03-18-2005 01:53 PM
Could someone shead light on the use of STICKY in reference to a virtual server.
My config:
sticky 20 netmask 255.255.255.255 timeout 300
!
policy FTP
client-group CSMnets
serverfarm FTPOUT
!
vserver FTPOUT
virtual 0.0.0.0 0.0.0.0 tcp ftp service ftp
vlan 160
sticky 300 group 20
reverse-sticky 20
replicate csrp sticky
replicate csrp connection
persistent rebalance
slb-policy FTP
inservice
When I show csm 3 sticky, I do not receive any information.
Did I configure it wrong?
Thanks
Frank
03-19-2005 05:19 AM
Frank,
you are using an slb-policy and no default serverfarm.
Therefore you need to configure the sticky group inside the policy configuration.
Also, do not configure reverse-sticky and sticky at the same time under the same vserver.
Regards,
Gilles.
03-23-2005 07:18 AM
Sorry, I missed entering the policy details.
I have configured "STICKY" on BOTH the policy and Virtual Server. The Cisco docs are VERY VAGUE.
This is what the Cisco documentations says:
"(OPTIONAL) Configures connections from the client to use the same real server. The default is sticky off"
Could you explain this in plain english, say for the dumb folks like me? 8)... PLEASE dont feel like you are giving me too much information - I have VERY thick skin.
Did I configure it correctly, is it configured just wrong or what? My experience is that you can configure MANY things wrong and traffic still flows.
My Topology:
.INTERNET
.| |
R-----R
| |
CSM---CSM
| |
FW FW
| |
CSM---CSM
| |
R-----R
INTERNAL NET
My config:
!
policy FTP
client-group NIHnets
serverfarm FTPOUT backup BACKUP-FTPOUT sticky
!
serverfarm FTPOUT
no nat server
no nat client
predictor hash address source
failaction purge
real name B12-GEFW1-DMZ
health probe FWOS-[R]-CLIENT
inservice
real name FW-GEFW1-DMZ
inservice
probe OUT-SRV-ALIAS
!
vserver FTPOUT
virtual 0.0.0.0 0.0.0.0 tcp ftp service ftp
vlan 160
sticky 300 group 20
reverse-sticky 20
replicate csrp sticky
replicate csrp connection
persistent rebalance
slb-policy FTP
inservice
!
sticky 20 netmask 255.255.255.255 timeout 300
Thanks for helping!
Frank
PS URLs that explain this stuff in detail would be GREAT too!
03-23-2005 07:34 AM
try not to use the policy.
This is not required in your case.
Do not configure sticky and reverse-sticky under the same vserver.
I wrote a document describing how to use reverse-sticky for firewall loadbalancing.
You can find it at :
Regards,
Gilles.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide