<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thank you KanwalIn this in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/cisco-ace-incorrect-translation-src-port/m-p/2604322#M42548</link>
    <description>&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-size:14px;"&gt;Thank you Kanwal&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;In this situation, class map matching on port 9081 and serverfarm listening on 9082.&lt;BR /&gt;----------------------------------------------------------------------------------&lt;BR /&gt;ACE30-1/VC_FRONT_SRV# show conn serverfarm SF_PRIZPRIV_9082&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;conn-id &amp;nbsp; &amp;nbsp;np dir proto vlan source &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;destination &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; state&lt;BR /&gt;----------+--+---+-----+----+---------------------+---------------------+------+&lt;BR /&gt;2085856 &amp;nbsp; &amp;nbsp;3 &amp;nbsp;in &amp;nbsp;TCP &amp;nbsp; 21 &amp;nbsp; 172.17.1.17:46983 &amp;nbsp; &amp;nbsp; 172.17.10.55:9081 &amp;nbsp; &amp;nbsp; ESTAB&lt;BR /&gt;2040930 &amp;nbsp; &amp;nbsp;3 &amp;nbsp;out TCP &amp;nbsp; 5 &amp;nbsp; &amp;nbsp;172.17.10.18:9082 &amp;nbsp; &amp;nbsp; 172.17.1.17:1037 &amp;nbsp; &amp;nbsp; &amp;nbsp;ESTAB&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-size:14px;"&gt;ACE30-1/VC_FRONT_SRV# show conn ipv4 | include 172.17.1.17&lt;BR /&gt;2085856 &amp;nbsp; &amp;nbsp;3 &amp;nbsp;in &amp;nbsp;TCP &amp;nbsp; 21 &amp;nbsp; 172.17.1.17:46983 &amp;nbsp; &amp;nbsp; 172.17.10.55:9081 &amp;nbsp; &amp;nbsp; ESTAB&lt;BR /&gt;2040930 &amp;nbsp; &amp;nbsp;3 &amp;nbsp;out TCP &amp;nbsp; 5 &amp;nbsp; &amp;nbsp;172.17.10.18:9082 &amp;nbsp; &amp;nbsp; 172.17.1.17:1037 &amp;nbsp; &amp;nbsp; &amp;nbsp;ESTAB&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;serverfarm host SF_PRIZPRIV_9082&lt;BR /&gt;&amp;nbsp; predictor leastconns slowstart 500&lt;BR /&gt;&amp;nbsp; rserver 172.17.10.18 9082&lt;BR /&gt;&amp;nbsp; &amp;nbsp; cookie-string "priz01"&lt;BR /&gt;&amp;nbsp; &amp;nbsp; inservice&lt;BR /&gt;-----------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;When ACE send back answer the port not changed to 46983&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Cisco sent to us new FW Version A5(3.1a) but the problem not gone&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;PLZ reply me if you have any ideas&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;&lt;SPAN style="font-size:14px;"&gt;BR,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;&lt;SPAN style="font-size:14px;"&gt;Denis&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 20 Nov 2014 12:54:58 GMT</pubDate>
    <dc:creator>CSCO117775131</dc:creator>
    <dc:date>2014-11-20T12:54:58Z</dc:date>
    <item>
      <title>Cisco ACE incorrect translation src port</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-incorrect-translation-src-port/m-p/2604320#M42546</link>
      <description>&lt;P&gt;Dear Experts please HELP!&lt;BR /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have one VIP IP&amp;nbsp;172.17.10.55:9082 for&amp;nbsp;loadbalance&amp;nbsp;between rservers with different ports(172.17.10.18:9083,&amp;nbsp;172.17.10.19:9087,&amp;nbsp;172.17.10.20:9084...)&lt;/P&gt;

&lt;PRE class="code-java" style="padding: 0px; font-size: 12px; margin-bottom: 0px; line-height: 16px; word-wrap: normal; max-height: 30em; overflow: auto;"&gt;
class-map match-all VS_PP_9082
  2 match virtual-address 172.17.10.55 tcp eq 9082 &lt;/PRE&gt;

&lt;P&gt;serverfarm host SF_PRIZPRIV_9082&lt;BR /&gt;&amp;nbsp; predictor leastconns&lt;BR /&gt;&amp;nbsp; probe PR_PP_9082&lt;BR /&gt;&amp;nbsp; rserver &lt;SPAN style="font-size: 16.3636360168457px;"&gt;172.17.10.18&lt;/SPAN&gt; 9083&lt;BR /&gt;&amp;nbsp; &amp;nbsp; inservice&lt;BR /&gt;&amp;nbsp; rserver &lt;SPAN style="font-size: 16.3636360168457px;"&gt;172.17.10.19&lt;/SPAN&gt; 9087&lt;BR /&gt;&amp;nbsp; ....&lt;/P&gt;
&lt;P&gt;Problem: ACE incorrect&amp;nbsp;translate src port. The src port 47016,&amp;nbsp;but&amp;nbsp;ACE&amp;nbsp;replace to 1092(or it can be 1280,1092,1278)&lt;/P&gt;
&lt;P&gt;When port Vip and port rserver in serverfarm the same it works correct.&lt;/P&gt;

&lt;PRE class="code-java" style="margin-bottom: 0px; padding: 0px; max-height: 30em; overflow: auto; word-wrap: normal; font-size: 12px; line-height: 16px;"&gt;
conn-id    np dir proto vlan source                destination           state
----------+--+---+-----+----+---------------------+---------------------+------+
488907     2  in  TCP   21   172.17.1.17:47016     172.17.10.55:9082     ESTAB
205377     2  out TCP   5    172.17.10.18:9083     172.17.1.17:1092      ESTAB&lt;/PRE&gt;

&lt;P&gt;ACE Version A5(3.0)&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How to solve it ? PLS give your recommendations.&lt;/P&gt;
&lt;P&gt;BR,&lt;/P&gt;
&lt;P&gt;Denis&lt;/P&gt;</description>
      <pubDate>Fri, 14 Nov 2014 13:28:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-incorrect-translation-src-port/m-p/2604320#M42546</guid>
      <dc:creator>CSCO117775131</dc:creator>
      <dc:date>2014-11-14T13:28:35Z</dc:date>
    </item>
    <item>
      <title>Hi Denis,You have class map</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-incorrect-translation-src-port/m-p/2604321#M42547</link>
      <description>&lt;P&gt;Hi Denis,&lt;/P&gt;&lt;P&gt;You have class map matching on port 9082 and you have serverfarm listening on 9083. So ACE, changes the destination port to 9083 before forwarding it to the server but remember it will also change the source port and that is FAD. Are you facing any issues with that?&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the reply from server i.e 172.17.10.18 from src port 9083 will hit the ACE, ACE will change the dst port from 1092 back to 47016 and fwd the request back &amp;nbsp;to client. Shouldn't be a problem.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Nov 2014 22:46:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-incorrect-translation-src-port/m-p/2604321#M42547</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-11-14T22:46:41Z</dc:date>
    </item>
    <item>
      <title>Thank you KanwalIn this</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-incorrect-translation-src-port/m-p/2604322#M42548</link>
      <description>&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-size:14px;"&gt;Thank you Kanwal&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;In this situation, class map matching on port 9081 and serverfarm listening on 9082.&lt;BR /&gt;----------------------------------------------------------------------------------&lt;BR /&gt;ACE30-1/VC_FRONT_SRV# show conn serverfarm SF_PRIZPRIV_9082&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;conn-id &amp;nbsp; &amp;nbsp;np dir proto vlan source &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;destination &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; state&lt;BR /&gt;----------+--+---+-----+----+---------------------+---------------------+------+&lt;BR /&gt;2085856 &amp;nbsp; &amp;nbsp;3 &amp;nbsp;in &amp;nbsp;TCP &amp;nbsp; 21 &amp;nbsp; 172.17.1.17:46983 &amp;nbsp; &amp;nbsp; 172.17.10.55:9081 &amp;nbsp; &amp;nbsp; ESTAB&lt;BR /&gt;2040930 &amp;nbsp; &amp;nbsp;3 &amp;nbsp;out TCP &amp;nbsp; 5 &amp;nbsp; &amp;nbsp;172.17.10.18:9082 &amp;nbsp; &amp;nbsp; 172.17.1.17:1037 &amp;nbsp; &amp;nbsp; &amp;nbsp;ESTAB&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN style="font-size:14px;"&gt;ACE30-1/VC_FRONT_SRV# show conn ipv4 | include 172.17.1.17&lt;BR /&gt;2085856 &amp;nbsp; &amp;nbsp;3 &amp;nbsp;in &amp;nbsp;TCP &amp;nbsp; 21 &amp;nbsp; 172.17.1.17:46983 &amp;nbsp; &amp;nbsp; 172.17.10.55:9081 &amp;nbsp; &amp;nbsp; ESTAB&lt;BR /&gt;2040930 &amp;nbsp; &amp;nbsp;3 &amp;nbsp;out TCP &amp;nbsp; 5 &amp;nbsp; &amp;nbsp;172.17.10.18:9082 &amp;nbsp; &amp;nbsp; 172.17.1.17:1037 &amp;nbsp; &amp;nbsp; &amp;nbsp;ESTAB&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;serverfarm host SF_PRIZPRIV_9082&lt;BR /&gt;&amp;nbsp; predictor leastconns slowstart 500&lt;BR /&gt;&amp;nbsp; rserver 172.17.10.18 9082&lt;BR /&gt;&amp;nbsp; &amp;nbsp; cookie-string "priz01"&lt;BR /&gt;&amp;nbsp; &amp;nbsp; inservice&lt;BR /&gt;-----------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;When ACE send back answer the port not changed to 46983&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Cisco sent to us new FW Version A5(3.1a) but the problem not gone&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;PLZ reply me if you have any ideas&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;&lt;SPAN style="font-size:14px;"&gt;BR,&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;&lt;SPAN style="font-size:14px;"&gt;Denis&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2014 12:54:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-incorrect-translation-src-port/m-p/2604322#M42548</guid>
      <dc:creator>CSCO117775131</dc:creator>
      <dc:date>2014-11-20T12:54:58Z</dc:date>
    </item>
    <item>
      <title>Hi Denis,Do you actually see</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-incorrect-translation-src-port/m-p/2604323#M42549</link>
      <description>&lt;P&gt;Hi Denis,&lt;/P&gt;&lt;P&gt;Do you actually see that port was not changed in pcaps or on the basis of "show conn" output you are saying that?&amp;nbsp;&lt;/P&gt;&lt;P&gt;So IN and OUT actually correspond to ICM(Inbound connection manager) and OCM(outbound connection manager).&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;2085856 &amp;nbsp; &amp;nbsp;3 &amp;nbsp;in &amp;nbsp;TCP &amp;nbsp; 21 &amp;nbsp; 172.17.1.17:46983 &amp;nbsp; &amp;nbsp; 172.17.10.55:9081 &amp;nbsp; &amp;nbsp; ESTAB&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;Above represents the incoming leg of the connection where client comes on VIP.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;2040930 &amp;nbsp; &amp;nbsp;3 &amp;nbsp;out TCP &amp;nbsp; 5 &amp;nbsp; &amp;nbsp;172.17.10.18:9082 &amp;nbsp; &amp;nbsp; 172.17.1.17:1037 &amp;nbsp; &amp;nbsp; &amp;nbsp;ESTAB&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;Above represents the leg of the connection where ACE forwarded the connection to server i.e&amp;nbsp;172.17.10.18. But in representation it is reversed. So when ACE forwarded the connection server .18, it changed the source port to 1037. This is what it represents.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;If you have packet capture on client side indicating that the ACE didn't rewrite &amp;nbsp;the source port before forwarding the packet to client, then that would be a bug. I doubt that is the case but then pcaps are our best friend to confirm that.