<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Rservers initiated traffic not sourcing the traffic as VIP in Ace 4710 in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460958#M41711</link>
    <description>&lt;P&gt;One of the feature of our application is that our Application Server initiate text message to our devices sourcing from UDP 1120 and device need to see the message come from a specific pubic IP (2.2.2.2) with UDP port 1120 and reply back with the same Public IP (2.2.2.2) with UDP port 1120.The problem is we can make that happen if we have only one server in our ACE Serverfarm when we do a SNAT the real servers with the VIP address (10.1.246.32) but it does not work when we have more than one server in the Serverfarm. Since we have 2 servers, i cannot nat the real servers with the VIP address, if I do a PAT, obviously it is changing the source port of the request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: This setup is working fine with the Cisco Content Switch module running on chasis 6509. When I sniff the traffic initiated from the server coming the CSM load balancer, it is sourcing the traffic as the VIP and the source port remains the same by default but this is not the case with ACE 4710&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic flow as follows&lt;/P&gt;&lt;P&gt;===============&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE 4710&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FWSM (Firewall static NAT)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Device ( configured with 2.2.2.2:1120 (udp) to snd/rcv msg)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VIP&lt;/P&gt;&lt;P&gt;Rserver 1&amp;nbsp;&amp;nbsp; - 10.1.104.80&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.1.246.32&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.1.246.32&amp;nbsp; &amp;lt; - &amp;gt; 2.2.2.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.1.1.1&lt;/P&gt;&lt;P&gt;Rserver 2&amp;nbsp;&amp;nbsp; - 10.1.104.81c &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -------------------------------&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - traffic flow from server to the device when we send msg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configs:&lt;/P&gt;&lt;P&gt;======&lt;/P&gt;&lt;P&gt;rserver host server1&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.1.104.80&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host server2&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.1.104.81&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; failaction purge&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe ICMP&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver server1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver server2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list TEST-1120 line 8 extended permit udp host 10.1.104.80 eq 1120 any &lt;/P&gt;&lt;P&gt;access-list TEST-1120 line 16 extended permit udp host 10.1.104.81 eq 1120 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type connection UDP_TIMEOUT&lt;/P&gt;&lt;P&gt;&amp;nbsp; set timeout inactivity 3600&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky ip-netmask 255.255.255.255 address source STKY-SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; timeout 180&lt;/P&gt;&lt;P&gt;&amp;nbsp; replicate sticky&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all CLS-SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 10.1.246.32 udp eq 1120&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all SERVERNAT&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match access-list TEST-1120&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match POL-SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm STKY-SFARM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match POL-LB&lt;/P&gt;&lt;P&gt;class CLS-SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy POL-SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options UDP_TIMEOUT&lt;/P&gt;&lt;P&gt;class SERVERNAT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 244&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int vlan 244&lt;/P&gt;&lt;P&gt;ip address 10.1.246.2 255.255.255.0&lt;/P&gt;&lt;P&gt;service-policy input POL-LB&lt;/P&gt;&lt;P&gt;nat-pool 1 10.1.246.32 10.1.246.32 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&amp;nbsp; mac-sticky enable&lt;/P&gt;&lt;P&gt;&amp;nbsp; no icmp-guard&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 2506&lt;/P&gt;&lt;P&gt;ip address 10.1.104.2 255.255.255.0&lt;/P&gt;&lt;P&gt;service-policy input POL-LB&lt;/P&gt;&lt;P&gt;&amp;nbsp; mac-sticky enable&lt;/P&gt;&lt;P&gt;&amp;nbsp; no icmp-guard&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;</description>
    <pubDate>Thu, 06 Feb 2014 19:10:50 GMT</pubDate>
    <dc:creator>Ethen Daniel</dc:creator>
    <dc:date>2014-02-06T19:10:50Z</dc:date>
    <item>
      <title>Rservers initiated traffic not sourcing the traffic as VIP in Ace 4710</title>
      <link>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460958#M41711</link>
      <description>&lt;P&gt;One of the feature of our application is that our Application Server initiate text message to our devices sourcing from UDP 1120 and device need to see the message come from a specific pubic IP (2.2.2.2) with UDP port 1120 and reply back with the same Public IP (2.2.2.2) with UDP port 1120.The problem is we can make that happen if we have only one server in our ACE Serverfarm when we do a SNAT the real servers with the VIP address (10.1.246.32) but it does not work when we have more than one server in the Serverfarm. Since we have 2 servers, i cannot nat the real servers with the VIP address, if I do a PAT, obviously it is changing the source port of the request.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Note: This setup is working fine with the Cisco Content Switch module running on chasis 6509. When I sniff the traffic initiated from the server coming the CSM load balancer, it is sourcing the traffic as the VIP and the source port remains the same by default but this is not the case with ACE 4710&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Traffic flow as follows&lt;/P&gt;&lt;P&gt;===============&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACE 4710&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; FWSM (Firewall static NAT)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Device ( configured with 2.2.2.2:1120 (udp) to snd/rcv msg)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; VIP&lt;/P&gt;&lt;P&gt;Rserver 1&amp;nbsp;&amp;nbsp; - 10.1.104.80&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.1.246.32&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 10.1.246.32&amp;nbsp; &amp;lt; - &amp;gt; 2.2.2.2&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1.1.1.1&lt;/P&gt;&lt;P&gt;Rserver 2&amp;nbsp;&amp;nbsp; - 10.1.104.81c &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -------------------------------&amp;gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - traffic flow from server to the device when we send msg&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Configs:&lt;/P&gt;&lt;P&gt;======&lt;/P&gt;&lt;P&gt;rserver host server1&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.1.104.80&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;rserver host server2&lt;/P&gt;&lt;P&gt;&amp;nbsp; ip address 10.1.104.81&lt;/P&gt;&lt;P&gt;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;serverfarm host SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; failaction purge&lt;/P&gt;&lt;P&gt;&amp;nbsp; probe ICMP&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver server1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp; rserver server2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list TEST-1120 line 8 extended permit udp host 10.1.104.80 eq 1120 any &lt;/P&gt;&lt;P&gt;access-list TEST-1120 line 16 extended permit udp host 10.1.104.81 eq 1120 any&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;parameter-map type connection UDP_TIMEOUT&lt;/P&gt;&lt;P&gt;&amp;nbsp; set timeout inactivity 3600&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;sticky ip-netmask 255.255.255.255 address source STKY-SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; serverfarm SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; timeout 180&lt;/P&gt;&lt;P&gt;&amp;nbsp; replicate sticky&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all CLS-SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match virtual-address 10.1.246.32 udp eq 1120&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;class-map match-all SERVERNAT&lt;/P&gt;&lt;P&gt;&amp;nbsp; 2 match access-list TEST-1120&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match POL-SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp; class class-default&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm STKY-SFARM&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;policy-map multi-match POL-LB&lt;/P&gt;&lt;P&gt;class CLS-SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy POL-SFARM&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip icmp-reply active&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; connection advanced-options UDP_TIMEOUT&lt;/P&gt;&lt;P&gt;class SERVERNAT&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp; nat dynamic 1 vlan 244&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;int vlan 244&lt;/P&gt;&lt;P&gt;ip address 10.1.246.2 255.255.255.0&lt;/P&gt;&lt;P&gt;service-policy input POL-LB&lt;/P&gt;&lt;P&gt;nat-pool 1 10.1.246.32 10.1.246.32 netmask 255.255.255.255&lt;/P&gt;&lt;P&gt;&amp;nbsp; mac-sticky enable&lt;/P&gt;&lt;P&gt;&amp;nbsp; no icmp-guard&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;interface vlan 2506&lt;/P&gt;&lt;P&gt;ip address 10.1.104.2 255.255.255.0&lt;/P&gt;&lt;P&gt;service-policy input POL-LB&lt;/P&gt;&lt;P&gt;&amp;nbsp; mac-sticky enable&lt;/P&gt;&lt;P&gt;&amp;nbsp; no icmp-guard&lt;/P&gt;&lt;P&gt;no shut&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2014 19:10:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460958#M41711</guid>
      <dc:creator>Ethen Daniel</dc:creator>
      <dc:date>2014-02-06T19:10:50Z</dc:date>
    </item>
    <item>
      <title>Rservers initiated traffic not sourcing the traffic as VIP in Ac</title>
      <link>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460959#M41712</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Ethen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are not using PAT then you would one more IP in the pool. If both servers need to communicate simultaneously we should have two IP's or we need to use PAT.&amp;nbsp; This is how it is suppose to work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 20:35:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460959#M41712</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-02-06T20:35:48Z</dc:date>
    </item>
    <item>
      <title>Rservers initiated traffic not sourcing the traffic as VIP in Ac</title>
      <link>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460960#M41713</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kanwal, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you for your reply. If I use the NAT with 2 ip address, I have the challenges to NAT it with the same public ip and same source port while it leaves the firewall. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In CSM, when the traffic leaves, it maintains the same source port and VIP address when the traffic egressess. Is there any way i can replicate in Ace 4710 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you know how the transparent command works with the serverfarm ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Ethen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 21:15:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460960#M41713</guid>
      <dc:creator>Ethen Daniel</dc:creator>
      <dc:date>2014-02-06T21:15:25Z</dc:date>
    </item>
    <item>
      <title>Rservers initiated traffic not sourcing the traffic as VIP in Ac</title>
      <link>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460961#M41714</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Ethen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Transparent command will mean that ACE will not do the destination NAT that it does by default when forwarding the packet to real server. It will not help in your scenario. For one server it should work in ACE 4710 as well but as you said when both servers will try to communicate it will be a problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 21:21:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460961#M41714</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-02-06T21:21:16Z</dc:date>
    </item>
    <item>
      <title>Rservers initiated traffic not sourcing the traffic as VIP in Ac</title>
      <link>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460962#M41715</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Ethen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you look at it logically if both the servers use same IP and same src port to go out , when the traffic will come back, how will ACE differentiate which packet shall go to which real server? That can be differentiated if you have PAT because it will have different destination ports when the traffic comes back.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 21:23:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460962#M41715</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-02-06T21:23:58Z</dc:date>
    </item>
    <item>
      <title>Rservers initiated traffic not sourcing the traffic as VIP in Ac</title>
