Cisco Application :: ACE4710 Troubleshooting Connection Failure From Client

Nov 12, 2012

I have a ACE4710 setup to load balance a couple of web servers. The real servers all show as inservice as do the propbes and serverfarms/virtual servers. If I ping the Virtuual server ip address I get a reply but it I try to access VIP via telnet or web browser. I get a connection could not be open error on the client.The question is how do i determine where the error is comming from so far I can not tell if the client is getting through the acl or not.I have used the trouble shooting guide and nothing has worked to determine the cause so far. show service-policy int479 detail does not show an increase in the hit count when I try to connect.show stats conn does not show an increase in failed or timed out connections when i try to connect. [code]

View 3 Replies


ADVERTISEMENT

Cisco Application :: ACE4710 TCP Connection Reuse

Jun 8, 2011

We have a rather strange issue, and I'm not sure it's really a problem with the ACE or not. We created an HTTP parameter map called "TCPreuse" and applied it to a virtual server. A show conn detail displays "[ conn in reuse pool : FALSE]" for all connections pertaining to this virtual server. The rserver in question is Linux(Ubuntu) + Apache.Next we applied the HTTP parameter map to another virtual server - this time IIS7 + Windows Server 2008. There are plenty of entries "[ conn in reuse pool : TRUE ]" when I do a "show conn detail".What could the web servers be doing differently that would cause the connection reuse to work on one virtual server and not the other?

View 1 Replies View Related

Cisco Application :: Cannot Telnet To ACE4710

Sep 27, 2011

I have a problem, recently I can not telnet to the ACE 4710, the ACE version is A4(2.0). I can enter by web and console but not for telnet.  I try to give more resource to the admin context but it doesnt work.

View 1 Replies View Related

Cisco Application :: ACE4710 - Unable To Perform End To End SSL?

Nov 9, 2011

I have to load balance traffic between 2 servers sitting behind the LB. The webservices are on HTTPS/8443. I followed the end to end configuration guide for SSL. No success.
 
Here is my configuration -
 
rserver host nms1
ip address 10.29.36.31
conn-limit max 4000000 min 4000000

[Code].....

View 3 Replies View Related

Cisco Application :: Upgrade ACE4710 With Different Context?

Sep 16, 2012

I need to upgrade 2 active-standby cisco ACE4710, the issue is I cannot access FTP/TFTP/SFTP server via Admin context but can be accessible via other contexts.

Can I copy the ACE system software file from FTP/SFTP/TFTP server to image: directory durectly or need some other way around ? I could see the option is available to copy ftp: to image: via other context.

View 2 Replies View Related

Cisco Application :: One Interface Configuration For ACE4710?

Jun 15, 2012

My customer they do not want change their real server IPs. So I need setup one interace (one armed) for them on ACE4710. Who had this sample configuration? (CSS has this but it seems to be not compitable with ACE)

View 4 Replies View Related

Cisco Application :: ACE4710 To Perform SSL End-to-end Configuration

May 31, 2012

I am attempting to configure an ACE4710 to perform SSL end-to-end confguration. i.e. SSL termination - load balance - SSL initiate to backend server.The configuration appears to work fine in a test lab using any old web server, however when I peform the same configuration in the production environment it does not work. It appeatrs from a capture run on the ace that the ace is reseting the tcp connections after communicating with the back end server. The main difference I can think of in this environment is that the cert and key pair the ace is using where exported from the backend server, i.e. both the ace and the backend server have the same certificates and keys. Is this allowed? how to troubleshoot why the ace resets the connection.

View 6 Replies View Related

Cisco Application :: Configuring URL Filter In ACE4710

Jul 10, 2011

I have 2 ACE4710 in HA enviroment, they receive connection from Internet. What I need to configure is following:
The ACE have configured two URL, with the same port and VIP Address, for example:
 
URL-1: www.xxxxx.com
URL-2: www.xxxxx.com/Admin
VIP Address: 10.10.10.10
Port: 8443
 
All clients point to unique VIP and Port configured, I need to know if I can apply any filter or rule that allows me to distinguish when a customer goes to the URL1 or URL2.If any client try to access to URL-2, your traffic must be deny.In summary, from Internet I should be able to go only to URL-1.

