<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Kanwal I forgot to mention in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463404#M41772</link>
    <description>&lt;P&gt;Kanwal I forgot to mention its not just the cas servers. If I try telnet to VIP from one of the web tier servers it works fine in vlan 62 but if I move that server to vlan 662 I have the same problem can't telnet to vip on 443 or 80.&lt;/P&gt;&lt;P&gt;You reckon still a source nat problem?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Apr 2014 17:21:44 GMT</pubDate>
    <dc:creator>netternewbie</dc:creator>
    <dc:date>2014-04-15T17:21:44Z</dc:date>
    <item>
      <title>ACE 20 CAS servers</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463381#M41749</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;I have to load balance two CAS servers. Is this the correct way to setup the probes and serverfarm. I am using an ACE 20.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;probe tcp TESTCAS-PROBE&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; interval 3&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; passdetect interval 5&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;parameter-map type ssl SSL-TESTCAS-FARM-ADVANCED&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; cipher RSA_WITH_RC4_128_MD5&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;rserver host TSTCAS&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; ip address 10.192.6.2&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; inservice&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;rserver host TSTCAS2&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; ip address 10.192.6.3&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; inservice&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;ssl-proxy service SSL-TESTCAS-FARM&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; key testcas.pem&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; cert testcascert&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; chaingroup TEST-CHAINGRP&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; ssl advanced-options SSL-TESTCAS-FARM-ADVANCED&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;serverfarm redirect HTTP-TESTCAS-FARM&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; rserver HTTP-TESTCAS&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; &amp;nbsp; inservice&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;serverfarm host TESTCAS-FARM&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; predictor leastconns&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; probe TESTCAS-PROBE&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; rserver TSTCAS 80&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; &amp;nbsp; inservice&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; rserver TSTCAS2 80&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; &amp;nbsp; inservice&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;sticky ip-netmask 255.255.255.255 address source&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;STICKY-SSL-TESTCAS-FARM&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; timeout 720&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; timeout activeconns&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; replicate sticky&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; serverfarm TESTCAS-FARM&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;class-map match-any TESTCAS-VIP&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; 2 match virtual-address 10.192.6.1 tcp eq https&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;policy-map type loadbalance first-match TESTCAS-POLICY&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; class class-default&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;&amp;nbsp; &amp;nbsp; sticky-serverfarm STICKY-SSL-TESTCAS-FARM&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;policy-map multi-match TESTCASPOLICY&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;class TESTCAS-VIP&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;loadbalance vip inservice&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;loadbalance policy TESTCAS-POLICY&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;loadbalance vip icmp-reply active&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;ssl-proxy server SSL-TESTCAS-PROXY&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;SPAN style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;"&gt;service-policy input TESTCASPOLICY&lt;/SPAN&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&lt;BR style="color: rgb(34, 34, 34); font-family: arial, sans-serif; font-size: 13px; line-height: normal;" /&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Apr 2014 22:58:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463381#M41749</guid>
      <dc:creator>netternewbie</dc:creator>
      <dc:date>2014-04-10T22:58:41Z</dc:date>
    </item>
    <item>
      <title>Hi,The above looks good.</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463382#M41750</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;The above looks good. Looking at the probe i would recommend that you always keep more than passdetect interval time. You can read about "Skipped probes" for detail. Ideally, interval should not be too aggressive. 3 seconds is very aggressive time to probe servers/application. I would suggest to increase it to 10-15 seconds.&lt;/P&gt;&lt;P&gt;Other than that config looks fine and i see that you have selected a particular cipher too so i guess that was the requirement. A client coming with another cipher will renegotiate and if it cannot come with the above cipher in list, handshake will fail.&lt;/P&gt;&lt;P&gt;Let me know if you have any questions.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 01:13:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463382#M41750</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-04-11T01:13:54Z</dc:date>
    </item>
    <item>
      <title>Thanks Kanwalsi, I am not</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463383#M41751</link>
      <description>&lt;P&gt;Thanks Kanwalsi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am not sure on passdetect interval as I have had no information from the server guys. This isn't micrsoft CAS but it is CAS for a webportal application.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will let you know what requirements the server guys get back to me with. Again they didn't specify a cipher but this has been used in all other load balancer configs.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 11 Apr 2014 09:03:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463383#M41751</guid>
      <dc:creator>netternewbie</dc:creator>
      <dc:date>2014-04-11T09:03:04Z</dc:date>
    </item>
    <item>
      <title>Hi Netter,It is your set up</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463384#M41752</link>
      <description>&lt;P&gt;Hi Netter,&lt;/P&gt;&lt;P&gt;It is your set up and you shall tweak different parameters available to suit your environment.&lt;/P&gt;&lt;P&gt;But let me know if you need anything from my side.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;</description>
      <pubDate>Sat, 12 Apr 2014 13:40:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463384#M41752</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-04-12T13:40:11Z</dc:date>
    </item>
    <item>
      <title>Thanks Kanwalsi,Seems there</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463385#M41753</link>
      <description>&lt;P&gt;Thanks Kanwalsi,&lt;/P&gt;&lt;P&gt;Seems there is a change in design. They want to pass traffic straight onto the CAS servers, where the certificates will be installed. The CAS certificates have to be on the CAS servers, both http and https traffic to be enabled from Load Balancer to CAS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;They say this method ensures that all servers&amp;nbsp; and internal communication to CAS takes place securely.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will redo the config and see how it goes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 08:49:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463385#M41753</guid>
      <dc:creator>netternewbie</dc:creator>
      <dc:date>2014-04-14T08:49:33Z</dc:date>
    </item>
    <item>
      <title>Hi Kanwalsi, Because now they</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463386#M41754</link>
      <description>&lt;P&gt;Hi Kanwalsi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because now they want the certs on the servers and traffic to reach the servers on 80 and 443 I have enabled the config below. AM I on the right track? I have probe probing the servers in 443 and have a redirect farm enabled as well. Not sure if I should have a https probe and 443 in the serverfarm?&lt;/P&gt;&lt;P&gt;May be I am on the wrong track altogether but this is what I have?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;probe https TESTCAS-PROBE&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;interval 3&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;passdetect interval 5&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;expect status 200 200&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;rserver redirect HTTP-TESTCAS&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;webhost-redirection &lt;A href="https://%h/%p" target="_blank"&gt;https://%h/%p&lt;/A&gt; 301&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;inservice&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;rserver host TSTCAS&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;ip address 10.192.168.44&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;inservice&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;rserver host TSTCAS2&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;ip address 10.192.168.58&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;inservice&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;serverfarm redirect HTTP-TEST-FARM&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;rserver HTTP-TEST&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;inservice&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;serverfarm host TESTCAS-FARM&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;predictor leastconns&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;probe TESTCAS-PROBE&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;rserver TSTCAS 443&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;inservice&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;rserver TSTCAS2 443&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;inservice&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;sticky ip-netmask 255.255.255.255 address source STICKY-SSL-**-TESTCAS-FARM&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;timeout 720&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;timeout activeconns&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;replicate sticky&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;sticky ip-netmask 255.255.255.255 address source STICKY-TESTCAS-FARM&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;timeout 720&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;timeout activeconns&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;replicate sticky&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;serverfarm TESTCAS-FARM&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;class-map match-any TESTCAS-VIP&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;2 match virtual-address 10.192.158.60 tcp eq https&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;class-map match-any REDIRECT-HTTPCAS-TEST&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;2 match virtual-address 10.192.168.60 tcp eq www&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;policy-map type loadbalance first-match TESTCAS-POLICY&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;class class-default&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;sticky-serverfarm STICKY-TESTCAS-FARM&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;policy-map type loadbalance first-match TESTCAS-POLICY-REDIRECT&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;class class-default&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;sticky-serverfarm STICKY-SSL-**-TESTCAS-FARM&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;policy-map multi-match TESTCASPOLICY&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;class TESTCAS-VIP&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;loadbalance vip inservice&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;loadbalance policy TESTCAS-POLICY&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;loadbalance vip icmp-reply active&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;policy-map multi-match TESTCASREDIRECTPOLICY&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;class REDIRECT-HTTPCAS-TEST&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;loadbalance vip inservice&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;loadbalance policy TESTCAS-POLICY-REDIRECT&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;loadbalance vip icmp-reply active&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;loadbalance vip advertise&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;service-policy input TESTCASREDIRECTPOLICY&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;service-policy input TESTCASPOLICY&lt;/P&gt;&lt;P style="margin-bottom:0in"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 12:02:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463386#M41754</guid>
      <dc:creator>netternewbie</dc:creator>
      <dc:date>2014-04-14T12:02:42Z</dc:date>
    </item>
    <item>
      <title>Hi,No problem. Let me know if</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463387#M41755</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;No problem. Let me know if you need anything. Also, if they don't want ACE to do anything but just loadbalance then it is just going to be simple L3-L4 based loadbalancing and should be pretty straight forward.&lt;/P&gt;&lt;P&gt;Good luck!&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 15:28:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463387#M41755</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-04-14T15:28:44Z</dc:date>
    </item>
    <item>
      <title>Thanks Kanwalsi, Is the</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463388#M41756</link>
      <description>&lt;P&gt;Thanks Kanwalsi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the configuration in the post above correct? I am not sure if the redirect server farm is the right approach to doing this. it may work but would the right approach&amp;nbsp; be to 443 from the servers in the serverfarm and have it like this:&lt;/P&gt;&lt;P&gt;serverfarm host TESTCAS-FARM&lt;/P&gt;&lt;P&gt;predictor leastconns&lt;/P&gt;&lt;P&gt;probe TESTCAS-PROBE&lt;/P&gt;&lt;P&gt;rserver TSTCAS&lt;/P&gt;&lt;P&gt;inservice&lt;/P&gt;&lt;P&gt;rserver TSTCAS2&lt;/P&gt;&lt;P&gt;inservice&lt;/P&gt;&lt;P&gt;And then just add another class match to the vip for www like below?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;class-map match-any TESTCAS-VIP&lt;/P&gt;&lt;P&gt;2 match virtual-address 10.192.158.60 tcp eq https&lt;/P&gt;&lt;P&gt;3 match virtual-address 10.192.158.60 tcp eq www&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And totally remove the redirect config?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 15:44:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463388#M41756</guid>
      <dc:creator>netternewbie</dc:creator>
      <dc:date>2014-04-14T15:44:45Z</dc:date>
    </item>
    <item>
      <title>Hi Netter,Redirect would be</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463389#M41757</link>
