02-27-2006 07:33 AM
Connectivity hang when inserting an arrowpoint cookie in the decrypted traffic flow (using SCA). We use one arm architecture with CSS 11150. From the trace it looks like the CSS cannot insert the cookie and reset the connection after a while.
02-27-2006 11:52 PM
we will need css config and sniffer traces to understand the problem.
You can attach them here or send them to gdufour@cisco.com
02-28-2006 03:12 AM
02-28-2006 03:54 AM
your SCA config does not match the CSS.
The CSS forwards the secure traffic to ip:port = 141.122.131.9:444.
Your SCA listens on port 446 [not 444] and it is supposed to forward the decrypted traffic to 141.122.180.254:90 which is not a CSS vip.
Gilles.
02-28-2006 06:17 AM
02-28-2006 08:31 AM
configs look good.
what about the trace ?
Did capture it between CSS and SCA ?
When do you see the reset ? Immediately ? After always the same amount of time ? Randomly ?
do you see the cookie inserted by the CSS in the server response ?
Thanks,
Gilles.
03-01-2006 05:37 AM
03-01-2006 06:00 AM
Find out the issue. As the destination server are not on directely attached interface the packets went out by a different interface than the return traffic. Seems that a flow include physical interface.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide