<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Need Help for redirect to HTTPS in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/need-help-for-redirect-to-https/m-p/2403208#M41381</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Hamzah,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The location regex that you enter must be a pure URL (for example, www\.cisco\.com) with no port or path designations if you are using SSL URL rewrite.&amp;nbsp; If you need to match a path, use the &lt;STRONG&gt;HTTP header rewrite&lt;/STRONG&gt; feature to rewrite the string.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;action-list type modify http X&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;header rewrite response Location header-value "&lt;A href="http://xxxx\.com/path"&gt;http://xxxx\.com/path&lt;/A&gt;" replace &lt;A href="https://xxxx\.com/path"&gt;https://xxxx\.com/path&lt;/A&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try and let me know how it goes. For simple URL without path your above configuration should work fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Nov 2013 12:53:51 GMT</pubDate>
    <dc:creator>Kanwaljeet Singh</dc:creator>
    <dc:date>2013-11-21T12:53:51Z</dc:date>
    <item>
      <title>Need Help for redirect to HTTPS</title>
      <link>https://community.cisco.com/t5/application-networking/need-help-for-redirect-to-https/m-p/2403207#M41380</link>
      <description>&lt;P&gt;Hello forum members,&lt;/P&gt;&lt;P&gt;i have difficulty while configuring http to https while accessing specific url.&lt;/P&gt;&lt;P&gt;the case:&lt;/P&gt;&lt;P&gt;i have &lt;A href="https://community.cisco.com/www.foo-bar.com.god" target="_blank"&gt;www.foo-bar.com.god&lt;/A&gt; in http, in the web page there is &lt;A href="https://community.cisco.com/www.foo-bar.com.god/trust/*" target="_blank"&gt;www.foo-bar.com.god/trust/*&lt;/A&gt; that must be accessing in https &lt;/P&gt;&lt;P&gt;is there any spesific line of config to apply in my config,&lt;/P&gt;&lt;P&gt;my config is below.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;### start&lt;/P&gt;&lt;P&gt;access-list INBOUND line 8 extended permit ip any any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type http PERSISTENCE-REBALANCE&lt;/P&gt;&lt;P&gt; persistence-rebalance&lt;/P&gt;&lt;P&gt;parameter-map type ssl SSL_END_to_END&lt;/P&gt;&lt;P&gt;&amp;nbsp; cipher RSA_WITH_RC4_128_SHA priority 10&lt;/P&gt;&lt;P&gt;&amp;nbsp; cipher RSA_WITH_3DES_EDE_CBC_SHA priority 7&lt;/P&gt;&lt;P&gt;&amp;nbsp; cipher RSA_WITH_AES_128_CBC_SHA priority 9&lt;/P&gt;&lt;P&gt;&amp;nbsp; cipher RSA_WITH_AES_256_CBC_SHA priority 8&lt;/P&gt;&lt;P&gt;&amp;nbsp; session-cache timeout 600&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host PORTAL-A&lt;/P&gt;&lt;P&gt; ip address 10.49.30.200&lt;/P&gt;&lt;P&gt; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;action-list type modify http FORCE-HTTPS&lt;/P&gt;&lt;P&gt; ssl url rewrite location "www\.foo\-\bar\.com\.god\trust\*"&lt;/P&gt;&lt;P&gt; header insert&amp;nbsp; response Cache-Control header-value "private, no-cache, no-store, must-revalidate"&lt;/P&gt;&lt;P&gt; header rewrite response Server header-value "" replace "BLANK"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host PORTAL-SFARM&lt;/P&gt;&lt;P&gt; rserver PORTAL-A 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl-proxy service PORTAL-CERT&lt;/P&gt;&lt;P&gt; key portal.key&lt;/P&gt;&lt;P&gt; cert portal.crt&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky ip-netmask 255.255.255.255 address source SOURCEIP-STICKY-HTTP-SFARM&lt;/P&gt;&lt;P&gt; replicate sticky&lt;/P&gt;&lt;P&gt; serverfarm PORTAL-SFARM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all SSL-VIP&lt;/P&gt;&lt;P&gt; 2 match virtual-address 10.49.30.230 tcp eq https&lt;/P&gt;&lt;P&gt;class-map match-all HTTP-VIP&lt;/P&gt;&lt;P&gt; 2 match virtual-address 10.49.30.230 tcp eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type management match-any remote_access&lt;/P&gt;&lt;P&gt; 202 match protocol icmp any&lt;/P&gt;&lt;P&gt; 204 match protocol ssh any&lt;/P&gt;&lt;P&gt; 207 match protocol snmp any&lt;/P&gt;&lt;P&gt; 208 match protocol telnet any&lt;/P&gt;&lt;P&gt; 209 match protocol http any&lt;/P&gt;&lt;P&gt; 210 match protocol https any&lt;/P&gt;&lt;P&gt; 211 match protocol xml-https any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type management first-match management&lt;/P&gt;&lt;P&gt; class remote_access&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; permit&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match LB-PORTAL-L7-POLICY&lt;/P&gt;&lt;P&gt; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; sticky-serverfarm SOURCEIP-STICKY-HTTP-SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; action FORCE-HTTPS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match LB-PORTAL-L4-POLICY&lt;/P&gt;&lt;P&gt; class SSL-VIP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; loadbalance policy LB-PORTAL-L7-POLICY&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 260&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options PERSISTENCE-REBALANCE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; ssl-proxy server PORTAL-CERT&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 260&lt;/P&gt;&lt;P&gt; description "User-Access"&lt;/P&gt;&lt;P&gt; ip address 10.49.30.231 255.255.255.192&lt;/P&gt;&lt;P&gt; peer ip address 10.49.30.232 255.255.255.192&lt;/P&gt;&lt;P&gt; access-group input INBOUND&lt;/P&gt;&lt;P&gt; nat-pool 1 10.49.30.252 10.49.30.252 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt; service-policy input management&lt;/P&gt;&lt;P&gt; service-policy input LB-PORTAL-L4-POLICY&lt;/P&gt;&lt;P&gt; no shutdown&lt;/P&gt;&lt;P&gt;### End&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;need for review the config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks and regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hamzah&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2013 05:36:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/need-help-for-redirect-to-https/m-p/2403207#M41380</guid>
      <dc:creator>hamz-zackops</dc:creator>
      <dc:date>2013-11-21T05:36:09Z</dc:date>
    </item>
    <item>
      <title>Need Help for redirect to HTTPS</title>
      <link>https://community.cisco.com/t5/application-networking/need-help-for-redirect-to-https/m-p/2403208#M41381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Hamzah,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The location regex that you enter must be a pure URL (for example, www\.cisco\.com) with no port or path designations if you are using SSL URL rewrite.&amp;nbsp; If you need to match a path, use the &lt;STRONG&gt;HTTP header rewrite&lt;/STRONG&gt; feature to rewrite the string.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;action-list type modify http X&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;header rewrite response Location header-value "&lt;A href="http://xxxx\.com/path"&gt;http://xxxx\.com/path&lt;/A&gt;" replace &lt;A href="https://xxxx\.com/path"&gt;https://xxxx\.com/path&lt;/A&gt;"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Try and let me know how it goes. For simple URL without path your above configuration should work fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Nov 2013 12:53:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/need-help-for-redirect-to-https/m-p/2403208#M41381</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2013-11-21T12:53:51Z</dc:date>
    </item>
    <item>
      <title>Need Help for redirect to HTTPS</title>
      <link>https://community.cisco.com/t5/application-networking/need-help-for-redirect-to-https/m-p/2403209#M41382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Singh,&lt;/P&gt;&lt;P&gt;thank you for reply,&lt;/P&gt;&lt;P&gt;i just change the config so hope fully the web can redirecting properly.&lt;/P&gt;&lt;P&gt;but when i apply the config, the Browser say, the connection was reset.