Cisco Application :: 6509 - ACE Module In Bridge Mode?
May 16, 2011
We have a 6509 with an ACE module. For reasons I don't fully understand the ACE is running using a BVI in bridge mode. It has loads of secondary interfaces.
I can ping all of the IPs on the BVI, but only servers in Subnet 10.7.42/42 can ping out of the the layer 3 on the 6509. I have all the routes configured properly on the 6509 pointing to the ACE for these subnets. The question is though the config has been excepted, is there a limit to the number of secondary on a BVI.
I am desiging a topology with two Cat 6509 and Two ACE Module, one ACE per Catalyst. I am thinking to use bridge mode for the customer contexts, I would like to know if the Bridged mode is an Assymetric topology.
The server gateway is the ip address of the ACE or the Router?
I trying configure ASN traffic load balance, but doesn't works.I have one Cisco Catalyst 6509 and onde Cisco Ace10 module, in my context "PanWEB" i have the interfaces above: [code] If i try to establish a telnet session(telnet 10.96.202.10 80) i see the SYN packet passing through the ACE and going to the real server, but, the server do not response the SYN packet. I done a capture in the server using wireshark and could see that the IP address of the destination is the VIP and not the rserver ip address , this is a problem? Why can not I have the SYN + ACK from the server?
We are facing a strange issue, our ACE 20 got failed due to power issue , after RMA once we are installing ACE 20 to 6509 , the status LED is showing ORANGE . The sh module shows it as " Others " ... The IOS is same as it was previously in 6509 .
Whatever a NAT is supported for ACE-20 module? I do need to convert working CSM(SLB) config to ACE configuration and I am not quite sure if the configuration below is correct. ACE module should be configured in bridge mode with two vlans - vlan 36 (client) and vlan 436 (server) - bridged with interface bvi 36. NAT on ACE configurad as "nat dynamic 1025 vlan 436" into corresponding "policy-map type loadbalance". Check two parts of configs and if the ACE config is properly converted from CSM and will be working in the same way (especialy for NAT). [code]
I am trying to get documentation on how to integrate an ACE30 module in a service chassis design integrated with the Nexus 7000 in routed mode. Only documentation I could find shows this design with the ACE30 module in a one arm mode. Any documentation that shows this implementation of this design?
I have two ACE working on active-standby mode, I have one context configured on bridge mode, with two vlans, the client (vlan 100) and server (vlan 101) sides.I need to balance another service for two servers (different from the ones on the first context ) on the vlan 101, so as the documentation says i can't configure the same vlan on another context because it is already configured on the 1st context as bridge.so my question is the only way i could balance this service is to configure it on the same context??. or there is another way?.These are the design limitations that i have to do this:
1.- I can't change the servers IP address.
2.- The VIP which will answer the clients request is on the same IP network segment as the servers, for example: server1: 192.168.100.125, server2: 192. 168. 100.126, VIP: 192.168.100.124
I am trying to setup ACE in bridge mode. Network topology is as follows:
1. ACE Gi 1/2 (client-side vlan) is connected to 3750 (vlan 40) 2. ACE Gi 1/3 (server-side vlan) is connected to 3750 (vlan 50) 3. Two real servers are connected to 3750 (vlan 50) 4. One client device (linux box) is connected to 3750 (vlan 40)
I am not using admin context. I have created a new one for user. I am unable to ping VIP (10.10.50.15) either from client linux box or from within ACE.
access-list everyone line 8 extended permit ip any any access-list everyone line 16 extended permit icmp any any probe http PROBE_CGNMS_WEB port 80 interval 15 passdetect interval 60
Current topology in network is such: web servers with content needing to be load balanced are in vlan 35 and these servers are directly connected to Core switch (two 6509 VSS) via 20 Gb EtherChannel. Vlan 35 also spans some other switches with other servers residing in this vlan. Additionally, there are dozens of another vlans (including external users) that need to communicate with web servers. IP addresses of these two web servers are: 192.168.35.1/24 and 192.168.35.2/24 accordingly with default gateway 192.168.35.254/24 (SVI on Core switch). Currently these ip addresses are used by management and other purposes and need to be reachable for same purposes after configuring load balancing with ACEs - it is needed to have direct access to servers behind ACE. How I can do that using ACE in routed mode?
We have a 6509-e (WS-C6509-E V04) with (4) (WS-X6148-GE-TX) 48 port modules and a supervisor 32 (WS-SUP32-GE-3B).We purchased a supervisor 720 (WS-SUP720-3B) and (2) (WS-6708-10G-3C) 8 port fiber modules and (1) WS-X6748-GE-TX)48 port module to add to the switch. My question is what is the best way to swap out the supervisor module? Can the SUP720 be added as a standby module so that the config can be transferred? Probably a long shot. Is there anything in this swap that I should be concerned with? The other three modules should be pretty straight forward.
we have two 6509 catalyst. we bought two new SFM-capable 16 port 1000mb GBIC/WS-X6516A-GBIC module. but our catalysts doesnt support them. we don't know the reason. we tried on another 6500 series catalyst they worked.
here are the outputs from our 6509:
Core-SW-1#sh module Mod Ports Card Type Model Serial No. --- ----- -------------------------------------- ------------------ ----------- 1 0 1-subslot SPA Interface Processor-600 7600-SIP-600 JAE14090958 2 48 CEF720 48 port 10/100/1000mb Ethernet WS-X6748-GE-TX SAL1413DX2B 3 16 CEF720 16 port 10GE WS-X6716-10GE SAL1414EL2Q 4 1 Application Control Engine Module ACE20-MOD-K9 SAD1408036Z 5 5 Supervisor Engine 720 10GE (Active) VS-S720-10G SAL1414ERDT 6 5 Supervisor Engine 720 10GE (RPR-Warm) VS-S720-10G SAL1414ERE3 7 16 CEF720 16 port 10GE WS-X6716-10GE SAL1414ER93 8 16 SFM-capable 16 port 1000mb GBIC WS-X6516A-GBIC SAL1326SVBS(code)
I have a pair of 6509-E Switches running VS-720 Supervisors. We are planning to add Ace Module onto the 6509-E. Will IP Base Image suffice the requirement? Will Ace Module work with only IP Base Image?
I have a switch Cisco WS-C6509-E WS-X6716-10G-3C module ( module for 10 GB) , i have the IOS s72033-ipservicesk9-mz.122-18.SXF9.bin. I want to know if this IOS can support this module or not ? or , if i must do a upgrade , is that the IOS : "s72033-ipservicesk9_wan-mz.122-33.SXH8" work fine ?
I recently installed the license ACE-SSL-05K-K9 on ACE10 with multicontext solution.The license provides 5000 Maximum number of SSL transactions per second (TPS).The customer would like to track this to find out the correct size and in the case of services https upgrade licenses.Can I do it so through particular output or it's necessary monitoring with snmp service? In the second case, can you tell me the oid string to use?
In case the module should receive a higher number of connections to that provided by the license, what's the issue for new https connections?
We are using a Ace module running version 3.0?We do have a service which can now be reached by a url like https://www.xxx.com/yyy/ < notice the last /This is running via the Ace which terminates SSL and so on..
So now our client wants an url like https://www.yyy.com . The backend realservers and place of virtual dirs on IIS stays the same.
So now /yyy/ needs to be added to the backend realserver request, so the correct virtual dir is used. Therfore I need to add this Uri towards the realserver.
Suffered a big outage on the network, the fix was to reload the module 3 on the 6509 switch, we had these errors on the log %CONST_DIAG-SW1_SP-3-HM_PORT_TEST_FAIL: Switch 1 Module 3 TestUnusedPortLoopback Port(s)[24,46] failed. System operation continues.in the end, we reloaded the card and it was all ok. is there anything I can do to check the card / or any deeper logs? would that error cause the card to crash?
I have a cisco 6509 configured with a cisco NAM module. I have reset the config of the NAM module by the config clear command. Since this moment I can't no more ping the NAM module via the management port: OK via the 127.0.0.91 address and log in ok via the ios cli session command. [code] I have already tried to reboot the module via the ios cli hw module command and nothing better.
I have a cisco 6509 (ws-c6509-e) IOS 12.2.(18)SXF6 with the following modules and submodules: [code] I would like to add another module, I have WS-6816-GBIC or WS-6516-GBIC which one will work with my 6509 ? The 6509 has four module slots empty: 4-7-8-9, Can I add the card in one of these slots ?
How I can shutdown a module when I am running vsl.I can use the following command #hw-module module 2 shutdown.As I have modules in both switch 1 and switch 2 how can I ensure I only shut down module 2 in switch 1.
We have a VSS environment with two Cisco 6509-Es. IOS image:s72033-ipservicesk9_wan-mz.122-33.SXI5 when I switch on or reload the Core switches(VSS), I find a Minor Error in the "Show module switch all" command.I also did a "show diagnostic result switch 1 module 5"Switch 1 Module 5: Supervisor Engine 720 10GE (Active) SerialNo : SAL1521E035
Overall Diagnostic Result for Switch 1 Module 5 : MINOR ERROR Diagnostic level at card bootup: complete Test results: (. = Pass, F = Fail, U = Untested) 45) TestVslLocalLoopback: Port 1 2 3 4 5 ------------------- U U U . F
This issue temporarily relieves when reseating the X2 module, but reappears after reloading the switch.
I Just deployed some of these new modules and running A4.x code. How to configure an ACE with the maximum context?
We run in tranparrent mode with 110 Contexts, we found that with a base config for each context(80 lines of code) this would only leave us with 7% of available RAM. The Device begins to shut down services @ 5%. like SSH and others.
So, Is this even possible to configure 250 contexts and still manage the device.
if the 7600-SIP-200 supported in VSS mode or not ?
I have configured to Cisco Catalyst 6513 as VSS, both of them have the 7600-SIP-200 module, before converting them to VSS I was able to work with the 7600-SIP-200 module, but after I did convert them to VSS, both modules didn't work.
here is the show module output, after VSS conversion:
VSS1#show module Mod Ports Card Type Model Serial No.--- ----- -------------------------------------- ------------------ ----------- 1 0 4-subslot SPA Interface Processor-200 7600-SIP-200 JAE14500GMT 7 5 Supervisor Engine 720 10GE
We have a requirement to build a datacenter within a datacenter for a new project. The existing Core network is 2 x Cisco 6509 in VSS configuration. We would like to connect the new datacenter to the existing Core switch from the new low-end Core switch. This datacenter would have a SAN network and blader chassis.
Listing the Cisco Switches requirements and expansion module requirements ?
- What expansion module is required at existing 6509 ? Can we have one 10Gibit modules on each switches and crate a port-channel connection from new datacenter core switch ?
- Which model of Switch you recommend for the new Datacenter Core which is only going to have one SAN Enclosure and two blade chassis? Will it be a good option to use 3750E ? If yes do we need any additional modules there ?
- Which aggregation switch should we use for the blade enclosure ?
- Should we have a Cisco Embedded Switch module on the chassis to create trunk with aggregation switch ?
- How the SAN director switch is connecting to the LAN ? should we have any particular module at new Core switch ?
I m planning to implement VSS in core but want some inputs on IOS as i have FWSM as a service module Core :- Ii am running 12.2(33)SXH2a on my Core 6509 and i checkd cisco sites and Fwsm release notes but it states only I-Train of IOS while mine is H-Train so can I directly upgrade to I-Train or I was thinking of SXH8b IOS.
I am currently stuck to setup an automated configuration backup for ACE Blades. I found a script to backup the ACE from the Cisco ANM box but unfortunately I am not very familiar with Linux. (script) in place, to "pull" the ACE config from a Microsoft system ?
I have an ACE20-MOD-K9 with version A2_3_6a, and i am having problems in cookie persistency. the setup contains 4 servers using round-robin algorithm and cookie persistency and that receive http traffic on port 9090. I have been receiving complains that the users are getting disconnected randomly while accessing the web application through ACE. Below is part of the config, when setting the timeout of the cookie to default or something equal to hours, the disconnection/complains gets worse.
I wanted to find out how many times can I apply a healthcheck in a single context. I have 50 farms that are using the same port and instead of creating 50 different healthchecks, I want to just create 1 healthcheck for the 50 farms and apply it to each farm. I also need to know if the same limitations (whatever they may be) is the same for the 4710, ACE20 and ACE30.