<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Advanced-balance ssl problem in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/advanced-balance-ssl-problem/m-p/303236#M4729</link>
    <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a problem dealing using advanced-balance ssl with a CSS11501 and 2 apache servers. &lt;/P&gt;&lt;P&gt;When we use the "balance srcip" or "balance aca" alone, it works fine. But we would like to use "advanced-balanced ssl" method, as we have to deal with HTTPS flow...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is part of my running config : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;circuit VLAN202&lt;/P&gt;&lt;P&gt;   ip address XX.2.2.4 255.255.255.0 &lt;/P&gt;&lt;P&gt;    no redirects &lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;circuit VLAN301&lt;/P&gt;&lt;P&gt;   ip address XX.3.1.2 255.255.255.0 &lt;/P&gt;&lt;P&gt;    no redirects &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service ssl_service1 &lt;/P&gt;&lt;P&gt;  port 443 &lt;/P&gt;&lt;P&gt;  protocol tcp &lt;/P&gt;&lt;P&gt;  keepalive type ssl &lt;/P&gt;&lt;P&gt;  ip address XX.2.2.11 &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;service ssl_service2 &lt;/P&gt;&lt;P&gt;  port 443 &lt;/P&gt;&lt;P&gt;  protocol tcp &lt;/P&gt;&lt;P&gt;  keepalive type ssl &lt;/P&gt;&lt;P&gt;  ip address XX.2.2.13 &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;content SSL_load_balancing &lt;/P&gt;&lt;P&gt;    protocol tcp &lt;/P&gt;&lt;P&gt;    port 443 &lt;/P&gt;&lt;P&gt;    application ssl &lt;/P&gt;&lt;P&gt;    balance aca &lt;/P&gt;&lt;P&gt;    advanced-balance ssl &lt;/P&gt;&lt;P&gt;    add service ssl_service1&lt;/P&gt;&lt;P&gt;    add service ssl_service2&lt;/P&gt;&lt;P&gt;    vip address XX.3.1.50&lt;/P&gt;&lt;P&gt;    active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've a doubt about the SSL handshake because i can see from our FW that a the Web Server tries to answer directly to the client, while it gateway is the CSS....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help or idea about my config will be appreciated...and plz excuse my bad english..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 27 Apr 2004 11:23:34 GMT</pubDate>
    <dc:creator>admin_2</dc:creator>
    <dc:date>2004-04-27T11:23:34Z</dc:date>
    <item>
      <title>Advanced-balance ssl problem</title>
      <link>https://community.cisco.com/t5/application-networking/advanced-balance-ssl-problem/m-p/303236#M4729</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have a problem dealing using advanced-balance ssl with a CSS11501 and 2 apache servers. &lt;/P&gt;&lt;P&gt;When we use the "balance srcip" or "balance aca" alone, it works fine. But we would like to use "advanced-balanced ssl" method, as we have to deal with HTTPS flow...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is part of my running config : &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;circuit VLAN202&lt;/P&gt;&lt;P&gt;   ip address XX.2.2.4 255.255.255.0 &lt;/P&gt;&lt;P&gt;    no redirects &lt;/P&gt;&lt;P&gt;  &lt;/P&gt;&lt;P&gt;circuit VLAN301&lt;/P&gt;&lt;P&gt;   ip address XX.3.1.2 255.255.255.0 &lt;/P&gt;&lt;P&gt;    no redirects &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;service ssl_service1 &lt;/P&gt;&lt;P&gt;  port 443 &lt;/P&gt;&lt;P&gt;  protocol tcp &lt;/P&gt;&lt;P&gt;  keepalive type ssl &lt;/P&gt;&lt;P&gt;  ip address XX.2.2.11 &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;service ssl_service2 &lt;/P&gt;&lt;P&gt;  port 443 &lt;/P&gt;&lt;P&gt;  protocol tcp &lt;/P&gt;&lt;P&gt;  keepalive type ssl &lt;/P&gt;&lt;P&gt;  ip address XX.2.2.13 &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;content SSL_load_balancing &lt;/P&gt;&lt;P&gt;    protocol tcp &lt;/P&gt;&lt;P&gt;    port 443 &lt;/P&gt;&lt;P&gt;    application ssl &lt;/P&gt;&lt;P&gt;    balance aca &lt;/P&gt;&lt;P&gt;    advanced-balance ssl &lt;/P&gt;&lt;P&gt;    add service ssl_service1&lt;/P&gt;&lt;P&gt;    add service ssl_service2&lt;/P&gt;&lt;P&gt;    vip address XX.3.1.50&lt;/P&gt;&lt;P&gt;    active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've a doubt about the SSL handshake because i can see from our FW that a the Web Server tries to answer directly to the client, while it gateway is the CSS....&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help or idea about my config will be appreciated...and plz excuse my bad english..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2004 11:23:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/advanced-balance-ssl-problem/m-p/303236#M4729</guid>
      <dc:creator>admin_2</dc:creator>
      <dc:date>2004-04-27T11:23:34Z</dc:date>
    </item>
    <item>
      <title>Re: Advanced-balance ssl problem</title>
      <link>https://community.cisco.com/t5/application-networking/advanced-balance-ssl-problem/m-p/303237#M4730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We have Advanced-Balance SSL but have included a line:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;url "/*"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;in the content rule. I think this forces the protocol up to layer 5 where the SSL ID can be found.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Good luck&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Andrew&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Apr 2004 12:18:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/advanced-balance-ssl-problem/m-p/303237#M4730</guid>
      <dc:creator>andrew.thomson</dc:creator>
      <dc:date>2004-04-27T12:18:48Z</dc:date>
    </item>
    <item>
      <title>Re: Advanced-balance ssl problem</title>
      <link>https://community.cisco.com/t5/application-networking/advanced-balance-ssl-problem/m-p/303238#M4731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;could you please provide some information about the problem itself.&lt;/P&gt;&lt;P&gt;Is it every connections or just a few of them ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you see the server bypassing the CSS, that would be a concern.&lt;/P&gt;&lt;P&gt;Can you sniff the server side and see the mac address of the SYN/ACK.&lt;/P&gt;&lt;P&gt;Also check where it breaks exactly in the TCP connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The url command is not required.&lt;/P&gt;&lt;P&gt;The command application ssl will make the CSS look for the session id.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Apr 2004 12:26:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/advanced-balance-ssl-problem/m-p/303238#M4731</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2004-04-27T12:26:43Z</dc:date>
    </item>
    <item>
      <title>Re: Advanced-balance ssl problem</title>
      <link>https://community.cisco.com/t5/application-networking/advanced-balance-ssl-problem/m-p/303239#M4732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your help...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me explain my case better.&lt;/P&gt;&lt;P&gt;All connections are "refused" when i use advanced-balance ssl. But if i put it away (i.e. using only balance srcip or else), it works fine (hopefully!)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;From my FW monitor, i can see the syn/ack flow : &lt;/P&gt;&lt;P&gt;SYN / From:myPC / Destination : XX.3.1.50 / Service :https/443&lt;/P&gt;&lt;P&gt;ACK / From:XX.2.2.13 / Destination : myPC / Service:4435 / Reason : no connection found for TCP packet&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Perhaps that is the problem : it should be the CSS that sends the ACK to the client ...? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anther point : from llama, i can see an increasing number of WCC_REJECTED from the Apache_side_vlan...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will try to see where the TCP connection stops but i'm not used to working with sniffer...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope these informations can help ! Any idea ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Apr 2004 13:34:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/advanced-balance-ssl-problem/m-p/303239#M4732</guid>
      <dc:creator />
      <dc:date>2004-04-27T13:34:30Z</dc:date>
    </item>
  </channel>
</rss>

