Cisco Application :: Content Switch 11501 / 11503 Abnormal Interface Link Down?

Mar 27, 2013

I have 2 pair of 11501 switches and 1 pair of 11503 switches on 3 sites(LA, China, Taiwan).Each site has a pair of 1105x switch running as redundancy between them and is a standalone which will not interact with others.Recently a series of interfaces(ports) down happened to every active 1150x switches without any reason and log.Especially today, it happened to active switches at 5:39 AM meanwhile on 3 sites.

View 3 Replies


ADVERTISEMENT

Cisco Application :: CSS 11503 - Multiple Content Groups?

Oct 4, 2011

I currently have a content group as follows;
 
content My_Group
add service blade1
add service blade2
add service blade3
vip address 1.2.3.4
advanced-balance arrowpoint-cookie

[code]...
 
So I have 3 blades which are proxy servers and user go first to an MS ISA server then the VIP of the CSS and then the rules processes them give them a blade and chuck them out onto the Internet.
 
I want to leave the above rule, but remove one blade create an additional content group with that blade and have it process requests for a particular site so, I would create the following
 
content My_Group2
add service blade3
vip address 1.2.3.4
advanced-balance arrowpoint-cookie

[code]...
 
So my question is can I do that having the same VIP's etc so if a request comes in and it matches www.thewebsite.com that the second content rule matches it 'better' and therefore processes it or would it still be caught by the "/*" content group. I don't want to create more VIPS as I have a real ache getting firewall rules done.

View 9 Replies View Related

Cisco Application :: Sample Command Output Of Show Chassis Inventory For CSS 11501 / 11503 / 11506?

Oct 30, 2011

I am trying to get a sample command output of "show chassis inventory" for:

CSS 11501
CSS 11503
CSS 11506

View 1 Replies View Related

Cisco Application :: CSS 11503 - Layer 5 Content Rule Match Wildcard And Suffix

Oct 2, 2011

Is it possible on the CSS11503 to create a layer 5 content rule that matches a url "/*/_edit".

View 3 Replies View Related

Cisco Application :: To Enable SSL3 On Content Switch

May 23, 2011

I had meeting with security auditor for a customer, he told me that  i need to enable SSL3 on content switch as his scanning found that all network is working on SSL2.I could not understand his view and then when i found the content switch documentation, it is mentioned that SSL3 is default enable on content switch."By default, the SSL version is SSL version 3 and TLS version 1. The SSL module sends a ClientHello that has an SSL version 3 header with the ClientHello message set to TLS version 1." Do i have to do some kind of configuration to enable SSL3 or its enable by default ?

View 3 Replies View Related

Cisco Switching / Routing :: CSS 11501 - Contact Content VIP On Same Subnet

Feb 5, 2013

I have an issue with the device in subject. I need that some server, listed as service on CSS, can contact a content VIP on the same subnet. To allow that traffic I configured grouping on CSS (group 1) with vip address and an ACL that allow traffic from subnet 10.1.1.0/24 toward same subnet 10.1.1.0/24 and I have bound this ACL with sourcegroup  1. The nat and portmap works but never at first attempt, instead since second attempts it works. Seem like a CSS require to much time to create nat entry.

View 4 Replies View Related

Cisco Switching/Routing :: CSS 11501 - Configuring CSS Content / Load Balancing

Feb 3, 2012

I would like configure a CSS content, that uses the sorry service principal in an advanced way.

I am familiar with the primary Sorry Server command and see that the CSS would send all connections to the named service that is configured as the primary Sorry Server.

What I would like to do is to configure the CSS, so that once it’s decided it’s in a “sorry” state (all the services that are configured with “add service” are down) that it load balances to a different set of services.

To explain what I’ve been trying to do in the form of configuration on the CSS, I’ve pasted some pretend config below.

Connections come into IP address 1.1.1.1, which normally get load balanced between  9.1.1.1, 9.1.1.2 and 9.1.1.3.

If 9.1.1.1, 9.1.1.2 and 9.1.1.3 are all down, the sorry service is used and the CSS starts passing traffic to 1.1.2.1, which I want it to load balance between  9.1.2.1, 9.1.2.2 and 9.1.2.3.

The order that I have applied the config, is different to the below, as I set out to configure in this order: secondary services, secondary content, sorry service, primary services, primary content.

The order of the config below is different, because I wanted it in the order that the traffic flows and the CSS won’t take the config in that order!

The wall I have ran into, is that when I try to create the service I have named “Sorry Service”, I get the following error:

%% Service IP Address conflicts with a local I/F, VIP, mg mt route.

[Code] .....

View 0 Replies View Related

Cisco Application :: CSS 11503 Ether-channel Configuration For Redundant Server Link

Jun 18, 2011

I have already raised this discussion on "LAN, Switching and Routing" group. But I guess this is the right group for my queries. So I am sending my queries in this group again.
 
We are using CSS 11503 with one 16FE line card. We have connected 3 servers with redundant link. So FE1-2 in Server1, FE 3-4 in Server2 and FE5-6 in Server3. Our system team has configured APA in their servers as they are using HP-Ux.
 
1) Do we need to do any configuration at line card.

2) Do we need to do ether-channel at loadbalancer end. if yes, can you share me any cisco doc on how to do it.

View 1 Replies View Related

Cisco Application :: XFF On CSS 11503?

Aug 1, 2011

Is the XFF [URL] on the Cisco CSS 11503?  If not, is it on the roadmap for a future code release?

View 1 Replies View Related

Cisco Application :: Clear Stickies On CSS 11501 By VIP?

Jan 30, 2012

it's possible to clear stickies per VIP?  The firmware is 08.20

View 2 Replies View Related

Cisco Application :: Slow Download Via SSL In CSS 11501

Nov 27, 2011

I have 2 CSS 11501 providing load-balancing rules and SSL termination. When CSS is used for downloading through the rules of SSL, the rates I get are quite lower than those obtained when the download is done either directly on the machine or by using the rules of HTTP. Is it normal? Is there anything that canspeed up this process?

View 2 Replies View Related

Cisco Application :: How To Enable Snmp On Css 11501

Feb 13, 2012

i need to enable snmp on Cisco CSS 11501. 

View 1 Replies View Related

Cisco Application :: SSO (Single Sign-on) Through CSS 11501?

Nov 22, 2011

I am load balancing Terminal Server Windows 2008 sessions with an CSS 11501. The code version is sg0750004 (07.50.0.04). I am trying to establish a Terminal Server session with Single Sign-On (SSO), but without success. Normal login with Username and Password on the TS are functionning, but never SSO session. The environment is: 10 Windows 2008 Terminal Servers (NTS1, NTS2,NTS3...). In DNS I have a host A named TS with IP for balanced CSS. The problem I see is that the client PC opens a TS session to "TS". then dont work SSO, but if client PC open a TS session to NTS1, NTS2...is working fine the SSO I am not sur if we can do something on the CSS.

View 3 Replies View Related

Cisco Application :: How To Test CSS 11501 Failover

Aug 7, 2012

I have 2 CSS, 1 as primary and 2nd as standby. I configured the standby CSS as my old standby CSS box and now wanted to test the faliover. I am not aware of how to test it in. ny how i have cr for that.

View 1 Replies View Related

Cisco Application :: MIB Objects For CSS 11503?

Jun 9, 2009

i need the MIB object names for monitoring the processor and Memory Utilization of CSS 11503 with software version 7.50 Where can I find it?

View 5 Replies View Related

Cisco Application :: CSS 11501 Not Dropping Flows If Service Is Down

Oct 14, 2012

some misconfiguration (?) may be the reason for an undesired behaviour we are experiencing with our Cisco CSS 11501s. Balancing mechanisms work fine, however if a service transitions to the "down" state, the corresponding flows remain "alive" leading to a temporary outage of our service. Subsequent client requests are still being sent to the "down" frontend which is unresponsive.

View 4 Replies View Related

Cisco Application :: 11503 CSS HTTP Redirects

Jul 19, 2011

I have a number of web sites that are currently being load balanced by CSS 11503s runninng 8x code.  I was recently requested to configure HTTP -->  HTTPS redirects on the CSS for every site.  In the past, I have only configured the redirects for sites that had a requirement.  Now it appears that the server teams want all content encrypted.

1)  What impact will this have on the CPU?
2)  What impact will this have on Memory utilization?
3)  Is there a maximum nubmer on redirects?
4)  Are there other things I should be concerned about?