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;Kanwal&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 14.3999996185303px;"&gt;Note: Please mark answers if they are helpful.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 20 Nov 2014 14:42:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-incorrect-translation-src-port/m-p/2604323#M42549</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-11-20T14:42:09Z</dc:date>
    </item>
    <item>
      <title>Hello Kanwal I check again,</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-incorrect-translation-src-port/m-p/2604324#M42550</link>
      <description>&lt;P&gt;Hello Kanwal&amp;nbsp;&lt;/P&gt;&lt;P&gt;I check again, the port translation work is correct, you are right.&lt;/P&gt;&lt;P&gt;In our configuration we use &amp;nbsp;S NAT, so the reply comes back through the ACE.&lt;/P&gt;&lt;P&gt;The scheme is Front---&amp;gt;LB---&amp;gt;APP,&amp;nbsp;but with different &amp;nbsp;ports APP it not work.&lt;/P&gt;&lt;P&gt;Q. ACE can work with different ports (Vip port not the same like in service-farm) ?&lt;/P&gt;&lt;P&gt;class-map match-all CM_LB_APP&lt;BR /&gt;&amp;nbsp; 2 match virtual-address 172.17.10.55 tcp eq 9081&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;serverfarm host SF_APP_EPZ&lt;BR /&gt;&amp;nbsp; predictor leastconns&lt;BR /&gt;&amp;nbsp; rserver APP 9082&lt;/P&gt;&lt;P&gt;I attach my configuration, if YOU have a time PLZ look on it.&lt;/P&gt;&lt;P&gt;BR&lt;/P&gt;&lt;P&gt;Denis&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 29 Nov 2014 19:18:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-incorrect-translation-src-port/m-p/2604324#M42550</guid>
      <dc:creator>CSCO117775131</dc:creator>
      <dc:date>2014-11-29T19:18:06Z</dc:date>
    </item>
    <item>
      <title>Hi Denis,I haven't checked</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-incorrect-translation-src-port/m-p/2604325#M42551</link>
      <description>&lt;P&gt;Hi Denis,&lt;/P&gt;&lt;P&gt;I haven't checked the configuration but what you have demonstrated above should work just fine. Any request that comes on 9081 would be forwarded to 9082 since you have mentioned 9082 port in front of real server in the farm.&lt;/P&gt;&lt;P&gt;Is this not working?&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Kanwal&lt;/P&gt;&lt;P&gt;Note: Please mark answers if they are helpful.&lt;/P&gt;</description>
      <pubDate>Sat, 29 Nov 2014 19:18:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-incorrect-translation-src-port/m-p/2604325#M42551</guid>
      <dc:creator>Kanwaljeet Singh</dc:creator>
      <dc:date>2014-11-29T19:18:07Z</dc:date>
    </item>
    <item>
      <title>Thank you, KanwalI used</title>
      <link>https://community.cisco.com/t5/application-networking/cisco-ace-incorrect-translation-src-port/m-p/2604326#M42552</link>
      <description>&lt;P&gt;Thank you,&amp;nbsp;Kanwal&lt;/P&gt;&lt;P&gt;I used capture packets directly on ACE, so it helped me.&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;BR&lt;/P&gt;&lt;P style="font-size: 14.5454540252686px;"&gt;Denis&lt;/P&gt;</description>
      <pubDate>Tue, 09 Dec 2014 09:57:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/cisco-ace-incorrect-translation-src-port/m-p/2604326#M42552</guid>
      <dc:creator>CSCO117775131</dc:creator>
      <dc:date>2014-12-09T09:57:30Z</dc:date>
    </item>
  </channel>
</rss>