View 3 Replies View Related

Cisco Application :: GSS 4492R Configuration With ACE4710?

Dec 8, 2010

I have to deploy the Cisco GSS in our 2 dataceters globally seprate IP ranges to loadbalance the exchange 2010 environment with Cisco ACE 4710 series SLBs.  The scenario is to deploy  one GSS + ACE on each datacenters and our nameserver will point to both GSS's IP addresses to get through. Incase primary site "site A" goes down name server will point the client's request to "site B".
 
What will be the physical setup of the GSS here and what configuration should on SLB ACE will make it work? Do GSS and ACE need to be in the same vlan? is this necessary to use Both interface of the GSS to get things working?  How the GSS will check the health check on ACE if they both are on different vlans/ip range? Our ACE will be in routed mode do we need to assign the Real server default gateway as ACE inside interface with the server farm or just do the SNAT of the client IPs so the request can come back to ACE?

View 6 Replies View Related

Cisco Application :: ACE4710 - Failover Over VLAN

Dec 3, 2011

I have HA configuration for two ACE4710. FT between Ace's is configured as L2 (V LAN). Active ACE is sending heartbeats, but switch shows lot of 'input errors' on ingress and this is a major problem. FT is logically not working (there is no connection between these two Ace's over V LAN). There is only L2 configuration, with speed and duplex auto, no other special configuration.  When I connect Ace's directly, FT is working without problem.

I can see lot of errors on input direction (from ACE) to switch port, that means, L1, or L2 problem, but direct connection (using the same Ethernet cable) is working. I tried 'shut/no shut' on both sides, set duplex/speed,... without success.
 
ACA IOS version is A4(1.x).

View 4 Replies View Related

Cisco Application Networking :: Possible In ACE4710 Appliance To Configure A SIP TLS

Feb 11, 2013

Do you know if it is possible in ACE 4710 appliance to configure a SIP TLS ?The SIP probe we have in the configuration guide it is only for clear text. for Lync 2013 we need to establish first a TLS session and then within it, send an SIP request..IS it possible in any version? I tried also to configure a HTTPS probe but it fails as it sends a GET which the Lync SIP server doesn't understand.

View 1 Replies View Related

Cisco Application :: ACE4710 Deployment Models Required

May 31, 2011

ACE 4710 deployment model.  We'll be doing an eval later in the year, but I'm just looking to understand the architecture.We have a stack of 3750 switches with a single VLAN (10.1.1.0/24).  Connected to that stack is a pair of web servers (10.1.1.5 and 6) that we want to provide load balancing/failover for.  Some of the clients are located right there on that same VLAN.  Other clients may be coming from other spots in the infrastructure.It sounds like I could put a pair of 4710s connected to that stack of switches, in a single arm deployment?  And then the virtual IP and the real servers would all be 10.1.1.0/24.  Maybe use an etherchanel to connect each 4710 to two 3750s?

View 9 Replies View Related

Cisco Application :: Putting ACE4710 Into Running System?

Apr 17, 2012

I'm implementing and found out some  issues are unresolvable on ACE4710. This network have been running on a server without LB. Now the second server comes up. We choosed to implement with Routed Mode.This network Peak @ 300Mbps. Now on we're doing the first context which is function as content  web-farm. In near future, 2nd context which takes care of indexing  web-farm when they buy more server.
 
From following diagrams.I browsed from internet into this service. "show service-policy" shown  as '0' (counter was not running). I guessed that there is something  wrong in FW configuration. So I isolated out FW. Then I plugged-in  my PC into network 30 (192.168.30.X) in front of this LB, then browsed  into LB's VIP (192.168.30.1). LB  "show service-policy" came up BUT  there is nothing return to my PC (client). "show conn" on LB as  "SYNSEEN". What's SYNSEEN?! Some meaningful.
 
Then I tried to figure out with a PC running 'apache' and took the  place of real server. "It works!" returned from LB/Server. "show conn"  became 'Establish' Programmer guy said if I browse into web-farm  (i.e. content web-farm) directly pkt will be redirected to indexing  server. But they said it will be L7 redirection. Not LB/Network level. 

View 5 Replies View Related

Cisco Application :: ACE4710 Is Not Able To Link Directly To APP / WEB Server?

Aug 31, 2011

We recently configured a setup to loadbalance 2 application server using ACE4710.  Initially the configuration was to link two app servers directly to ACE4710 without connecting to a Switch, but later, it was advised that ACE4710 is not able to work without connecting to a switch. 
 
1. ACE4710 is not able to link directly to APP/WEB server, but it must go through a network Switch.
 
2. If item-1 above is true.  We used to have a older Cisco Loadbalancer which is able to link directly to WEB/APP servers. What is the reason or advantage of removing this feature?

View 7 Replies View Related

Cisco Application :: ACE4710 - Microsoft Windows CPU OID Changes Between Reboots

Oct 14, 2012

On my ACE4710s I'm using least-loaded predictors monitoring Microsoft Windows CPU usage. There are times when the MS Windows CPU OIDs can change between reboots. Any way for the ACE to automatically adjust to the new CPU OIDs and continue to get accurate CPU usage values?

View 1 Replies View Related

Cisco Application :: ACE4710 Started To Continuously Reboot?

Mar 3, 2010

one of our 2 ACE boxes in FT group suddenly reboot-ed from active state and now it continuously reboots with the following error:
 
insmod: error inserting '/isan/bin/klm_octeon_device.klm': -1 No such deviceerror inserting /isan/bin/klm_octeon_device.klmDaughter Card Not Found. Rebooting..INIT: Sending all processes the TERM signal...

View 10 Replies View Related

Cisco Application Networking :: CSS11503 To ACE4710 And Server Side NAT

Dec 16, 2012

We have a CSS11503 that is currently being used to accept incoming HTTPS and SSH connections on a specific VIP and then PAT those client connections.  I understand that it also PATs the server initiated connections. [code]

View 1 Replies View Related

Cisco Application Networking :: Does The ACE4710 Support Custom Protocols

Jun 1, 2011

For server load balancing, does the ACE4710 support custom protocols? We'll be using HTTP for server health monitoring, and to determine if a server is up or down. But the client/server application is custom, and includes a lot of non-standard ports.  Can the server VIP handle generic TCP connections?  For example client1 connects to the VIP on http, but then later client1 switches to using tcp842 (a custom protocol, not http).

View 5 Replies View Related

Cisco Application Networking :: ACE4710 - Can't Assign IP Address To Physical Ethernet Port

Jan 4, 2013

My customer wants each ACE4710 (of a highly available cluster) to have its own, dedicated port for management purposes.
 
According to documentation, IP addressing can be applied to VLAN interfaces, so in order to satisfy the requirement, I should make one port belong to an "access VLAN X", and then apply IP addressing to the corresponding "interface VLAN X". This should satisfy my customer´s requirement in an indirect way.
 
But... ¿ Can´t I just configure IP address on one of the 4 ethernet ports in order to save the work of building the aforementioned VLAN? I am asking this since I do not have access to a real box in order to verify.

View 2 Replies View Related

Cisco Application :: ACE4710 Insert Cookie - Does It Overwrite Server Cookie

Mar 28, 2012

I was trying to implement stickiness based on cookie. Server inserts a cookie and sends it to the browser. I learned from app team that this cookie is changing dynamically during the session, so stickiness based on server’s cookie doesn’t work.
 
Now I want to investigate into possibility of ACE to insert a cookie. My question is: ACE feature of “cookie insert”: does it add additional cookie into http header without removing server cookies or it deletes the cookie(s) that server put into http header and replaces them with its own cookie?

View 1 Replies View Related

Dell :: XPS400 Lost LAN Connection / Cannot Connect To Internet After Troubleshooting

May 28, 2013

I have an older windows xp computer, xps 400.

 I had unplugged my computer due to painting the room. When i plugged back it I couldn not connect to internet. But oddlly enough my mcafee security center gave me a message that mcafee subscription expired, which it can't as I use it through my subscription through aol. Had this problem once before. So i uninstalled mcafee. I ran malwarebytes to see if there was anything that might prevent me for accessing internet, it found two adware that I quarentined.

I have tested my ethernet cord and connectivity on another computer it works fine.I had a realek RTL8139 Family PCI Ethernet NIC, i reloaded the driver after downloading from my other computer, now it say it is a realtek RTL 8139/810x family ethernet nic, not sure if I downloaded the wrong driver but before that I tried changing the speed to less than auto detect.

I have rebooted in safe mode in case there was a virus. I am at my wits end.Is there a way to factory reset the network adapter. What else can I do. light at the ethernet port looks to be yellow. Everything says it is working, I just can't connect.

View 4 Replies View Related

Cisco Application :: ACE4710 Appliance To ANM Virtual Appliance NATed

Oct 12, 2011

We have an ACE Appliance in a DMZ and the ACE Appliance's Admin Context IP is translated between ACE and ANM. The ANM Server does not get translated. It is just the opposite then in another Community discussion.
 
Our Problem: When adding the ACE4710 Appliance to the ANM imported Device List, we use the ACE's NATed Admin Context IP. Import works well, but ANM reflects the Admin Context IP with it's real configured IP. Polling the ACE Appliance does not work therefore.
 
Is there a possibility of telling the ANM, that the ACE has to be polled through a NATed IP? I could not find a field to set a NATed Mgmt IP.
 
Configured IP on ACE Admin Context: 192.168.0.10
NATed ACE Admin  Context IP:           172.16.0.10
 
Imported ACE with IP 172.16.0.10 into ANM, but ANM polls for Rserver, Vserver, Probes, etc. via 192.168.0.10 - which is not reachable from the ANM.

View 2 Replies View Related

Cisco Application :: ANM 5.2 Authentication Failure

Apr 15, 2013

I'm using the Cisco ANM 5.2 version and I'm trying to import the configurations from ACE modules of Cisco switches. The first step is to import the configuration from Cisco switch and the second one is to import the ACE module in the ANM software. I'm getting an authentication problem to import the configuration from Cisco switch and of course I cannot import the ACE as well. The switches and the ACE are using AAA authentication and I have created a specific username to authenticate and import the configurations in the ANM. If I remove the AAA configurations from the switches and ACE modules it works fine.
 
Is there some problem with the AAA configurations in the switches or ACE module?

View 7 Replies View Related

Cisco Application :: ACE 4710 Getting Configuration Download Failure

Jan 22, 2013

I have Ace 4710 version A4.1.1 and I am experiencing interesting problem with GUI and SSH reachability. I am unable to connect to management vlan3000. Interesting is that I can ping from ACE to network but unable to ping or SSH or HTTPS to ACE. Everything seems good. ARP is ok, switch is OK, line is up, protocol is up. Management is enabled for icmp, https, ssh to any.
 
When I do show interface I noticed line  Config download failures : 9.
 
Hardware type is VLAN  MAC address is 00:1e:68:1e:bc:db  Virtual MAC address is 00:0b:fc:fe:1b:01  Mode : routed  IP address is 10.168.0.18 netmask is 255.255.255.128  FT status is active  Description:Management VLAN  MTU: 1500 bytes  Last cleared: never  Last Changed: Mon Jan 21 16:48:54 2013  No of transitions: 5  Alias IP address not set  Peer IP address is 10.168.0.19 Peer IP netmask is 255.255.255.128  Assigned on the physical port, up on the
[Code] ....

View 7 Replies View Related

Cisco Application :: CSS11501 Commit Vip Redundancy Script Failure?

Jun 23, 2011

recently when i run the commit vip redundancy script, i encountered the following error. This script has never failed in the past. Upon checking the backup CSS, i did notice that my most recent changes were actually synced. The following is the debug i have captured while running the script.

active-lb# script play commit_vip_redundancy "local 167.168.165.10 remote 167.168.165.9 -a -d" active-lb# Checking available disk space on systems ... Checking the disk space locally before continuing with the script. Verifying that another local session is not running the script. Creating script/vipr_config_sync_lock file. Verifying app and redundancy configs ... Verifying that app session is up with backup switch. Making sure app session is up. Seconds to wait before calling it quits:    60 Checking the disk space remotely before continuing with the script. Checking local and remote switch versions ... Storing the running code versions of the local and remote switch. Storing the local switch's version. Retrieving the remote switch's version. Checking remote version for 4.0 Checking if switch is BACKUP for any virtual routers and if the state is 'No Service'. Checking vip redundancy state.... Checking if backup switch is Master for any VRIDs. If it is, either a local

[code].....

View 1 Replies View Related

Cisco :: WLC 5508 - Client Association Failure Null

Feb 21, 2013

I am running WLC 5508 and WCS version 7.0.98.  We are noticing with some of our handheld devices that have Sychip Wireless cards that they constantly have issues communicating.  The error I see on the WCS side is shown below:     
 
Client '00:0b:6c:2f:d0:32 (0.0.0.0)' failed to associate with interface  '802.11b/g' of AP 'HO-BRSales'. The reason code is '0(null)'.

View 11 Replies View Related

Cisco Wireless :: Client Can't Get DHCP Address When On-MAC-Filter-failure

Aug 21, 2012

The wireless client can't get the DHCP address when I enable the On-MAC-Filter-failure, MAC Filtering and Web Auth. Client can get the DHCP address when I only enable the Web Auth in the same WLAN SSID. The WiSM verion is v7.0.235.0. [code]

View 1 Replies View Related

Cisco Wireless :: 5508 WLC Excessive Client Authentication Association Failure

Jan 29, 2013

I have been noticing in my trap logs that there are an excessive amount of Client Association/Authentication Failures. I cannot figure out why. I have a Cisco 5508 WLC with 81 AP's (1131ag, 1142abgn, 1262N) models. The wireless devices are on a Windows Domain and use 802.1x EAP authentication, authenticating the user and computer info with a RADIUS Server. I look at the logs and all it can tell me is Reason:Unspecified ReasonCode:1. I read that the Reason Code is due to "Client associated but no longer authorized" but to be honest I am not sure what that means.

View 9 Replies View Related

Cisco Firewall :: ASA5520 IPsec Client Reverse Path Failure

May 4, 2011

ASA-5-305013: Asymmetric NAT rules matched for forward and reverse flows; Connection for icmp src outside:192.168.13.50 dst DMZ2:192.168.13.15 (type 8, code 0) denied due to NAT reverse path failure
 
Cant seem to get around this one yet. I have a remote ASA that I can VPN into. It has 2 dmz's, outside and inside interface configured.
 
Inside subnet is 192.168.11.0 / 24
DMZ2 is 192.168.13.0 / 24 
VPN client pool is 192.168.15.0 /24
 
I login in fine. But have no access to the DMZ2 subnet. I get the failure listed above.

View 1 Replies View Related

Two Client Socket For Same Application?

Mar 31, 2012

I have two wi-fi network, and i have written client server model in c (Linux), client has three threads and each thread having different physical wi-fi conection to server. But the problem is that, overall data rate is not increased by this, it is similar to using with one wi-fi connection.

View 1 Replies View Related

Cisco Application :: 389 Vip Not Responding To Client Requests On ACE

Jan 4, 2012

client is unable to establish a connection to the backend servers via the vip on port 389 ,636 configured that servers are listening on these ports .even the probe is successful on port 389 but not getting any response back from the servers. [code]

View 1 Replies View Related

Cisco Application :: CSS11503 / How To Preserve Client Port On CSS

Mar 12, 2012

I’m wondering if there is a way to configure CSS11503 running 8.10 so that the servers in the content rules can see the client port number?The servers can see the client IP, but not the port!! It seems when forwarding packets to the servers in the content rule, the CSS uses a new high-number port when communicating with servers.

View 2 Replies View Related

Cisco Application :: ACE-20 Module In Bridged Mode With Client NAT

Apr 15, 2012

Whatever a NAT is supported for ACE-20 module? I do need to convert working CSM(SLB) config to ACE configuration and I am not quite sure if the configuration below is correct. ACE module should be configured in bridge mode with two vlans - vlan 36 (client) and vlan 436 (server) - bridged with interface bvi 36. NAT on ACE configurad as "nat dynamic 1025 vlan 436" into corresponding "policy-map type loadbalance". Check two parts of configs and if the ACE config is properly converted from CSM and will be working in the same way (especialy for NAT). [code]

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved