Cisco Application :: CSS 11501 Load Balancing With X-forwarded For Address

Sep 15, 2011

We have a pair of CSS 11501,Currently it is using source ip for load balancing and 5 servers as backend , however we have users loggin in using http and based on its source IP (ISP PROXY) , it is forwarded to SERVER A.However, we have a SSL page and when the client switches over to SSL , it is forwarded to SERVER B/C/D/E  based on its source IP ( REAL CLIENT IP) .This will cause the user to be terminated as the 5 servers are independent and not running in a cluster.
 
Is there any way that we can use the X-Forwarded-For address to load balance so that when users loging , they are sent to SERVER A (Based on X-Forwarded-For Header IP which translate to REAL CLIENT IP).This way we are able to also send it back to the same server when it uses SSL.I believe that we should be able to load balance using X-Forwarded-For IP or to rewrite the X-Forwarded-For IP into client source IP.

View 3 Replies


ADVERTISEMENT

Cisco WAN :: 11501 CSS Load / Advance Balancing

Mar 1, 2011

We have Cisco CSS 11501 and connected in  One-Arm way.Currently there are 4 source sending traffic and 3 server to  receive the request. We are using Advance-balancing with Source IP. So  the ratio become 2:1:1 or 1:2:1 or 1:1:2.But our target is to do the load balancing in equal ratio.

View 1 Replies View Related

Cisco Switching/Routing :: CSS 11501 - Configuring CSS Content / Load Balancing

Feb 3, 2012

I would like configure a CSS content, that uses the sorry service principal in an advanced way.

I am familiar with the primary Sorry Server command and see that the CSS would send all connections to the named service that is configured as the primary Sorry Server.

What I would like to do is to configure the CSS, so that once it’s decided it’s in a “sorry” state (all the services that are configured with “add service” are down) that it load balances to a different set of services.

To explain what I’ve been trying to do in the form of configuration on the CSS, I’ve pasted some pretend config below.

Connections come into IP address 1.1.1.1, which normally get load balanced between  9.1.1.1, 9.1.1.2 and 9.1.1.3.

If 9.1.1.1, 9.1.1.2 and 9.1.1.3 are all down, the sorry service is used and the CSS starts passing traffic to 1.1.2.1, which I want it to load balance between  9.1.2.1, 9.1.2.2 and 9.1.2.3.

The order that I have applied the config, is different to the below, as I set out to configure in this order: secondary services, secondary content, sorry service, primary services, primary content.

The order of the config below is different, because I wanted it in the order that the traffic flows and the CSS won’t take the config in that order!

The wall I have ran into, is that when I try to create the service I have named “Sorry Service”, I get the following error:

%% Service IP Address conflicts with a local I/F, VIP, mg mt route.

[Code] .....

View 0 Replies View Related

Cisco Application :: URL Load Balancing In ACE 20?

May 23, 2011

I have 2 rservers 10.30.1.73, 10.30.1.76,I have 3 URLs in both

[URL]
 
I want to have only one link for two same link in both servers with this ip address 10.30.1.172 so I will have 3 link and will load balance to 6 links

[URL]

View 4 Replies View Related

Cisco Application :: 389 Load Balancing LDAP In ACE?

Dec 5, 2011

Does loadbalancing ldap services in ACE? Both port 389 and 636.

View 4 Replies View Related

Cisco Application :: SIP Load Balancing With ACE 4710?

Nov 8, 2011

SIP Load balancing Issue with ACE 4710?I have a Cisco ace 4710 with vesion Version A4(2.2). i configued simple SIP load balancing first without stickiness. without stikeiness we are having a problem because bye packet at the was not going to the same server all the time that left our port in used even though user hang up the phone. its happen randmly. i have a total 20 licenced ports and its fill out very quickly. so i dicided to use the stickiness with call-ID but still same issue. below is the config
 
rserver host CIN-VOX-31
  ip address 172.20.130.31
  inservice
rserver host CIN-VOX-32
  ip address 172.20.130.32
  inservice

[code].....