      <description>&lt;P&gt;Hi Netter,&lt;/P&gt;&lt;P&gt;Redirect would be needed if you want the ACE to redirect the users coming on HTTP&amp;nbsp; to HTTPS. Once they come on HTTPS they will be loadbalanced.&lt;/P&gt;&lt;P&gt;If redirect is needed then you need to configure a redirect server, serverfarm, call it in policy map and then call the class-map for www in policy multi-match. So traffic would be redirected from http to HTTPS. Once the user comes on HTTPS, it will match class 443, and get loadbalanced to a different serverfarm.&lt;/P&gt;&lt;P&gt;Coming back to your configuration i don't see you have called redirect serverfarm in policy map. That will not work. So you need to be very clear what customer wants and we can configure accordingly.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 15:50:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463389#M41757</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-04-14T15:50:48Z</dc:date>
    </item>
    <item>
      <title>Thanks Kanwalsi,This is what</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463390#M41758</link>
      <description>&lt;P&gt;Thanks Kanwalsi,&lt;/P&gt;&lt;P&gt;This is what I got from the external server guys.&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:11.0pt;font-family:Symbol;color:#1f497d"&gt;&lt;SPAN&gt;·&lt;SPAN style="font:7.0pt &amp;quot;Times New Roman&amp;quot;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size:11.0pt;font-family:&amp;quot;Calibri&amp;quot;,&amp;quot;sans-serif&amp;quot;;color:#1f497d"&gt;For the CAS Tier, pass the traffic straight onto the CAS servers, on which the certificates will be installed. The CAS Certificates just have to be on the CAS servers, both http and https traffic to be enabled from Load balancer to CAS.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The internal server guys say the servers listen on both 80 and 443 and if a request comes in on 80 the servers redirect to 443.&lt;/P&gt;&lt;P&gt;This makes me think I need my server farm setup as follows:&lt;/P&gt;&lt;P&gt;serverfarm host TESTCAS-FARM&lt;/P&gt;&lt;P&gt;predictor leastconns&lt;/P&gt;&lt;P&gt;probe TESTCAS-PROBE&lt;/P&gt;&lt;P&gt;rserver TSTCAS&lt;/P&gt;&lt;P&gt;inservice&lt;/P&gt;&lt;P&gt;rserver TSTCAS2&lt;/P&gt;&lt;P&gt;inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And then my class match as follows:&lt;/P&gt;&lt;P&gt;class-map match-any TESTCAS-VIP&lt;/P&gt;&lt;P&gt;2 match virtual-address 10.192.158.60 tcp eq https&lt;/P&gt;&lt;P&gt;3 match virtual-address 10.192.158.60 tcp eq www&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Am I totally wrong or is this the right idea? Never had to do a configuration where the servers handled ssl offload and where they accepted traffic on both 80 and 443.&lt;/P&gt;&lt;P&gt;Do I need two probes configured to the one serverfarm? Then two vips as above?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 16:31:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463390#M41758</guid>
      <dc:creator>netternewbie</dc:creator>
      <dc:date>2014-04-14T16:31:12Z</dc:date>
    </item>
    <item>
      <title>Hi Netter,So you should have</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463391#M41759</link>
      <description>&lt;P&gt;Hi Netter,&lt;/P&gt;&lt;P&gt;So you should have two class-maps:&lt;/P&gt;&lt;P&gt;class-map match-any TESTCAS-VIP&lt;/P&gt;&lt;P&gt;2 match virtual-address 10.192.158.60 tcp eq https&lt;/P&gt;&lt;P&gt;class-map match-any TESTCAS-VIP1&lt;/P&gt;&lt;P&gt;3 match virtual-address 10.192.158.60 tcp eq www&lt;/P&gt;&lt;P&gt;Then you should have two serverfarms:&lt;/P&gt;&lt;P&gt;serverfarm host TESTCAS-FARM&lt;/P&gt;&lt;P&gt;predictor leastconns&lt;/P&gt;&lt;P&gt;probe TESTCAS-PROBE&lt;/P&gt;&lt;P&gt;rserver TSTCAS&lt;/P&gt;&lt;P&gt;inservice&lt;/P&gt;&lt;P&gt;rserver TSTCAS2&lt;/P&gt;&lt;P&gt;inservice&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;serverfarm host TESTCAS-FARM-HTTPS&lt;/P&gt;&lt;P&gt;rserver TSTCAS 443&lt;/P&gt;&lt;P&gt;inservice&lt;/P&gt;&lt;P&gt;rserver TSTCAS2 443&lt;/P&gt;&lt;P&gt;inservice&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match TESTCAS-POLICY-HTTP&lt;/P&gt;&lt;P&gt;class class-default&lt;/P&gt;&lt;P&gt;serverfarm TESTCAS-FARM&lt;/P&gt;&lt;P&gt;policy-map type loadbalance first-match TESTCAS-POLICY-HTTPS&lt;/P&gt;&lt;P&gt;class class-default&lt;/P&gt;&lt;P&gt;serverfarm TESTCAS-FARM-HTTPS&lt;/P&gt;&lt;P&gt;policy-map multi-match TESTPOLICY&lt;/P&gt;&lt;P&gt;Class TESTCAS-VIP&lt;/P&gt;&lt;P&gt;loadbalance vip inservice&lt;/P&gt;&lt;P&gt;loadbalance policy TESTCAS-POLICY-HTTPS&lt;/P&gt;&lt;P&gt;class TESTCAS-VIP1&lt;/P&gt;&lt;P&gt;loadbalance vip inservice&lt;/P&gt;&lt;P&gt;loadbalance policy TESTCAS-POLICY-HTTP&lt;/P&gt;&lt;P&gt;That's the configuration you need to do. I just did it for you:)&lt;/P&gt;&lt;P&gt;Now of course you should have two different probes. Simply you can have TCP port 80 for serverfarm TESTCAS-FARM and TCP port 443 for serverfarm TESTCAS-FARM-HTTPS or you can have HTTP and HTTPS for respective serverfarms.&lt;/P&gt;&lt;P&gt;Let me know if you have any questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 18:35:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463391#M41759</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-04-14T18:35:34Z</dc:date>
    </item>
    <item>
      <title>Hi Kanwal,Firstly thanks for</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463392#M41760</link>
