Cisco Application :: ACE 4710 / Module Routed Versus Bridged Mode
Nov 10, 2010I understand routed vs bridged mode configuration fairly well, however, I do not understand the pros/cons between using them.
View 6 RepliesI understand routed vs bridged mode configuration fairly well, however, I do not understand the pros/cons between using them.
View 6 RepliesWhatever a NAT is supported for ACE-20 module? I do need to convert working CSM(SLB) config to ACE configuration and I am not quite sure if the configuration below is correct. ACE module should be configured in bridge mode with two vlans - vlan 36 (client) and vlan 436 (server) - bridged with interface bvi 36. NAT on ACE configurad as "nat dynamic 1025 vlan 436" into corresponding "policy-map type loadbalance". Check two parts of configs and if the ACE config is properly converted from CSM and will be working in the same way (especialy for NAT). [code]
View 2 Replies View RelatedI am desiging a topology with two Cat 6509 and Two ACE Module, one ACE per Catalyst. I am thinking to use bridge mode for the customer contexts, I would like to know if the Bridged mode is an Assymetric topology.
The server gateway is the ip address of the ACE or the Router?
I am trying to get documentation on how to integrate an ACE30 module in a service chassis design integrated with the Nexus 7000 in routed mode. Only documentation I could find shows this design with the ACE30 module in a one arm mode. Any documentation that shows this implementation of this design?
View 2 Replies View RelatedCan an ACE 4710 have , in the same context - servers which are
a. just being routed to
b. a set of load-shared servers
I have been told you may not be able to do this on this version?
In 2008-2010 timeframe, I used the ace 4710 appliances at one customer and kind of liked them. The deployment was not too SSL intensive and B/W requirements were low, but I configured a few HA pairs and that worked well. The configuration was pretty comparable to other Cisco devices; so easy to learn/pick-up.Fast forward to 2011: stepped into an environment, where customer purchased 3 - ACE 20 modules (before I got here), and had multiple issues with them. I found 4 documented TAC cases, and 1 was still open. I started working from December 2011 on getting Cisco to own-up WRT modules but customer by that time had had enough.
The most serious issue was a random reboot, hang or lockup. I wasn’t here to work with them to verify, but that’s eventually what the deal breaker was. Around the February 2012 timeframe, talking to Cisco SE, he revealed Cisco had an independent lab in Switzerland verify that some hardware component on the device had a terminal defect, in which a bit would flip, and force the device to lock or reboot - subject ot radioactive decay or interference.Cisco and the lab attributed this to improper shielding, coupled with defective material in the electronic component; hence the device was highly susceptible to radiation-type errors. This is the kind of stuff you read in doomsday reports! As a result, Cisco was EOL-ing the ACE-20 module. I am trying to get Cisco to replace the ACE-20 modules with something else, but they haven’t been too cooperative. They have also limited their SE/Salseperson presence where I work (Pacific Northwest); and are not too responsive.
I have gotten a verbal agreement to get a credit on prior purchases for the amount this customer spent on the ACE-20 modules. However, the credit is only a few points off their normal discounting model. And Cisco will not go into loss on new product sales. Using example, $100 product would cost me $55 with standard Cisco discounting. Cisco’s cost might be $45 so I will only get another $10 credit on this new purchase.The 3 Cisco ACE-20’s originally cost customer about $100K, so to dwindle this credit down, we would need to purchase about $1-$2 million of new hardware - that's a lot of new gear! And I don’t have any real way of knowing that Cisco is applying the credit honestly, and they won’t put anything in writing. This entire issue has really dampened customer’s impression of Cisco. They had smartnet on the ACE-20’s for 2+ years, but then dumped that after losing faith in the product. Now I am trying to resurrect smartnet to see if Cisco will give us an alternate product.
And to cap it all off, the original Cisco salesperson (who sold customer the ACE’s), has left and went to work for F5! And yes, he has been calling on customer to try to sell some big-IP's! At least there is some humor in all of this. So... Has anyone else had bad experience with ACE-20 module? How about ACE 4710? How to get a reliable working ACE module from Cisco?
We currently have ACE20's, which only support multicast in bridge mode.Was wondering if it's the same on ACE30's, or if Cisco finally implemented support for mcast in routed mode.
