<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: backend-servies and SSL modules in Application Networking</title>
    <link>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411956#M7380</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;well I suppose your CSS is behind a firewall or is using ACLs for security reasons. I'd suggest to monitor the VIP of your back-end services via a NAT-Statement only permitting the GSS to monitor this IP.&lt;/P&gt;&lt;P&gt;This allows you to guess if the backend service is available or not. This allows the GSS to decide if the site with no alive backend service is address or not.&lt;/P&gt;&lt;P&gt;I guess this is a viable approache.&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt; Joerg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 09 Aug 2005 06:14:59 GMT</pubDate>
    <dc:creator>jfoerster</dc:creator>
    <dc:date>2005-08-09T06:14:59Z</dc:date>
    <item>
      <title>backend-servies and SSL modules</title>
      <link>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411951#M7375</link>
      <description>&lt;P&gt;In our network, the GSS replies to the url queries with an A-record. It returns IP addresses hosted by active/backup CSS boxes located at 2 different sites. GSS monitors the health of the sites/CSS using KAL-AP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The CSS are configured in a 'Routing' topology I mean &amp;#145;full-proxy&amp;#146; configuration as we employ different ip subnets in the client/server side networks. CSS maintains a client encryption in the front and a server encryption in the back-end. We use couple of SSL modules for this purpose.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now my problem is, the SSL modules accepts connections even when all the back-end services of a Content Rule are down. GSS shows on-line for that site. Both CSS and GSS behaves fine with the clear front and clear back config.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Version: 07.30.3.13s&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea? Is that an expected behaviour?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Jun 2005 00:39:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411951#M7375</guid>
      <dc:creator>skumar1969</dc:creator>
      <dc:date>2005-06-01T00:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: backend-servies and SSL modules</title>
      <link>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411952#M7376</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;this is becaus you have a L5 rule for SSL.&lt;/P&gt;&lt;P&gt;You probably configured advanced-balance ssl to do stickyness based on SSLID.&lt;/P&gt;&lt;P&gt;A CSS will always spoof connection for L5 rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should use a different type of keepalive on the GSS.  You should use KAL-AP.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2005 09:35:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411952#M7376</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2005-06-01T09:35:49Z</dc:date>
    </item>
    <item>
      <title>Re: backend-servies and SSL modules</title>
      <link>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411953#M7377</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is the CR below. I only use KAL-AP on the GSS to  keep-alive on the CSS.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;  content ssl-front &lt;/P&gt;&lt;P&gt;    vip address xx.xx.xx.xx &lt;/P&gt;&lt;P&gt;    application ssl &lt;/P&gt;&lt;P&gt;    add service ssl-module-1 &lt;/P&gt;&lt;P&gt;    add service ssl-module-2 &lt;/P&gt;&lt;P&gt;    protocol tcp &lt;/P&gt;&lt;P&gt;    port 443 &lt;/P&gt;&lt;P&gt;    advanced-balance ssl &lt;/P&gt;&lt;P&gt;    active &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 01 Jun 2005 22:44:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411953#M7377</guid>
      <dc:creator>skumar1969</dc:creator>
      <dc:date>2005-06-01T22:44:30Z</dc:date>
    </item>
    <item>
      <title>Re: backend-servies and SSL modules</title>
      <link>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411954#M7378</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ok, but this content rule will never go down since the ssl module service is using 'keepalive type none'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You should use kal-ap by vip and assign a name to the backend content rule and monitor this *name*&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Gilles.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jun 2005 07:22:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411954#M7378</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2005-06-02T07:22:07Z</dc:date>
    </item>
    <item>
      <title>Re: backend-servies and SSL modules</title>
      <link>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411955#M7379</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Pretty good idea Gilles!....but it wouldn't work for me as the VIP of my backend CR is in a non-routable ip range.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For security reasons, I would think communicating to that IP addrs from anywhere in the client/browser segment wouldn't be a good option.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anyother way?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Jun 2005 09:00:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411955#M7379</guid>
      <dc:creator>skumar1969</dc:creator>
      <dc:date>2005-06-02T09:00:09Z</dc:date>
    </item>
    <item>
      <title>Re: backend-servies and SSL modules</title>
      <link>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411956#M7380</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;well I suppose your CSS is behind a firewall or is using ACLs for security reasons. I'd suggest to monitor the VIP of your back-end services via a NAT-Statement only permitting the GSS to monitor this IP.&lt;/P&gt;&lt;P&gt;This allows you to guess if the backend service is available or not. This allows the GSS to decide if the site with no alive backend service is address or not.&lt;/P&gt;&lt;P&gt;I guess this is a viable approache.&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt; Joerg&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Aug 2005 06:14:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411956#M7380</guid>
      <dc:creator>jfoerster</dc:creator>
      <dc:date>2005-08-09T06:14:59Z</dc:date>
    </item>
    <item>
      <title>Re: backend-servies and SSL modules</title>
      <link>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411957#M7381</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes the CSS is behind the firewall. The server segment is a non-routable private ip one as you are aware. Yes I understand I should have the NAT-ing but was wondering where? On the CSS, how do I do that?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 09 Aug 2005 21:48:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411957#M7381</guid>
      <dc:creator>skumar1969</dc:creator>
      <dc:date>2005-08-09T21:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: backend-servies and SSL modules</title>
      <link>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411958#M7382</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;the nating should be done on the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;G.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 10 Aug 2005 05:20:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/application-networking/backend-servies-and-ssl-modules/m-p/411958#M7382</guid>
      <dc:creator>Gilles Dufour</dc:creator>
      <dc:date>2005-08-10T05:20:08Z</dc:date>
    </item>
  </channel>
</rss>

