<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic CSS+SSL Failover in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/css-ssl-failover/m-p/400235#M7018</link>
    <description>&lt;P&gt;If I have two CSS with SSL module in an ASR config, in case the master CSS fails, will the redundant CSS chassis take over the SSL sessions as well, without the client having to reconnect?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Christos&lt;/P&gt;</description>
    <pubDate>Tue, 05 Apr 2005 21:21:57 GMT</pubDate>
    <dc:creator>conoufri</dc:creator>
    <dc:date>2005-04-05T21:21:57Z</dc:date>
    <item>
      <title>CSS+SSL Failover</title>
      <link>https://community.cisco.com/t5/application-networking/css-ssl-failover/m-p/400235#M7018</link>
      <description>&lt;P&gt;If I have two CSS with SSL module in an ASR config, in case the master CSS fails, will the redundant CSS chassis take over the SSL sessions as well, without the client having to reconnect?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx,&lt;/P&gt;&lt;P&gt;Christos&lt;/P&gt;</description>
      <pubDate>Tue, 05 Apr 2005 21:21:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-ssl-failover/m-p/400235#M7018</guid>
      <dc:creator>conoufri</dc:creator>
      <dc:date>2005-04-05T21:21:57Z</dc:date>
    </item>
    <item>
      <title>Re: CSS+SSL Failover</title>
      <link>https://community.cisco.com/t5/application-networking/css-ssl-failover/m-p/400236#M7019</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;no.  We are currently working on such a solution but this is not possible as of now.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Apr 2005 06:36:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-ssl-failover/m-p/400236#M7019</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2005-04-06T06:36:00Z</dc:date>
    </item>
    <item>
      <title>Re: CSS+SSL Failover</title>
      <link>https://community.cisco.com/t5/application-networking/css-ssl-failover/m-p/400237#M7020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Gilles hi,&lt;/P&gt;&lt;P&gt;Thx for your reply.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I couldn't find on the web was info on SSL fail-over and how the SSL will behave in the event that the Master CSS fails and the Stand-by takes over.  What will happen to the SSL sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also, how does the CSS behave in the event that it looses one of the back-end web-servers?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you want you can contact me direct at:&lt;/P&gt;&lt;P&gt;&lt;A href="mailto:conoufriou@odysseyconsultants.com"&gt;conoufriou@odysseyconsultants.com&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Christos&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Apr 2005 08:41:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-ssl-failover/m-p/400237#M7020</guid>
      <dc:creator>conoufri</dc:creator>
      <dc:date>2005-04-06T08:41:18Z</dc:date>
    </item>
    <item>
      <title>Re: CSS+SSL Failover</title>
      <link>https://community.cisco.com/t5/application-networking/css-ssl-failover/m-p/400238#M7021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;we can save TCP connections but not the ssl info.&lt;/P&gt;&lt;P&gt;So after failover, the traffic will be sent to the new active SSL module which will send a RESET to the client.&lt;/P&gt;&lt;P&gt;The client will normally restart the connection.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you lose the backend server, the CSS does nothing.&lt;/P&gt;&lt;P&gt;If the client is sending traffic, the SSL module will forward it to the dead server and if we don't get a response during the timeout period the SSL module will reset the connection.&lt;/P&gt;&lt;P&gt;If a new connection is open it will be sent to another active server if one is available.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 06 Apr 2005 09:45:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/css-ssl-failover/m-p/400238#M7021</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2005-04-06T09:45:46Z</dc:date>
    </item>
  </channel>
</rss>