      <description>&lt;P&gt;Hi Kanwal,&lt;/P&gt;&lt;P&gt;Firstly thanks for all your help and time spent on this. I have taken your advice and redone the hole config. I have 2 class maps and 2 serverfarms. Can you please double check my serverfarms and probes?&lt;/P&gt;&lt;P&gt;Below is the full config. Does it look ok to you? Am I on the right track?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;probe https TESTCASHTTPS-PROBE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family: 'times new roman', times, serif;"&gt;&amp;nbsp; interval 3&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; passdetect interval 5&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; expect status 200 200&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;probe http TESTCASWWW-PROBE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; interval 3&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; passdetect interval 5&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; expect status 200 200&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;rserver host TSTCAS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; ip address&amp;nbsp; 10.192.158.44&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; inservice&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;rserver host TSTCAS2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; ip address 10.193.158.58&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; inservice&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;serverfarm host TESTCASHTTPS-FARM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; predictor leastconns&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; probe TESTCASHTTPS-PROBE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; rserver TSTCAS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SMALL&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; rserver TSTCAS2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SMALL&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="times new roman, times, serif"&gt;&lt;SPAN style="font-size: 12px;"&gt;&amp;nbsp; &amp;nbsp; inservice&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;serverfarm host TESTCASWWW-FARM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; predictor leastconns&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; probe TESTCASWWW-PROBE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; rserver TSTCAS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; rserver TSTCAS2&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; inservice&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;sticky ip-netmask 255.255.255.255 address source STICKY-TESTCASWWW-FARM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; timeout 720&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; timeout activeconns&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; replicate sticky&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; serverfarm TESTCASWWW-FARM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;sticky ip-netmask 255.255.255.255 address source STICKY-TESTCASHTTPS-FARM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; timeout 720&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; timeout activeconns&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; replicate sticky&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; serverfarm TESTCASHTTPS-FARM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;class-map match-any TESTCASHTTPS-VIP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; 2 match virtual-address 10.192.158.60 tcp eq https&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;class-map match-any TESTCASWWW-VIP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; 3 match virtual-address 10.192.158.60 tcp eq www&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;policy-map type loadbalance first-match TESTCAS-POLICY-HTTPS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; class class-default&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm STICKY-TESTCASHTTPS-FARM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;policy-map type loadbalance first-match TESTCAS-POLICY-WWW&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; class class-default&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sticky-serverfarm STICKY-TESTCASWWW-FARM&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;policy-map multi-match TESTCASPOLICYHTTPS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; class TESTCASHTTPS-VIP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy TESTCAS-POLICY-HTTPS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;policy-map multi-match TESTCASPOLICYWWW&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp; class TESTCASWWW-VIP&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance vip inservice&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; loadbalance policy TESTCAS-POLICY-WWW&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;service-policy input TESTCASPOLICYWWW&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:12px;"&gt;&lt;SPAN style="font-family:times new roman,times,serif;"&gt;service-policy input TESTCASPOLICYHTTPS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 22:42:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463392#M41760</guid>
      <dc:creator>netternewbie</dc:creator>
      <dc:date>2014-04-14T22:42:26Z</dc:date>
    </item>
    <item>
      <title>Hi Netter,The configuration</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463393#M41761</link>
      <description>&lt;P&gt;Hi Netter,&lt;/P&gt;&lt;P&gt;The configuration looks good but you should also have port number 443 defined in the HTTPS serverfarm.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 23:06:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463393#M41761</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-04-14T23:06:10Z</dc:date>
    </item>
    <item>
      <title>Thanks Kanwal,But why when</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463394#M41762</link>
      <description>&lt;P&gt;Thanks Kanwal,&lt;/P&gt;&lt;P&gt;But why when the probe is https? Am I missing something?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&lt;SPAN style="font-size: 12px;"&gt;&lt;SPAN style="font-family: 'times new roman', times, serif;"&gt;probe https TESTCASHTTPS-PROBE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&lt;SPAN style="font-size: 12px;"&gt;&lt;SPAN style="font-family: 'times new roman', times, serif;"&gt;&amp;nbsp; interval 3&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&lt;SPAN style="font-size: 12px;"&gt;&lt;SPAN style="font-family: 'times new roman', times, serif;"&gt;&amp;nbsp; passdetect interval 5&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 14px;"&gt;&lt;SPAN style="font-size: 12px;"&gt;&lt;SPAN style="font-family: 'times new roman', times, serif;"&gt;&amp;nbsp; expect status 200 200&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 23:15:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463394#M41762</guid>
      <dc:creator>netternewbie</dc:creator>
      <dc:date>2014-04-14T23:15:04Z</dc:date>
    </item>
    <item>
      <title>Hi Netter,No. You are good:</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463395#M41763</link>
      <description>&lt;P&gt;Hi Netter,&lt;/P&gt;&lt;P&gt;No. You are good:)&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 23:17:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463395#M41763</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-04-14T23:17:58Z</dc:date>
    </item>
    <item>
      <title>Great, thanks again for all</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463396#M41764</link>
      <description>&lt;P&gt;Great, thanks again for all the help on this. Lets hope the server guys are happy. I will let you know how it goes.&lt;/P&gt;&lt;P&gt;Thanks/&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 23:25:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463396#M41764</guid>
      <dc:creator>netternewbie</dc:creator>
      <dc:date>2014-04-14T23:25:29Z</dc:date>
    </item>
    <item>
      <title>Hi Netter,Sure. Welcome</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463397#M41765</link>
      <description>&lt;P&gt;Hi Netter,&lt;/P&gt;&lt;P&gt;Sure. Welcome always!&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;</description>
      <pubDate>Mon, 14 Apr 2014 23:26:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463397#M41765</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-04-14T23:26:28Z</dc:date>
    </item>
    <item>
      <title>Hi Kanwalsi, One problem that</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463398#M41766</link>
      <description>&lt;P&gt;Hi Kanwalsi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One problem that I have never seen before. I can get to the VIP from outside the network and the external world but can't from the two CAS servers. Have you ever seen this before?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2014 09:32:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463398#M41766</guid>
      <dc:creator>netternewbie</dc:creator>
      <dc:date>2014-04-15T09:32:56Z</dc:date>
    </item>
    <item>
      <title>Hi Netter,What do you mean by</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463399#M41767</link>
      <description>&lt;P&gt;Hi Netter,&lt;/P&gt;&lt;P&gt;What do you mean by you cannot get to them? Are you not able to ping them or you are trying to access the URL? You would need proper NAT in place for the server connection to work. But why do you need to access servers via VIP from the servers itself?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2014 14:01:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463399#M41767</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-04-15T14:01:50Z</dc:date>
    </item>
    <item>
      <title>Hi Kanwal,I have 3 vlans 62</title>
      <link>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463400#M41768</link>
      <description>&lt;P&gt;Hi Kanwal,&lt;/P&gt;&lt;P&gt;I have 3 vlans 62 layer 3 on router, 362 bridged fwsm and 662 bridged ace.&lt;/P&gt;&lt;P&gt;If I put a server in vlan 62 I can telnet to the VIP on port 443. telnet 10.192.228.60 443 and I get a connection fine.&lt;/P&gt;&lt;P&gt;However if I try from a server behind the ace in vlan 662 it doesn't connect.&lt;/P&gt;&lt;P&gt;I have a webtier vip on this same context and that works fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2014 14:10:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-20-cas-servers/m-p/2463400#M41768</guid>
      <dc:creator>netternewbie</dc:creator>
      <dc:date>2014-04-15T14:10:04Z</dc:date>
    </item>
  </channel>
</rss>