View 6 Replies View Related

Cisco Application :: ACE20 Load Balancing

Apr 26, 2011

I have a problem with the ACE 20 load balance
 
To start with following is our architectural request flow:

Load Balancer --> Webseal /(reverse proxy) --> HTTP Server --> Portal Server

We have Hardware Load Balancer Cisco ACE20. When we access our portal from Webseal server it works totally fine without any issue, but when we access the same application using ACE we face the following issues:

1) Some of the links on do not work. For eg: We have a link "subscribe" which points to [URL], whenever we click on this link, the request is directed to [URL] i.e homepage

2) URL redirection does not work We have some links which have a url forwarding or redirection for example when we open [URL] it forwards the requests to [URL] opendocument....., but this redirection fails and again the request is thrown to homepage i.e., [URL]

3) The response of the request and the overall portal when accessed via ACE is very sluggish and it takes 20 seconds for homepage to load, whereas the homepage loads in 4 secs when accessed via webseal.

Below is the ACE details.

Hardware Product Number: ACE20-MOD-K9  Card Index:     207  Hardware Rev:   2.3  Feature Bits:   0000 0002  Slot No. :      7  Type:           ACE
Software  loader:    Version 12.2[120]  system:    Version A2(1.4) [build 3.0(0)A2(1.4) adbuild_11:54:12-2009/03/05_/auto/adbu-rel2/rel_a2_1_4_throttle/REL_3_0_0_A2_1_4]  system image file: [LCP] disk0:c6ace-t1k9-mz.A2_1_4.bin  installed license: ACE-SEC-LIC-K9

View 3 Replies View Related

Cisco Application :: ACE 4700 Not Load Balancing

Oct 26, 2011

I'm running an ACE 4700 appliance, i have a 4 server serverfarm setup, non-ssl, with leastconns predictor...i have tried round robin as well, and nothing...
 
I've taken each rserver out of service, and placed back in, and still, the traffic is handed off only to 1 server...
 
I do have sticky persistence (IP subnet)...

View 8 Replies View Related

Cisco Application :: ACE 4710 Server Load Balancing?

Jul 7, 2012

We have two Cisco ACE 4710 and we want to install both of the devices in HA with load balancing mode.While i have done HA mode configuration between ACE 4710.But unable to configure load balancing configuration between them.i want to tell you connectivity between server,client & loadbalancer.Our Web servers are connected to VLAN 152 on the L3 (3750) switch.Which are alreday working in redundancy between other L3.And ACE 4710 it is also connected to vlan 150 which are connected to same L3 (3750) switches and users are also connected to vlan 6 on the same L3 itself. 

View 2 Replies View Related

Cisco Application :: ACE30 Load Balancing Across Two Slightly Different Servers

Apr 10, 2013

is there a possibility to get a load balancing across two rservers so: when client sends http://vip/ and it goes to rserver1 then url is sent without change when client sends http://vip/ and it goes to rserver2 then url is modified to http://vip/xyz/
 
Or maybe load balancing can be done across two serverfarms ?

View 3 Replies View Related

Cisco Application :: ACE 4710 (1) SSL Certificate Import ( 2 ) With Load Balancing?

Dec 3, 2012

I am performing a deployment, in which i require clarity on the following. Our setup has DC and DR , in each site we have two devices for HA.We have received One SSL Certificate from Public CA, Kindly clarify the following doubts i have on thisIn Doc, i found Cert.pem and key.pem is required to generate the pair ,do i receive both Cert.pem and key.pem from the CA or we can generate key.pem from Cert.pem ?SSL Offloading is planned for the X application, and it is running in both DC and DR ( Considering each having their own Public IP address ) , do i need to have two different public certificates or a single certificate can i use in both DC and DR.Load Balancing IssueIs it possible to configure in ACE to access the service in Business hours and in non Business hours to display HTML page showing this is available only during these hours ?In DC we have Three Web Servers ( only in One physical server the service is active, other two are backup ), and these three servers are under cluster and shares one cluster IP , In ACE we have created the VIP and Pointed to only Cluster IP ( like pass through only ). The issue we face is if active web server is down, even then ACE is sending the traffic to that webserver only instead of sending it to the new Active web server. let us know if any solution is there to overcome this issue ?as per my understanding instead of giving cluster IP as real server IP we can issue the three physical servers. now i dont require load balancing between three servers instead require failover king like if first server is down then it should forward to Second server ?

View 4 Replies View Related

Cisco Application :: ACE30 Normal Load Balancing In Routed Mode

Sep 23, 2012

We are in the situation we have a active configuration with ACE30 doing normal load balancing in routed mode, we have tons of rservers going out on a VIP.we now had to add a new private network to a provider that strangely enough does not want to see our public or private addresses. we need to loadbalance towards him on a priovided subnet (still rfc1918) (IOS VRF bug? is that correct?)I have two options, add the network (new interface) to the active loadbalancers (contexts) and then tie in new policies to the active serverfarms or make a new context just to load balance towards this provider.(preferred)Now - If I do this, the rservers see the client source addresses from this new provider. as the loadbalancer does not "hide" the client IP's. I would then have to add static routers toward the new context - I would want to skip that.
 
is there a way, to make the loadbalancer hide the client addresses towards the rservers ? perhaps I'm just needing the correct search term to find the config example.

View 1 Replies View Related

Cisco Application :: Configure ACE 4710 For Load Balancing Speech Servers?

Sep 18, 2012

I'm configuring ACE 4710's for the first time and I want to load balance my Nuance speech servers on port 554. Here's my configuration on ACE01:
 
[code].....

View 23 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Load Balancing - TACACS+ NAS IP Address?

Jun 26, 2012

I'm currently evaluating a scenario where AAA request are load balanced across multiple ACS 5.3 instances. The application delivery controller runs in L3 mode, which naturally causes the original packet's source IP address to be replaced by a randomly selected proxy address.As far as RADIUS is concerned, I can perfectly determine the originating NAS by means of a 'Device Filter' condition. Unfortunately, ACS seems to lack the possibility of achieving the same for TACACS+. According to the user manual, only the actual IP address from the received packet is taken into account. I've also come across the 'NAS-Address' attribute in the protocol dictionary, but it can't be used in a custom condition either.how to retrieve the initial device IP address from a TACACS+ request in order to use it for further policing?

View 8 Replies View Related

Cisco Application :: CSS 11503 - Server-to-server Load Balancing?

Feb 16, 2012

I'm trying to design a CSS configuration that allows servers in the same vlan to be the source and destination of load-balanced traffic. My thought is to add two new vlans, one for the VIPs and one for the servers, then NAT the source IPs going from the LB to the servers.
 
Is this the right way to do it?I've never NATted using CSSs, so I wanted to verify what I'm thinking.Our current config trunks the vlans -
 
interface 1/1
   trunk
   vlan 1
    default-vlan
  vlan 555

[code]....

View 3 Replies View Related

Cisco Application :: Clear Stickies On CSS 11501 By VIP?

Jan 30, 2012

it's possible to clear stickies per VIP?  The firmware is 08.20

View 2 Replies View Related

Cisco Application :: Slow Download Via SSL In CSS 11501

Nov 27, 2011

I have 2 CSS 11501 providing load-balancing rules and SSL termination. When CSS is used for downloading through the rules of SSL, the rates I get are quite lower than those obtained when the download is done either directly on the machine or by using the rules of HTTP. Is it normal? Is there anything that canspeed up this process?

View 2 Replies View Related

Cisco Application :: How To Enable Snmp On Css 11501

Feb 13, 2012

i need to enable snmp on Cisco CSS 11501. 

View 1 Replies View Related

Cisco Application :: SSO (Single Sign-on) Through CSS 11501?

Nov 22, 2011

I am load balancing Terminal Server Windows 2008 sessions with an CSS 11501. The code version is sg0750004 (07.50.0.04). I am trying to establish a Terminal Server session with Single Sign-On (SSO), but without success. Normal login with Username and Password on the TS are functionning, but never SSO session. The environment is: 10 Windows 2008 Terminal Servers (NTS1, NTS2,NTS3...). In DNS I have a host A named TS with IP for balanced CSS. The problem I see is that the client PC opens a TS session to "TS". then dont work SSO, but if client PC open a TS session to NTS1, NTS2...is working fine the SSO I am not sur if we can do something on the CSS.

