Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Hi,The VIPs on my ACE configuration are not advertising themselves. They don't show up in the ARP table in the upstream router/firewall.The VIPs are configured to be "Inservice". I have probes that are successful. I can access the real servers beh...
Hi,I would like to implement Source-NAT for some traffic, but not all traffic for the ACE 4700. The ACE 4700 will be configured as a bridge.Can I configure Source-NAT using an extended access-list when the ACE 4700 is used as a bridge? I need Sourc...
Hi, I would like to accomplish the following.www.xyz.com resolves to a VIP on the Cisco ACE 4700 on HTTP.When a client types in http://www.xyz.com/bcd, I would like the request to be redirected to www.bcd.comHow do I go about doing this? Do I need t...
I have a question regarding choice of Layer-3 devices on a mid-size network. This network averages about 1200 client machines and there are 100 servers.Which is a better choice for core and distribution-layer routing? Should I go with four Catalyst...
Hi,Regarding IP-Helper Configuration, when you list IP addresses with the ip-helper address command, does the router forward the broadcast/DHCP/BootP request to the first IP address on the list first or does the router forward the request to all IP a...
Hi Gilles,Yes, the policy is assigned to both VLAN interfaces of the bridge-group.Yes, all VIPs show INSERVICE when I run the command "show service-policy int204-n2"None of the VIPs are responding to pings or showing up in arp table of the upstream r...
Hi Syed,Thanks for your response.There are no ACLs on the client VLAN interfaces.There is a global ACL on the entire ACE, permitting all ICMP, TCP, UDP, and IP traffic.I can access all real servers behind the ACE in bridged mode, so there is no restr...
Hi Gilles,I followed your advice about using webhost redirect rserver, but the ACE doesn't seem to recognize the match-http-url.I also can't ping the VIP, even though the VIP is active, and the probes are successful.I've attached my ACE configuration...
Thanks, Gilles.One more thing - for the Nat pool, do I associate it with the Client-Side VLAN or the Server-Side VLAN?As for the Service-Policy for NAT, should I associate it with the Client-Side VLAN or the Server-Side VLAN?
Thanks, Gilles!So, does it mean I can just use a standard access-list to identify traffic for Source-NAT? Meaning, I can just Source-NAT based on source IP addresses instead of using an extended access-list to specify both source address and destina...