.&lt;/P&gt;&lt;P&gt;Is there difference between insert-http in the policy and active-list? May be it need to replace active-list?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Nov 2013 06:32:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396890#M41341</guid>
      <dc:creator>Vladimir Buyalsky</dc:creator>
      <dc:date>2013-11-14T06:32:32Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 no real ip in header with referer</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396891#M41342</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For inserting the client IP you don't need an action list and insert-http X-real-IP header-value "%is" is enough.&amp;nbsp; You can remove the action list that you have configured above and it should still work fine by applying&amp;nbsp; insert -http xxxx ..under policy map.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am not sure what exactly is the difference but we use insert-http for this scenario. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Nov 2013 12:19:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396891#M41342</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2013-11-14T12:19:04Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 no real ip in header with referer</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396892#M41343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Fnu.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I deleted action-list and finally did test of x-forwared-for. It not work, unfortunately. Some packets was arriving with ip of ace in http-header again. ( &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Nov 2013 13:59:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396892#M41343</guid>
      <dc:creator>Vladimir Buyalsky</dc:creator>
      <dc:date>2013-11-14T13:59:48Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 no real ip in header with referer</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396893#M41344</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The configuration looks fine.&amp;nbsp; Does this happen to specific connections or is it random? Do you see ACE NAT IP in x-forwarded-for or you don't see anything at all? Can you paste here what you see in HTTP header? Both good and not-good output.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you see insert errors increasing under "show stats http"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is it happening for HTTP OR HTTPS connections?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 14 Nov 2013 16:38:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396893#M41344</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2013-11-14T16:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: ACE 4710 no real ip in header with referer</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396894#M41345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Fnu.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It is happening for HTTP and HTTPS.&lt;/P&gt;&lt;P&gt;Now https is disable and doesn't go through ace.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Header insert errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Max parselen errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 29&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;Static parse errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 1216&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Resource errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;Invalid path errors&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bad HTTP version errors&amp;nbsp; : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;BR /&gt;Headers rewritten&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : 24018818&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Header rewrite errors&amp;nbsp;&amp;nbsp;&amp;nbsp; : 0&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I can't find a dependence.&lt;/P&gt;&lt;P&gt;so, there is output of log nginx below, that connect to ace:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;good log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example.com 9X.7X.54.200 - [15/Nov/2013:15:07:20 +0400] "GET /path/view/?id=0142200001313011430 HTTP/1.1" 200 43544 "-" Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322) 1.000 10.X.X.XX:80 -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;bad log&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;example.com 10.99.1.2 - [15/Nov/2013:14:47:15 +0400] "GET /images/blocks/picture.png HTTP/1.1" 400 0 "-" Opera/9.80 (Windows NT 6.1; WOW64) Presto/2.12.388 Version/12.16 0.100 - -&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;SPAN&gt;example.com 10.99.1.2 - [15/Nov/2013:10:21:19 +0400] "GET /pathto/?q=\xD0\xBA\xD1\x81\xD0\xB5\xD1\x84\xD0\xB4.\xEF\xBF\xBD,4/\xEF\xBF\xBD\x18Y\xEF\xBF\xBDOLI\xEF\xBF\xBD\x1A[Z]\x0FML\xEF\xBF\xBD\xDC\x99\x19\x5C\xEF\xBF\xBD\x5C\x1DX\xEF\xBF\xBD\x18]\x19I\xEF\xBF\xBD\x1A\x5C\xEF\xBF\xBDY\x19\x5C\xEF\xBF\xBD\xC9\x8FI\xEF\xBF\xBD\x1E\x5C\x19W\xEF\xBF\xBDO[\xDB\x89\xEF\xBF\xBD\x1E\x5C\x19W\xD8\x8F[\xDB\x89\xEF\xBF\xBD\x1E\x5C\x19W\xEF\xBF\xBD\xEF\xBF\xBD[\xDB\x89\xEF\xBF\xBD\x1E\x5C\x19W\xEF\xBF\xBD HTTP/1.1" 200 18338 "&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://200.100.96.40:4080/nonauth/expiration.php?dest=aHR0cDovL2V0cC5yb3NlbHRvcmcucnUvdHJhZGUvcGFzdC8%2FcT3QutGB0LXRhNC%2B0LrQsNC8JnBhZ2U9MSZsaW1pdD01MCZvcmRlcj1wdWJkYXRlJmRpcj1kZXNjJj0mdHlwZV9hPW9uJnR5cGVfYj1vbiZ0eXBlX2M9b24mdHlwZV9wPW9u&amp;amp;expired=1" rel="nofollow"&gt;http://X.X.X.X:5080/nonauth/expiration.php?dest=aHR0cDovL2V0cC5yb3NlbHRvcmcucnUvdHJhZGUvcGFzdC8%2FcT3QutGB0LXRhNC%2B0LrQsNC8JnBhZ2U9MSZsaW1pdD01MCZvcmRlcj1wdWJkYXRlJmRpcj1kZXNjJj0mdHlwZV9hPW9uJnR5cGVfYj1vbiZ0eXBlX2M9b24mdHlwZV9wPW9u&amp;amp;expired=1&lt;/A&gt;&lt;SPAN&gt;" Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; WOW64; Trident/5.0) 3.400 10.X.X.X:80 - &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have changed some IP and domain names.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Nov 2013 11:16:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396894#M41345</guid>
      <dc:creator>Vladimir Buyalsky</dc:creator>
      <dc:date>2013-11-15T11:16:03Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 no real ip in header with referer</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396895#M41346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please try "persistence-rebalance strict" in the http parameter-map and see if it helps ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Rajesh.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 15 Nov 2013 14:11:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396895#M41346</guid>
      <dc:creator>rajsures</dc:creator>
      <dc:date>2013-11-15T14:11:48Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 no real ip in header with referer</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396896#M41347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, Rajesh.&lt;/P&gt;&lt;P&gt; &lt;SPAN style="font-size: 10pt;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seems, it works, but only partially. So it is very strange. For serverfarm NGINX-FARM-443 all is good, but serverfarm NGINX-FARM-80 keep to receive packet with ip of ace instead of real ip sometimes.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Nov 2013 20:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396896#M41347</guid>
      <dc:creator>Vladimir Buyalsky</dc:creator>
      <dc:date>2013-11-18T20:00:09Z</dc:date>
    </item>
    <item>
      <title>ACE 4710 no real ip in header with referer</title>
      <link>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396897#M41348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Vladimir,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Everything looks good but it is weird that it is working for HTTPS and not HTTP. I would suggest opening a TAC case and since this is reproducible it could be new bug or something which we are missing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As far as configuration goes it is fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Nov 2013 13:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-4710-no-real-ip-in-header-with-referer/m-p/2396897#M41348</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2013-11-19T13:07:10Z</dc:date>
    </item>
  </channel>
</rss>