View 3 Replies View Related

Cisco Application :: How To Test CSS 11501 Failover

Aug 7, 2012

I have 2 CSS, 1 as primary and 2nd as standby. I configured the standby CSS as my old standby CSS box and now wanted to test the faliover. I am not aware of how to test it in. ny how i have cr for that.

View 1 Replies View Related

Cisco Application :: CSS 11501 Not Dropping Flows If Service Is Down

Oct 14, 2012

some misconfiguration (?) may be the reason for an undesired behaviour we are experiencing with our Cisco CSS 11501s. Balancing mechanisms work fine, however if a service transitions to the "down" state, the corresponding flows remain "alive" leading to a temporary outage of our service. Subsequent client requests are still being sent to the "down" frontend which is unresponsive.

View 4 Replies View Related

Cisco Application :: Active CSS 11501 Telnet And Console Not Working?

Mar 31, 2013

implementation of the cisco CSS 11501 boxes available as spare on our site into production for an application evry thing worked as expected. i was able to telnet the active/master box and was able to console both master and backup box from the console port.however a week post the activity im faced with this weird problem where im not able to take console or the telnet access of my primary/active box.The boxes are working in BOX-to-BOX redundancy and now im not able to telnet or console my active/master box. The telnet and console window prompts me for username and password and after entering the credentials nothing happens. no prompt or no error message is displayed.

The telnet primary authentication is via tacacs and secondary is via local. however for console im not using any method for primay authentication and local for secondary authentication. however i can successfully console my backup box. below are my obsrvations 1. the left and right status LED on the active CSS box is OFF.- it means my CSS 11501 failed and has no power. 2. upon firing the rcmd command with show line command on backup box i see that the telnet sessions and console session is established with the master box3. the redundancy state of the active box says it is master and has not changed state since my last activity, no application issue reported, all the services are active on the active box and also i can ping the active box ip address from my backup box over which box to box redundancy is established. This confirms the active box is functioning well 4. i initially thought the telnet sessions are not getting cleared, however the show line cmd with the rcmd cmd on the backup box confirms this is not happening. now im stuck as the active box cannot be accessed at all via console or telnet. i was thinking of below steps to be carried out.1. to failover the boxes and make the backup as master2. then try to take the faulty box off the network and troubleshoot (are there any other commands that i should use to troubleshoot)3. if nothing works try rebooting the box and check
 
NOTE: the software running is version 7.20.30.3 with standard feature set. we are not using cvdm or the CSS GUI. we could access the css initially on CSS gui and that is also not working now.

View 1 Replies View Related

Cisco Application :: 11501 Ftp Server Setup Using Non-standard Port?

Dec 13, 2011

we would like to setup FTP server over CSS where our member sever use non-std-port to open both control/data channel (i.e. 6370 as ctrl and 6369 as data this case.) but seems we only get Passive mode FTP mode work only but not for Active mode FTP case for data channel establishement for server back to client..
 
#  sh ver
Version:               sg0820501 (08.20.5.01)
Flash (Locked):        08.10.1.06
Flash (Operational):   08.20.5.01
Type:                  PRIMARY
Licensed Cmd Set(s):   Standard Feature Set

[code]....

View 3 Replies View Related

Cisco Application :: CSS 11501 - Wildcard Certificate With Subject Alternative Names

Sep 6, 2012

I generated a wildcard certificate for my company type *. [URL] in a CSS 11501. For the site [URL] worked fine, for the site [URL] didn't worked. I read on the web that should generate a wildcard certificate with subject alternative names. Is it possible in CSS? how can I do it?

View 5 Replies View Related

Cisco Application Networking :: CSS 11501 Reboots When Making Change To Global Keepalive?

May 17, 2010

I've got an issue with a CSS 11501 where, if *any* change is made to a global keepalive (active), the device reboots. The code is 08.10.2.05. I'm unable to search the TAC archive or I would've gone there first.

View 2 Replies View Related

Cisco Application :: Content Switch 11501 / 11503 Abnormal Interface Link Down?

Mar 27, 2013

I have 2 pair of 11501 switches and 1 pair of 11503 switches on 3 sites(LA, China, Taiwan).Each site has a pair of 1105x switch running as redundancy between them and is a standalone which will not interact with others.Recently a series of interfaces(ports) down happened to every active 1150x switches without any reason and log.Especially today, it happened to active switches at 5:39 AM meanwhile on 3 sites.

View 3 Replies View Related

Cisco Application :: Sample Command Output Of Show Chassis Inventory For CSS 11501 / 11503 / 11506?

Oct 30, 2011

I am trying to get a sample command output of "show chassis inventory" for:

CSS 11501
CSS 11503
CSS 11506

View 1 Replies View Related

Cisco WAN :: ASR1001 / L2 Over L3 With Load-balancing?

Nov 30, 2011

i'm trying to accomplish the following:I want to trasport a bunch of vlan layer 2 etherchannel on a pair of layer3 connections, using L3 to load balance.i was considering a pair of options:
 
1) bridging + gre (non applicable since i cant bridge 2 interface beloging to a etherchannel to a tunnel)
 
2) L2TP is it possible to accomplish this with the above tecnology? any reference, configuration example?
 
3) AoMLPS is it possible to accomplish this with the above tecnology ? any reference, configuration example?
 
I cant modify topology, the routers used are ASR1001 It is mandatory that both sites have a layer2 connection between them.

View 1 Replies View Related

Cisco WAN :: 2811 DSL Load Balancing

Dec 9, 2010

I have a Cisco 2811 router with two HWIC-ADSL cards configured for dsl connection. I have two lines from the same ISP and i am load balancing between them. I have created a couple of SLA's to check the state of the connections and add to the routing table the two default routes if both are up or any one of them is up.My problem is that when i  try to download big files (especially antivirus updates) the download at some point stops (especially the antivirus exits with an error of unreachability). If i shut down one line everything works fine.Could i use something (configuration-wise) to prevent this problem from happening?????Is there any way i can combine the two lines? They are simple ADSL connctions with static ip's.

View 8 Replies View Related

Cisco WAN :: Load Balancing On ASR1002?

Jun 25, 2012

One of our customer just purchased ASR1002 router, they have three internet links from different ISPs and they dont have any remote site, they have three different public IP pool as their respective ISPs. So, is it possible to load balance the internet traffic using all three link on Cisco ASR router ( IOS - Advance Enterprise Services)

View 3 Replies View Related

Cisco WAN :: 4506-E DSL Load Balancing

Jun 10, 2012

I need to configure DSL Load Balancing on Core Cisco Switch 4506-E. I have a Router Cisco 2811 with 2GE Ports and a Firewall Cisco ASA5505. I have 8 Physical DSL Connections with 1Mb each. I need to combine that 8 Mb on Core Switch and allow each end user to access the Internet via the available DSL connection which means that every user has 8 Mb available.

View 7 Replies View Related

Cisco VPN :: Load Balancing ASA 5520

Sep 13, 2011

We have an ASA5520 pair that we will be installing to load balance SSLVPN connections.  Below is a portion of our configs pertaining to the VPN load-balancing feature (configured on both ASAs):My specific question is related to routing of return traffic to load-balanced VPN sessions.  Is there some kind of persistence function that tells the return traffic which ASA to route back to?  For instance, if ASA1 has a VPN connection having IP address 10.211.112.1 associated to it, and ASA2 has a VPN connection having IP address 10.211.112.100, how does the return traffic for each connection know which ASA to route back to?

View 1 Replies View Related

Cisco VPN :: Load Balancing ASA 5510

Sep 13, 2011

Currently we have deployed site to site vpn between 2 asa 5510 model. one is corporate site and one is remote site. now we plan to use radware load balancer in which 2 isp will terminate. now if at a remote site wecreate only 1 ipsec tunnel and mention sigle isp peering. if one isp fails at corporate how remote site will be access by site to site vpn through 2 isp vpn. what thing we need to do over asa as well as load balancer at both end.

View 6 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved