cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
999
Views
0
Helpful
3
Replies

ACE One Arm Setup

ramarao
Level 1
Level 1

Hi,

I would like to know whether CIsco ACE MODULE can be configured in such :

CLIENTS : 10.10.10.X

ACE VIP : 10.20.20.20

SERVER 1 ACTUAL IP : 10.20.20.21

SERVER 2 ACTUAL IP : 10.20.20.22

Both the VIP and Server are in one segment. This segment also are behind FWSM and in the same chassis.

Thanks in advance.

Rama

1 Accepted Solution

Accepted Solutions

Hi Rama,

I'm afraid I cannot answer any of the two questions without first seeing a diagram of the exact topology you are planning to implement.

For the configuration example, I would recommend you to have a look at http://docwiki.cisco.com/wiki/Basic_Load_Balancing_Using_One_Arm_Mode_with_Source_NAT_on_the_Cisco_Application_Control_Engine_Configuration_Example

Regards

Daniel

View solution in original post

3 Replies 3

Daniel Arrondo Ostiz
Cisco Employee
Cisco Employee

Hi Rama,

Yes, it would be fine to use this kind of setup. You just need to take into account a few points points:

  • The policy-map has to be applied on the vlan on which the client traffic is arriving
  • Traffic towards the VIPs needs to be routed towards the ACE
  • You need to ensure that the return traffic from the servers towards the clients also goes through the ACE, so, you probably will need to configure either some source-nat or policy-based-routing to achieve this.

Let me know if you need more clarification on any of the points.

Regards

Daniel

Hi Daniel,

The traffic towards the ACE, can it be achieved if the ace context is parked behind the FWSM, and the context itself points the gateway to FWSM.

And for Source NAT, can I also use back the same segment VIP and server segment?

Appreciate if you could give me a sample config on this.

Many thanks

Rama

Hi Rama,

I'm afraid I cannot answer any of the two questions without first seeing a diagram of the exact topology you are planning to implement.

For the configuration example, I would recommend you to have a look at http://docwiki.cisco.com/wiki/Basic_Load_Balancing_Using_One_Arm_Mode_with_Source_NAT_on_the_Cisco_Application_Control_Engine_Configuration_Example

Regards

Daniel

Review Cisco Networking for a $25 gift card