cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
591
Views
0
Helpful
8
Replies

Error message on connections with CSM Natpool?

jcmattos1
Level 1
Level 1

We have a CSM 4.1.6 with a set of reals which is trying to access the vip from the same subnet behind the csm and connections keep receiving this error upon SYN only thru the natpool. Any ideas?

8 Replies 8

Gilles Dufour
Cisco Employee
Cisco Employee

this is a weird one.

Could you get us the config, csm arp table, show mod csm x vserver name det.

Also, if you control one source, enable the following debug :

'debug mod ContentSwitchingModule x packet x.x.x.x/32'

Get a show tech before and after the test as well as the 'show mod csm x vser ...' cmd above.

Thanks,

Gilles.

Here is the info you requested it is all in one file. One thing I did notice is that in the client capture (dev10ux) i notice an immediate RST by the VIP 172.23.3.227 with mac of 4b:e6 and another SYN/ACK response from the same VIP but different mac 1a:02. Is this normal?

I also noticed the difference in source mac address. This is really a weird issue.

Is it happening for other client ip ?

Could you get a 'sho mod csm x arp | i 172.23.'

Also, could you try to enable the debugging mentioned before.

Thanks,

Gilles.

Giles, I really appreciate your help...I was able to get the arp info you requested im hitting the vip but im not receving any debug packets? I enabled logging on, term mon, is there something else im missing?

I'm sorry I can't solve the issue immediately, but this looks like a new issue and therefore we have to go step by step.

I'm being assisted by another developpers and we're trying to identify where is the problem.

Could you collect the following command from the csm venus prompt [you have to session to csm slot and then enter the command 'venus' or be on the csm console].

find_nat_encaps

Thanks,

Gilles.

I tried those commands and it doesn't seem to allow me to session to the module...I can do it to the standby csm but not the active. Any ideas as to why?

from the csm not giving you the prompt, could you try to enter the following commands [even if you do not get prompt]

venus

tracelog_off

If you get the prompt after that, then capture the command that we need.

If you still do not get the prompt, unfortunately there is not much we'll be able to do on this csm, so I would suggest to failover to the backup and then reload this csm.

Gilles.

valerie_devera
Level 1
Level 1

hi Gillies,

I heard of the new ACE (application control engine) and interested to know which Cisco course tackles this module

Review Cisco Networking for a $25 gift card