&lt;/P&gt;&lt;P&gt;Need help&lt;/P&gt;&lt;P&gt;here is my full config&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;crypto chaingroup portal-verySign&lt;/P&gt;&lt;P&gt;&amp;nbsp; cert portal.pem&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list everyone line 8 extended permit ip any any &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;rserver host PORTAL-A&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.49.30.200&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver redirect PORTAL_REDIR_HTTPS&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; webhost-redirection &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://community.cisco.com/"&gt;https://%h%p&lt;/A&gt;&lt;SPAN&gt; 302&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm redirect PORTAL_HTTPS_SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver PORTAL_REDIR_HTTPS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;serverfarm host WWW_PORTAL_SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver PORTAL-A 80&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type http PERSISTENCE-REBALANCE&lt;/P&gt;&lt;P&gt;&amp;nbsp; persistence-rebalance&lt;/P&gt;&lt;P&gt;parameter-map type ssl SSL_END_to_END&lt;/P&gt;&lt;P&gt;&amp;nbsp; cipher RSA_WITH_RC4_128_SHA priority 10&lt;/P&gt;&lt;P&gt;&amp;nbsp; cipher RSA_WITH_3DES_EDE_CBC_SHA priority 7&lt;/P&gt;&lt;P&gt;&amp;nbsp; cipher RSA_WITH_AES_128_CBC_SHA priority 9&lt;/P&gt;&lt;P&gt;&amp;nbsp; cipher RSA_WITH_AES_256_CBC_SHA priority 8&lt;/P&gt;&lt;P&gt;&amp;nbsp; session-cache timeout 600&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky http-cookie PORTAL-STICKY STICKY-PORTAL-1&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm WWW_PORTAL_SFARM&lt;/P&gt;&lt;P&gt;sticky ip-netmask 255.255.255.255 address source SOURCEIP-STICKY-HTTP-SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; replicate sticky&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm WWW_PORTAL_SFARM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;action-list type modify http HTTP_MODIFICATION&lt;/P&gt;&lt;P&gt;&amp;nbsp; header insert request X-Forwarded-Proto header-value "%pd"&lt;/P&gt;&lt;P&gt;&amp;nbsp; header insert request Via header-value "1.1 web:%pd"&lt;/P&gt;&lt;P&gt;&amp;nbsp; header insert response Via header-value "1.1 web:ps"&lt;/P&gt;&lt;P&gt;&amp;nbsp; ssl url rewrite location ".*"&lt;/P&gt;&lt;P&gt;&amp;nbsp; ssl header-insert session Id&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ssl-proxy service CLIENT_PORTAL&lt;/P&gt;&lt;P&gt;&amp;nbsp; ssl advanced-options SSL_END_to_END&lt;/P&gt;&lt;P&gt;ssl-proxy service SERVER_PORTAL&lt;/P&gt;&lt;P&gt;&amp;nbsp; key portal-key.pem&lt;/P&gt;&lt;P&gt;&amp;nbsp; cert portal.pem&lt;/P&gt;&lt;P&gt;&amp;nbsp; chaingroup portal-verySign&lt;/P&gt;&lt;P&gt;&amp;nbsp; ssl advanced-options SSL_END_to_END&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map type http loadbalance match-any PORTAL-SSL&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match http url .*&lt;/P&gt;&lt;P&gt;class-map match-all VIP-SSL-PORTAL&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 10.49.30.230 tcp eq https&lt;/P&gt;&lt;P&gt;class-map match-all VIP-WWW-PORTAL&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 10.49.30.230 tcp eq www&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match PORTAL_HTTPS_DEFAULT&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; compress default-method gzip&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm SOURCEIP-STICKY-HTTP-SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; action HTTP_MODIFICATION&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy client CLIENT_PORTAL&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match PORTAL_HTTP_DEFAULT&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; serverfarm PORTAL_HTTPS_SFARM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match L4_PORTAL_LB&lt;/P&gt;&lt;P&gt;&amp;nbsp; class VIP-WWW-PORTAL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy PORTAL_HTTP_DEFAULT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 260&lt;/P&gt;&lt;P&gt;&amp;nbsp; class VIP-SSL-PORTAL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy PORTAL_HTTPS_DEFAULT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 260&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options PERSISTENCE-REBALANCE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy server SERVER_PORTAL&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 260&lt;/P&gt;&lt;P&gt;&amp;nbsp; description User-Access&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.49.30.231 255.255.255.192&lt;/P&gt;&lt;P&gt;&amp;nbsp; peer ip address 10.49.30.232 255.255.255.192&lt;/P&gt;&lt;P&gt;&amp;nbsp; access-group input everyone&lt;/P&gt;&lt;P&gt;&amp;nbsp; nat-pool 1 10.49.30.252 10.49.30.252 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&amp;nbsp; service-policy input L4_PORTAL_LB&lt;/P&gt;&lt;P&gt;&amp;nbsp; no shutdown&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ip route 0.0.0.0 0.0.0.0 10.49.30.195&lt;/P&gt;&lt;P&gt;ip route 10.0.0.0 255.255.255.0 10.49.30.193&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;need your advice&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 03:41:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/need-help-for-redirect-to-https/m-p/2403209#M41382</guid>
      <dc:creator>hamz-zackops</dc:creator>
      <dc:date>2013-11-22T03:41:44Z</dc:date>
    </item>
    <item>
      <title>Need Help for redirect to HTTPS</title>
      <link>https://community.cisco.com/t5/application-networking/need-help-for-redirect-to-https/m-p/2403210#M41383</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Hamzah,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your redirect configuration looks good. It should work. So any user who comes and class match conditon should be redirected to HTTPS and you dont' need NAT there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Nov 2013 16:53:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/need-help-for-redirect-to-https/m-p/2403210#M41383</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2013-11-22T16:53:20Z</dc:date>
    </item>
    <item>
      <title>Need Help for redirect to HTTPS</title>
      <link>https://community.cisco.com/t5/application-networking/need-help-for-redirect-to-https/m-p/2403211#M41384</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi kanwal,&lt;/P&gt;&lt;P&gt;you mean i should remove "nat dynamic 1 vlan 260" from class VIP-SSL-PORTAL ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; class VIP-SSL-PORTAL&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy PORTAL_HTTPS_DEFAULT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; &lt;STRONG&gt; nat dynamic 1 vlan 260&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; appl-parameter http advanced-options PERSISTENCE-REBALANCE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ssl-proxy server SERVER_PORTAL&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Nov 2013 03:57:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/need-help-for-redirect-to-https/m-p/2403211#M41384</guid>
      <dc:creator>hamz-zackops</dc:creator>
      <dc:date>2013-11-25T03:57:46Z</dc:date>
    </item>
    <item>
      <title>Need Help for redirect to HTTPS</title>
      <link>https://community.cisco.com/t5/application-networking/need-help-for-redirect-to-https/m-p/2403212#M41385</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Hamzah,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No i was talking for redirection so you don't need NAT here since traffic is never given to any realserver but ACE itself redirects&amp;nbsp; it. It shouldn't make any difference but worth a try if it is not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, i just noticed that you are using end to end SSL which means front and back end connections would be SSL, so why you have defined rserver with port 80 in serverfarm?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host WWW_PORTAL_SFARM&lt;/P&gt;&lt;P&gt;rserver PORTAL-A 80--------------------&amp;gt;80 is for http,&amp;nbsp; you should be using the port on which the server listens. If server listens on port 80 then it means that you cannot use end to end and hence you should remove SSL-PROXY CLIENT configuration from policy map.&lt;/P&gt;&lt;P&gt;inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match L4_PORTAL_LB&lt;/P&gt;&lt;P&gt;class VIP-WWW-PORTAL&lt;/P&gt;&lt;P&gt;loadbalance vip inservice&lt;/P&gt;&lt;P&gt;loadbalance policy PORTAL_HTTP_DEFAULT&lt;/P&gt;&lt;P&gt;loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;nat dynamic 1 vlan 260-----------&amp;gt;Remove this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 25 Nov 2013 13:16:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/need-help-for-redirect-to-https/m-p/2403212#M41385</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2013-11-25T13:16:27Z</dc:date>
    </item>
  </channel>
</rss>