View 3 Replies View RelatedCurrent topology in network is such: web servers with content needing to be load balanced are in vlan 35 and these servers are directly connected to Core switch (two 6509 VSS) via 20 Gb EtherChannel. Vlan 35 also spans some other switches with other servers residing in this vlan. Additionally, there are dozens of another vlans (including external users) that need to communicate with web servers. IP addresses of these two web servers are: 192.168.35.1/24 and 192.168.35.2/24 accordingly with default gateway 192.168.35.254/24 (SVI on Core switch). Currently these ip addresses are used by management and other purposes and need to be reachable for same purposes after configuring load balancing with ACEs - it is needed to have direct access to servers behind ACE. How I can do that using ACE in routed mode?
View 3 Replies View RelatedI wanted to find out how many times can I apply a healthcheck in a single context. I have 50 farms that are using the same port and instead of creating 50 different healthchecks, I want to just create 1 healthcheck for the 50 farms and apply it to each farm. I also need to know if the same limitations (whatever they may be) is the same for the 4710, ACE20 and ACE30.
View 1 Replies View RelatedWe are in the situation we have a active configuration with ACE30 doing normal load balancing in routed mode, we have tons of rservers going out on a VIP.we now had to add a new private network to a provider that strangely enough does not want to see our public or private addresses. we need to loadbalance towards him on a priovided subnet (still rfc1918) (IOS VRF bug? is that correct?)I have two options, add the network (new interface) to the active loadbalancers (contexts) and then tie in new policies to the active serverfarms or make a new context just to load balance towards this provider.(preferred)Now - If I do this, the rservers see the client source addresses from this new provider. as the loadbalancer does not "hide" the client IP's. I would then have to add static routers toward the new context - I would want to skip that.
is there a way, to make the loadbalancer hide the client addresses towards the rservers ? perhaps I'm just needing the correct search term to find the config example.
what is that mean-"Redundancy is not supported between an ACE module and an ACE appliance operating as peers" I'm designing network in which I plan to use ACE-4710-0.5F-K9 appliances.
View 1 Replies View RelatedI have two ACE working on active-standby mode, I have one context configured on bridge mode, with two vlans, the client (vlan 100) and server (vlan 101) sides.I need to balance another service for two servers (different from the ones on the first context ) on the vlan 101, so as the documentation says i can't configure the same vlan on another context because it is already configured on the 1st context as bridge.so my question is the only way i could balance this service is to configure it on the same context??. or there is another way?.These are the design limitations that i have to do this:
1.- I can't change the servers IP address.
2.- The VIP which will answer the clients request is on the same IP network segment as the servers, for example: server1: 192.168.100.125, server2: 192. 168. 100.126, VIP: 192.168.100.124
We have a 6509 with an ACE module. For reasons I don't fully understand the ACE is running using a BVI in bridge mode. It has loads of secondary interfaces.
[Code]...
I can ping all of the IPs on the BVI, but only servers in Subnet 10.7.42/42 can ping out of the the layer 3 on the 6509. I have all the routes configured properly on the 6509 pointing to the ACE for these subnets. The question is though the config has been excepted, is there a limit to the number of secondary on a BVI.
What are the pros and cons of configuring a Switch Virtual Interface (SVI) versus a routed physical port between layer 3 switches?For example, if I have two 4506s and have a need to run HSRP and route between them which feature is better and why?
switch_a
!
interface vlan 25
ip address 10.10.10.1 255.255.255.0
!
interface fa0/1
switchport mode trunk
[code].....
I'm a Cisco newbie and I'm in the following situation:
1>The router (867) must connect to my ISP in 1483 bridged (2684 bridged) mode, LLC, VPI/VCI 0/35
2>WAN IP will be assigned by ISP (DHCP)
3>No username and password required to establish the connection
4>MAC-Cloning is advised, not required
5>Firewall behind 867, WAN IP should be assigned to WAN interface firewall, connection established by 867
6>867 router will be used as a switch, so no NAT required. NAT will be setup on the firewall
7>Connection type: Analog (annex A)
The required setup can be fixed by configuring the 867 in half-bridged mode, but I don't no how and I don't know exactly how to config the 867 in bridged mode.
First, it's even hard to setup a good bridged config.
version 15.1no service padservice tcp-keepalives-inservice tcp-keepalives-outservice timestamps debug datetime msecservice timestamps log datetime msecservice password-encryptionservice sequence-numbers!hostname router1!boot-start-markerboot-end-marker!logging buffered 51200logging console criticalenable secret 5 ****!no aaa new-modelmemory-size iomem 10clock timezone GMT 1clock summer-time GMT date Mar 30 2010 1:00 Oct 26 2035 1:59!!no ip source-route!ip cefno ip bootp serverno ip domain lookupip domain name domain.local!!!!username admin privilege 15 secret 5 ***!!ip tcp synwait-time 10ip ssh time-out 60ip ssh authentication-retries 2!!!!!!!interface ATM0 no ip address no atm ilmi-keepalive!interface ATM0.1 point-to-point pvc
[code].....
Report run via Individual Web server URL’sThe report takes less than 20 minutes (average 15 minutes) to fetch and return the data. This is observed 9 out of 10 times.Report run via ACE Load Balanced URLThe report keeps on running for more than 20 minutes and never completes. The front end keeps showing report is running.The data in general when tested directly by running queries against the database (bypassing the platform) completes in 15-18 minutesThe network connectivity for each and every ports involved (Loadbalancer/Servers) have been throulgly checked.
View 6 Replies View RelatedI would like to convert my cable modem Cisco epc3825 (bridge only), and thus can not function as a router. Before if I could, but my Internet Service provider has updated the firmware epc3825 and I can not pass it on to cable modem (bridge only).
View 2 Replies View RelatedI have been trying this for ours and need to get it to work for a small branch office so I can get their cisco device connected and phones working.
The device works fine if I assigned it an IP address but the minute I set bridge mode only and assign the static IP to my system then nothing works. I have the latest firmware.
I'm trying to connect my WAG160N as a ADSL modem (disable the router function) and connect a real router (RVS4000)So, i put my WAG160N on birdged mode only, disable the DHCP on my RVS4000, i did configure my PPPOE access (user and password), change the IP adress 192.168.0.2.configure the DHCP and try to connect. i tryed to connect the RVS4000 and the WAG160N either with cross cable or a direct cable. I can get access to the RVS4000 192.168.0.2 and get access to the configuration menu but cannot get access to my WAG160N 192.168.0.1 even a simple ping.when i try to test the connection on my RVS4000 (status) it seems that my connection is up but i cannot get access to internet.
View 6 Replies View RelatedI've a Cisco SRP527W, it have a LAN in 192.168.1.0 range, now I need to put in bridge mode, to be transparent with my firewall, how can I do this?
View 3 Replies View RelatedI cannot find any explicit instructions on this. Maybe they're calling it other things or implying it in other settings.
How do I configured a BEFSR41 to operate in bridged mode?
My Encapsulation router WAG54G2 switch RFC 2516 PPPoE to Bridged mode only everyday and all configuration that i made will reset and also Application & Gaming button error when i click.I'v reset to factory default and upgrade the firmwire to the latest one but it not work also I replace the device but nothing changed.The problem will solve if I cut the powir off and restarted agein.
View 3 Replies View RelatedI put the ea4500 on Bridged mode, and now I cant connect!I know I have to put the new ip address, and when I do I choose direct conect, it ask me for a password, I put the password, I click to connect, and then it just sits there in waiting....
View 9 Replies View RelatedUsing Cisco 1811W with IOS 15.1(4)M5. FE0 and FE1 are connected to the internet via Billion ADSL2+ modems operating in bridged mode. Both lines are similar so I'll only discuss FE0 from this point on.Local subnet is 192.168.128.0/24 with router on 192.168.128.1 as default gateway. Modem on FE0 has static LAN IP of 192.168.128.2 and when plugged into the switch on the LAN side, the web interface can be accessed at that IP address. Unplug the modem from the switch and plug it into FE0 and it now works as desired providing access from the router to the internet but the web interface is no longer accessable at 192.168.128.2
I tried adding a static route "ip route 192.168.128.2 255.255.255.255 FastEthernet 0" and also "ip route 192.168.128.2 255.255.255.255 Dialer 1" Neither worked and presumably it isn't that straight forward. Possibly NAT or other routing configuration required.Although there isn't much to configure when in bridged mode, I mostly want this setup so I can look at the ADSL connection status and for the modem to write messages to syslog (works when plugged into switch on LAN side), or SNMP access.
I'm trying to connect my WAG160N as a ADSL modem (disable the router function) and connect a real router (RVS4000) So, i put my WAG160N on birdged mode only, disable the DHCP on my RVS4000, i did configure my PPPOE access (user and password), change the IP adress 192.168.0.2 configure the DHCP ... and connect ... no way !
i tryed to connect either with cross cable or a direct cable ... same result. I can get access to the RVS4000 192.168.0.2 bit cannot get acess to my WAG160N 192.168.0.1 (strange ... don't have explanation for that) even a simple ping !
when i try to test the connection on my RVS4000 ... it seems that my connection is up .
I'm trying to use my WAG120N router as a modem only/Bridged Mode and I've managed to enter all my settings needed on the WAG120N which is the Encapsulation to Bridged Mode Only, QoS to UBR, Type Of Connection to LLC, VPI and VCI to 0 and 35, DSL Modulation to Multi mode.On the EA4500's end I've entered my Usrname and password in the Internet settings and configured for PPPoE.
View 8 Replies View RelatedI have a WAG54G2 working fine for more than 2 years now. It has the initial firmware version 1.00.10
Recently I mode it from my home to my store, where I have a already working CCTV setup. Initially the router did not work, but once the service provider removed the mac-id binding (with my previous ADSL2+ router) the WAG54G2 was connecting on DSL. However it never got a DNS value. Currently I am using it with a fixed DNS.
After a few days of working I noticed that my remote viewing for the CCTV was not working. On checking the router settings I saw that the router had defaulted to no settings at all. Changing it back to PPPoE did not work since the page would not render completely. Resetting to Factory settings also did not work. However simply switching off the router and restarting it worked. I let it go then. The same thing happened again within a day or two. Each time restarted the router seemed to solve the problem, however temporarily.
I have the SPI firewall enabled also I have application port forwarding set for HTML port 80 forwarding to say port 1234.
have a Cisco ASA that I am trying to configure in a unique way, I want it to perform a variety of tasks;
VPN SSL
VPN Tunnels
Firewall Inside to Outside via versa
But the difficult task, is creating a DMZ with devices that are assigned fully routed IP addresses from our ISP directly, these are H323 and SIP devices that cannot use NAT, and must have a fully routed IP address assigned to them.
Obviously the problem I have with the Firewall in its default routed mode, is that it wont allow me to overlap IP addresses on the outside interface with the DMZ interface.
Could the Firewall be configured for Transparent mode between Outside and DMZ, but Routed mode between Outside and Inside?
Eth0/0: 10.0.0./24 (inside)
Eth0/1: 190.0.0.0/24 (dmz)
Eth0/2: 190.0.0.0/24 (outside)
[Code]....
But could the new Cisco ASA with the latest firmware and model be ale to do this with 1 physical firewall?
EA4500 in bridged mode and I can log in the the CCC account but nothing appears on the screen. I was able to see the settings, etc with the previious firmware. I reset the router and tried different browsers, PC, etc. Now running Ver.2.1.39.144146.
View 9 Replies View RelatedIs it possible to have context in transperant mode and routed mode. Means if i need three context then 2 of them is in routed mode and one of them is in transperant mode. If yes then how, i can 't find this info in cisco website.?I am havin 5585-x and asa version 8.4?
View 8 Replies View RelatedI'm runing an ea3500 in bridged mode, classic configuration, firmware 1.0.30 build 126544. I got ftp working for my usb attached wv delements drive , but it is totally invisible in windows (except for ftp of course).I read in an older post that the usb drive in certain situations does not work (independent of disk manufacturer/type and such) and for certain configurations the ftp option might work but the windows mapped network drive doesn't , does that still apply? does it apply to bridged mode ?
View 1 Replies View RelatedI have 2 modules of FWSM in 6500 switch (failover). I need 5 context. When I use in routed mode (like in the picture) , I cannot ping the servers behind the firewall. (I have ping to FW context) In transparent mode, it is not happening.
View 1 Replies View RelatedWhat should the duplex mode to be set on a routed port gi0/21 that are running HSRP ? I try setting the gi0/21 to full, but it caused the port to be down. The only way for the port to be up is setting it to half duplex.
Cisco 3750 Switch
==============
interface GigabitEthernet0/21
no switchport
ip address 10.200.104.34 255.255.255.248
[Code].....