      <link>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460963#M41716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kanwal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You are right. I understand that. I dont know what logic is been used by CSM to behave like this and why not. We are in the process of migrating everything from CSM to ACE 4710 due to EOL but knda stuck in the middle.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you know of any alternate solution, please let me know... Thanks again for your help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ethen&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 21:27:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460963#M41716</guid>
      <dc:creator>Ethen Daniel</dc:creator>
      <dc:date>2014-02-06T21:27:49Z</dc:date>
    </item>
    <item>
      <title>Rservers initiated traffic not sourcing the traffic as VIP in Ac</title>
      <link>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460964#M41717</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Ethen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thought about it but out of ideas:). May be someone else can throw some light on it but it is strange that it is working in CSM.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 22:30:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460964#M41717</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-02-06T22:30:46Z</dc:date>
    </item>
    <item>
      <title>Rservers initiated traffic not sourcing the traffic as VIP in Ac</title>
      <link>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460965#M41718</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see in CSS, they are able to nat the source ip address with VIP and port-mapping diabled. How do I implement &lt;/P&gt;&lt;P&gt;portmap disable in ACE 4710&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14pt; font-weight: bold; background-color: #ffffff; font-family: Arial, Helvetica, sans-serif;"&gt;Disabling Port Mapping&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt; &lt;A name="wp1150193" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;A name="wpmkr1150194" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0em 6px; background-color: #ffffff;"&gt;By default, the CSS NATs source IP addresses &lt;EM&gt;and&lt;/EM&gt; PATs source ports for a configured source group. If you configure the &lt;STRONG&gt;portmap disable&lt;/STRONG&gt;command in a source group, the CSS performs NAT on the source IP addresses but does not perform PAT on the source ports of UDP traffic that matches on that source group.&lt;/P&gt;&lt;P&gt; &lt;A name="wp1156247" style="color: #000000; font-family: Arial, Helvetica, sans-serif; background-color: #ffffff;"&gt;&lt;/A&gt;&lt;/P&gt;&lt;P style="color: #000000; font-family: Arial, Helvetica, sans-serif; font-size: 12px; margin: 1px 0em 6px; background-color: #ffffff;"&gt;For UDP applications with high-numbered assigned ports (for example, SIP and WAP), we recommend that you preserve those port numbers by configuring destination services in source groups instead of using the &lt;STRONG&gt;portmap disable&lt;/STRONG&gt; command. Destination services cause the CSS to NAT the client source ports, but not the destination ports. For information about configuring destination services,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 06 Feb 2014 23:05:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460965#M41718</guid>
      <dc:creator>Ethen Daniel</dc:creator>
      <dc:date>2014-02-06T23:05:33Z</dc:date>
    </item>
    <item>
      <title>Rservers initiated traffic not sourcing the traffic as VIP in Ac</title>
      <link>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460966#M41719</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Ethen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you paste the configuration done in CSM which you say is working? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Feb 2014 01:40:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460966#M41719</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-02-07T01:40:28Z</dc:date>
    </item>
    <item>
      <title>Rservers initiated traffic not sourcing the traffic as VIP in Ac</title>
      <link>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460967#M41720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kanwal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is the configuration I see in CSS, I will add the configurations from CSM as well later....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;group VIP-NAT&lt;/P&gt;&lt;P&gt;vip address &lt;SPAN style="font-size: 10pt;"&gt;10.1.246.32&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;portmap disable&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;active&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;acl 15 &lt;/P&gt;&lt;P&gt;&amp;nbsp; clause 10 permit udp 10.1.104.80 eq 1120 destination 1.0.0.0 255.0.0.0 sourcegroup &lt;SPAN style="font-size: 10pt;"&gt;VIP-NAT&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp; clause 20 permit udp 10.1.104.81 eq 1120 destination 1.0.0.0 255.0.0.0 sourcegroup &lt;/SPAN&gt;&lt;SPAN style="font-size: 10pt;"&gt;VIP-NAT&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;apply circuit-(VLANX)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ethen&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Feb 2014 16:49:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460967#M41720</guid>
      <dc:creator>Ethen Daniel</dc:creator>
      <dc:date>2014-02-07T16:49:43Z</dc:date>
    </item>
    <item>
      <title>Rservers initiated traffic not sourcing the traffic as VIP in Ac</title>
      <link>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460968#M41721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Ethen,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't see any option in ACE to disable port mapping. By default it doesn't do port mapping unless you define PAT.&amp;nbsp; What is baffling here is that destination is same and when traffic comes back how does CSS or CSM decide to which server packet should be given unless that doesn't matter. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would suggest to open a TAC case as well. If it works for CSM it should for ACE module/appliance. Since it is isn't it would be helpful to know why this functionality was removed or not given. May be they can add a new feature in future releases but with ACE phasing out i doubt it will happen.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 07 Feb 2014 17:02:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/rservers-initiated-traffic-not-sourcing-the-traffic-as-vip-in/m-p/2460968#M41721</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-02-07T17:02:07Z</dc:date>
    </item>
  </channel>
</rss>

