<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic HI KanwalThank you for the in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535333#M42201</link>
    <description>&lt;P&gt;HI Kanwal&lt;/P&gt;&lt;P&gt;Thank you for the response, I take it this command was introduced in A4. I have checked the configuration guide on the latest software for the ACE20 and I have not been able to see this setting.&lt;/P&gt;&lt;P&gt;Regards Craig&lt;/P&gt;</description>
    <pubDate>Mon, 21 Jul 2014 18:43:19 GMT</pubDate>
    <dc:creator>craig bache</dc:creator>
    <dc:date>2014-07-21T18:43:19Z</dc:date>
    <item>
      <title>ACE Cookie insert</title>
      <link>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535329#M42197</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;I am hoping someone can help with the following on the Cisco ACE, this is the ACE20.&lt;/P&gt;&lt;P&gt;A scan of our environment has revealed a vulnerability in the application hosted on ACE Load Balancer due to ACE inserting a predictable cookie for sticky http sessions.&lt;/P&gt;&lt;P&gt;The cookie type used is&amp;nbsp;cookie insert browser-expire, I believe this is expected as the cookie value is derived from a combination from the serverfarm name, rserver name, and rserver port.&lt;/P&gt;&lt;P&gt;Is there anyway to changed this so the cookie is not&amp;nbsp;predictable....&lt;/P&gt;&lt;P&gt;Thanks Craig&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2014 18:05:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535329#M42197</guid>
      <dc:creator>craig bache</dc:creator>
      <dc:date>2014-07-21T18:05:57Z</dc:date>
    </item>
    <item>
      <title>Hi Craig,I was wrong. You can</title>
      <link>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535330#M42198</link>
      <description>&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;I was wrong. You can actually define the string of your choice. Please have a look below:&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/interfaces_modules/services_modules/ace/vA4_2_0/configuration/slb/guide/slbcfggd/rsfarms.html#wpxref94060&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H3 class="p_H_Head3"&gt;Configuring a Real Server Cookie Value for Cookie Insertion&lt;/H3&gt;&lt;P&gt;From the above link:&lt;/P&gt;&lt;P class="pB1_Body1"&gt;You can enter a cookie string value of a real server that you want to use for HTTP cookie insertion by using the &lt;B class="cBold"&gt;cookie-string&lt;/B&gt; &lt;EM class="cEmphasis"&gt;value&lt;/EM&gt; command in server farm real server configuration mode. You can configure one cookie string for each real server. Valid entries are text strings with a maximum of 32 alphanumeric characters. You can include spaces and special characters in a cookie string value provided that the spaces and special characters are included in double quotes (for example, "test cookie string"). If you use quotes in a cookie string, the specified cookie-string value appears in double quotes in the running-configuration file.&lt;/P&gt;&lt;P&gt;Use cookie insertion when you want to use a session cookie for persistence if the server is not currently setting the appropriate cookie. With this feature enabled, the ACE inserts the cookie in the Set-Cookie header of the response from the server to the client.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2014 18:18:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535330#M42198</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-07-21T18:18:16Z</dc:date>
    </item>
    <item>
      <title>Hi Craig,So something like</title>
      <link>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535331#M42199</link>
      <description>&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;So something like this you can do in the serverfarm.&lt;/P&gt;&lt;P&gt;switch/Admin(config)# do sh running-config serverfarm XXX&lt;BR /&gt;Generating configuration....&lt;/P&gt;&lt;P&gt;serverfarm host XXX&lt;BR /&gt;rserver xxx1&lt;BR /&gt;cookie-string "test123"&lt;BR /&gt;inservice&lt;/P&gt;&lt;P&gt;Now, ACE shall use the above string for cookie insertion and it will point to rserver xxx1. You should have different string for each rserver under the serverfarm.&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2014 18:23:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535331#M42199</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-07-21T18:23:23Z</dc:date>
    </item>
    <item>
      <title>Hi Craig,I don't think there</title>
      <link>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535332#M42200</link>
      <description>&lt;P&gt;m&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2014 18:33:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535332#M42200</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-07-21T18:33:33Z</dc:date>
    </item>
    <item>
      <title>HI KanwalThank you for the</title>
      <link>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535333#M42201</link>
      <description>&lt;P&gt;HI Kanwal&lt;/P&gt;&lt;P&gt;Thank you for the response, I take it this command was introduced in A4. I have checked the configuration guide on the latest software for the ACE20 and I have not been able to see this setting.&lt;/P&gt;&lt;P&gt;Regards Craig&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2014 18:43:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535333#M42201</guid>
      <dc:creator>craig bache</dc:creator>
      <dc:date>2014-07-21T18:43:19Z</dc:date>
    </item>
    <item>
      <title>Hi Craig,I don't see it</title>
      <link>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535334#M42202</link>
      <description>&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;I don't see it either. It seems that it was never added to ace20. Only for appliance and ace30. With ACE end of life i don't see that it would be introduced either.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note:Please mark answers if they are helpful.&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2014 19:10:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535334#M42202</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-07-21T19:10:27Z</dc:date>
    </item>
    <item>
      <title>Hi Craig,I confirmed it and</title>
      <link>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535335#M42203</link>
      <description>&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;I confirmed it and you don't have this option in ACE20. Do you think you can try and configure static cookie? But you have limitation of 4095 static cookies only.&lt;/P&gt;&lt;P&gt;sticky http-cookie ACE COOKIE1&lt;/P&gt;&lt;P&gt;cookie insert&lt;/P&gt;&lt;P&gt;serverfarm Cookie-Sticky-Farm&lt;/P&gt;&lt;P&gt;1 static cookie-value "PC1" rserver PC1-1&lt;/P&gt;&lt;P&gt;2 static cookie-value "PC11" rserver PC2-1&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;</description>
      <pubDate>Mon, 21 Jul 2014 19:29:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535335#M42203</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-07-21T19:29:56Z</dc:date>
    </item>
    <item>
      <title>Hi KanwalThanks for the</title>
      <link>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535336#M42204</link>
      <description>&lt;P&gt;Hi Kanwal&lt;/P&gt;&lt;P&gt;Thanks for the response, I take it this will be a predictable cookie as the value is static.&lt;/P&gt;&lt;P&gt;Regards Craig&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2014 07:49:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535336#M42204</guid>
      <dc:creator>craig bache</dc:creator>
      <dc:date>2014-07-22T07:49:49Z</dc:date>
    </item>
    <item>
      <title>Hi Craig,You can define any</title>
      <link>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535337#M42205</link>
      <description>&lt;P&gt;Hi Craig,&lt;/P&gt;&lt;P&gt;You can define any anything there like "2 static cookie-value Test rserver PC2-1" and that will not make it predictable since it is not being generated by ACE depending upon standard parameters like rserver name etc.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note:Please mark answers if they are helpful.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jul 2014 16:58:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/ace-cookie-insert/m-p/2535337#M42205</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-07-22T16:58:48Z</dc:date>
    </item>
  </channel>
</rss>

