07-21-2004 06:22 AM
Hi :
I have problems with a couple of FTP servers balanced with a CSS11555.
As we know, we have to define a GROUP for these two services in order to the data connection works.
I´m using the same services in the group that I configure on the content rule.
The problem is that this group affects all outbound traffic from this servers (i.e. FTP or DNS traffic to an outside server).
Does anyone knows how "SOURCEGROUP" keyword works on an ACL or how can i solve this problem ?
Regards
Martín
07-21-2004 07:10 AM
Martin,
You need to configure the source group with VIP address only [without any service] and use the ACL with source group to NAT the source depending on your prefrence.
ACL example
clause number permit protocol [source_info {source_port}]
dest [dest_info {dest_port}] {sourcegroup name_of_group}
Here is the link which will help to config ACL.
http://www.cisco.com/univercd/cc/td/doc/product/webscale/css/css_720/bsccfggd/sgacleql.htm#1047423
Note:-Be careful while configuring the ACL on CSS.Bydefault there is explicit deny all as soon as you enable the ACL on CSS.
07-21-2004 08:32 AM
Thanks Tanveer.
I will try it ...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide