cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
355
Views
0
Helpful
1
Replies

6500 CSM with SSL, gw on real servers.

marcin.mazurek
Level 1
Level 1

I've got a CSM with SSL module. Is it necessary on real serversto point the gateway on CSM VIP or can I pass by the 6500 with CSM and SSL and point the gatway to the router in the network before 6500?

It's not clear to me from docs if the connections going through the SSL must be going back through CSM.

any hints?

tia

1 Accepted Solution

Accepted Solutions

Gilles Dufour
Cisco Employee
Cisco Employee

The CSM must see both side of a connection or it will close the connection with a RESET.

So, yes, the traffic from the real server must go back to the CSM.

There is a way to avoid this called 'Direct Server Return' but I would not recommend it unless you are an expert with CSM.

Gilles.

View solution in original post

1 Reply 1

Gilles Dufour
Cisco Employee
Cisco Employee

The CSM must see both side of a connection or it will close the connection with a RESET.

So, yes, the traffic from the real server must go back to the CSM.

There is a way to avoid this called 'Direct Server Return' but I would not recommend it unless you are an expert with CSM.

Gilles.

Review Cisco Networking for a $25 gift card