ā02-21-2011 07:18 PM
We're running ACE SM in bridge mode and also have a L2 fw in front of it. We can ping the VIP OK from the outside, but not from the back-end servers. The back-end servers are on a different vlan from the VIP, but on the same subnet. The servers are pointing to the switch for the default gateway. Would it even be possible to ping the VIP since both, the fw and the ACE are running in bridge mode?
Thanks..
Solved! Go to Solution.
ā02-22-2011 06:14 AM
Try to configure the service-policy on your server-interface too. Or configure it globally, than you should be able to ping from both sides.
ā02-22-2011 01:10 AM
Where is your service-policy for the VIPs configured?
ā02-22-2011 04:55 AM
From:
For security reasons, the ACE does not allow pings from an interface on a VLAN on one side of the ACE through the module to an interface on a different VLAN on the other side of the module. For example, a host can ping the ACE address that is on the IP subnet using the same VLAN as the host, but cannot ping IP addresses configured on other VLANs on the ACE.
ā02-22-2011 06:11 AM
As I understood his question right, he dont want to ping an interface of the ACE
, he wants to ping the VIP.
ā02-22-2011 05:29 AM
It's configured on the client side interface, not on the server side,
Thanks..
ā02-22-2011 06:14 AM
Try to configure the service-policy on your server-interface too. Or configure it globally, than you should be able to ping from both sides.
ā02-22-2011 06:21 AM
I'd have to test to confirm but the security feature should be applicable to the VIP as well. The ACE still has to route/bridge from one side to the other to ping the VIP.
A global/serverside service policy would allow the ping but would not make sense from a load-balancing perspective because servers hitting the VIP to access other servers in the same subnet would need to be source NAT'ed. The question really is - do you want to load balance traffic from the back-end servers with the same VIP or are you just checking if you can ping the VIP?
ā02-22-2011 06:33 AM
We have some similiar setup and it is possible to ping the
VIP in frontend and to use it access it from backend to
o. If it makes sense? sure not, but it is part of the configuration that the customer wants.
ā02-24-2011 06:40 AM
Thanks for your reply. Configuring the service policy on the server side int did the trick. I was also able to ping the physical interface, but not the alias.
Thanks again..
_ Alex
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide