cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
580
Views
0
Helpful
6
Replies

Not bieng able to see Http or HTTPS traffic

AndyGB5150
Level 1
Level 1

Morning or Evening.

I hope you can help me.

At the moment I can ping from a cisco ace 4710 two Web Servers and the rest of the infrastructure as shown below

Connectivity.bmp

At present the sticky sessions and ssl isn't really too much of a concern but I would like to see HTTP or HTTPS traffic running though the ACE 4710.

Ping from the Ace is successfull as it can ping AD servers, Database Servers, etc..

Show conn only shows that the HA links are connected but nothing else.

Show arp shows that ever thing is up from the Real Server,VIP addresses, H/A IP's and also a couple of vlans on a core switch.

I think the problem maybe due to the class-map and possibly a policy map that's not applied to the Virtual IP's

Thanks again

6 Replies 6

AndyGB5150
Level 1
Level 1

The attatched is a current VIP status.

Thanks again

I would guess about a direct-server-return, but without your configuration it will be all just guessing.

Thanks for the reply.

Config attatched

At first you should put your access-list on all your interfaces. The ACE is acting like a firewall. Then you should enable logging. The ACE is very good in telling you why something blocked or not.

Thanks for the reply.

I take it adding an access-list would be the same as a normal switch ???

Daft question but I had to ask

on VLAN 200 you have the command

access-group input ALL

you should add this to VLAN 210 and 220 too. By default ACE is blocking all incoming traffic.