View 3 Replies View Related

Cisco Application :: CSS 11503 SSL Service Suspended

Mar 24, 2013

i have two CSS-11503 in redundant mode running 8.20 code.  We had an incident in our network where a layer 2 loop caused some high traffic through the CSS' and had to shutdown some network gear(including the CSS) to clear the problem.  When the CSS' were powered back up, the SSL service was suspended, why this would occur?  There rest of the config appeared normal. I am the only person on these boxes, the configs were written, and I have never had a reason to suspend the ssl service.

View 1 Replies View Related

Cisco Application Networking :: CSS 11503 And SAN Cert

Oct 14, 2012

I know that CSRs cannot be generated with multiple names, but if the SAN is added after the cert is ordered from Geo Trust, Veri sign, etc. can the CSS support using the cert?

View 1 Replies View Related

Cisco Application :: CSS 11501 Load Balancing With X-forwarded For Address

Sep 15, 2011

We have a pair of CSS 11501,Currently it is using source ip for load balancing and 5 servers as backend , however we have users loggin in using http and based on its source IP (ISP PROXY) , it is forwarded to SERVER A.However, we have a SSL page and when the client switches over to SSL , it is forwarded to SERVER B/C/D/E  based on its source IP ( REAL CLIENT IP) .This will cause the user to be terminated as the 5 servers are independent and not running in a cluster.
 
Is there any way that we can use the X-Forwarded-For address to load balance so that when users loging , they are sent to SERVER A (Based on X-Forwarded-For Header IP which translate to REAL CLIENT IP).This way we are able to also send it back to the same server when it uses SSL.I believe that we should be able to load balance using X-Forwarded-For IP or to rewrite the X-Forwarded-For IP into client source IP.

View 3 Replies View Related

Cisco Application :: Active CSS 11501 Telnet And Console Not Working?

Mar 31, 2013

implementation of the cisco CSS 11501 boxes available as spare on our site into production for an application evry thing worked as expected. i was able to telnet the active/master box and was able to console both master and backup box from the console port.however a week post the activity im faced with this weird problem where im not able to take console or the telnet access of my primary/active box.The boxes are working in BOX-to-BOX redundancy and now im not able to telnet or console my active/master box. The telnet and console window prompts me for username and password and after entering the credentials nothing happens. no prompt or no error message is displayed.

The telnet primary authentication is via tacacs and secondary is via local. however for console im not using any method for primay authentication and local for secondary authentication. however i can successfully console my backup box. below are my obsrvations 1. the left and right status LED on the active CSS box is OFF.- it means my CSS 11501 failed and has no power. 2. upon firing the rcmd command with show line command on backup box i see that the telnet sessions and console session is established with the master box3. the redundancy state of the active box says it is master and has not changed state since my last activity, no application issue reported, all the services are active on the active box and also i can ping the active box ip address from my backup box over which box to box redundancy is established. This confirms the active box is functioning well 4. i initially thought the telnet sessions are not getting cleared, however the show line cmd with the rcmd cmd on the backup box confirms this is not happening. now im stuck as the active box cannot be accessed at all via console or telnet. i was thinking of below steps to be carried out.1. to failover the boxes and make the backup as master2. then try to take the faulty box off the network and troubleshoot (are there any other commands that i should use to troubleshoot)3. if nothing works try rebooting the box and check
 
NOTE: the software running is version 7.20.30.3 with standard feature set. we are not using cvdm or the CSS GUI. we could access the css initially on CSS gui and that is also not working now.

View 1 Replies View Related

Cisco Application :: 11501 Ftp Server Setup Using Non-standard Port?

Dec 13, 2011

we would like to setup FTP server over CSS where our member sever use non-std-port to open both control/data channel (i.e. 6370 as ctrl and 6369 as data this case.) but seems we only get Passive mode FTP mode work only but not for Active mode FTP case for data channel establishement for server back to client..
 
#  sh ver
Version:               sg0820501 (08.20.5.01)
Flash (Locked):        08.10.1.06
Flash (Operational):   08.20.5.01
Type:                  PRIMARY
Licensed Cmd Set(s):   Standard Feature Set

[code]....

View 3 Replies View Related

Cisco Application :: Transferring Existing SSL Certificate From 11503 To ACE?

Jun 2, 2012

We now have a new requirement . We are replacing existing pair of CSS with ACE 4710 appliances. The problem here is that I can see from the configuration that  some SSL certificate installed in CSS .Is it possible to transfer the existing SSL certificate from the 11503 to the ACE? Or, do we need to generate a new key pair and CSR on the ACE?  Is there any document available to know the steps for the same.

View 2 Replies View Related

Cisco Application :: Several Pairs Of CSS11501 And 11503 In Network

May 21, 2012

We have several pairs of CSS11501 and 11503 in our network.This issue affects only one pair of CSS11503 in one of our data centres. [code] We use vrrp in one-armed mode for load balancing and they units have performed great for a number of years. We're obviously going to be migrating to ACE ... but not just yet.We have started to experience a problem with replicating the configurations between two CSS11503 in a pair.When running the commit-VipRedundConfig, it starts off happily enough, though slowly.Ending with "working" and the spinning cursor, even after 1 hour the script hasn't completed.We noted on the backup CSS that the APP configuration disappears during the process and I can't remember if this is normal behaviour.
 
Re-adding the app session configuration seems to interrupt the process, and when checking the configuration on the backup CSS approximately half of it is missing. Everything after the first owner is gone.

1. Configuration is too large, or just large enough to make the commit script take too long for realistic service.
2. Software bug?
3. Combination of both.
4. From now on manually add config to both CSS's and maintain it by process management.

View 5 Replies View Related

Cisco Application :: CSS 11503 Session Stickiness Configuration

Sep 17, 2012

I only have configured load balancing on apache with a very simple setup. I have to deploy 2 applications on my clients environment that run inside jboss. One of these applications needs session to be sticky to work properly. The other does not.
 
In apache I can configure is the sticky parameter is true or false, based on the url, like /appA/* is sticky and /appB/* is not sticky. Can I do that in a CSS 11503? My client insists that it is impossible. That the CSS is only ip based.
 
I copied the configuration below from the manual: owner arrowpoint # content ruleWapSticky

View 14 Replies View Related

Cisco Application :: CSS 11503 V ACE 4710 Performance Comparison

Mar 20, 2012

Am trying to verify performance figures for ACE 4710 as EOL replacement for a CSS 11503 Am sure that the ACE 4710 smokes the CSS but have to complete the due diligence
 
Pulling figures from data sheets, release notes etc.. I have only come up with the followingIs there any further figures available for the ACE 4710 to fill in the blanks in table?

View 1 Replies View Related

Cisco Application :: 11503 Ping For One Virtual Host

Apr 27, 2013

I have a single  cisco 11503 load balancer.There is a single Banner student information system which is load balanced on it with Virtual ip 10.3.20.101 which is working fine without any issues .I am now trying to add an Oracle ERP application with virtual IP 10.3.20.230 and physical ips 10.3.19.22 and 10.3.19.23 all on port 8003.When I just make the group  ERP-Apps-Grp active , the vitual ip address 10.3.20.230 is pingable , but when I make the  the content Erp_IAT active  it stops pinging. [code]

View 6 Replies View Related

Cisco Application :: Passdetect Command Equivalent In CSS 11503?

Sep 11, 2011

what is the "passdetect" command equivalent in CSS 11503 load balancer. software version 8.20.

View 3 Replies View Related

Cisco Application :: Hairpinning On CSS 11503 When Using Source Groups?

Jun 26, 2011

I'm not sure if my terminology is correct when using hairpinning but i was wondering if there is any special config needed when you try to access a content rule VIP from a server that's configured as a member of a source group on the same CSS?
 
So say i have a content rule with a VIP 20.20.20.20 and i also have two servers 192.168.1.1 and 192.168.1.2 that are part of a source group with VIP of 20.20.20.21. My problem at the moment is if from the servers 192.168.1.x i try to ping the other VIP 20.20.20.20 that's configured on the same CSS then it doesn't work and ping fails. The same happens with HTTP traffic to the 20.20.20.20 VIP.
 
I would have thought that the NAT of the source group would happen before the routing so the 192.168.1.x IP's would be natted to 20.20.20.21 and then passed over for routing where the CSS would see that the VIP 20.20.20.20 is local and it would send it on it's way.
 
I thought it might be ACL related but i increased the verbosity of acl logging and couldn't see anything in the logs.The source group works fine on it's own and from the CSS itself i can ping the 20.20.20.20 VIP fine. It just seems that from the source group members i can't ping the VIP.

View 1 Replies View Related

Cisco Application :: CSS 11501 - Wildcard Certificate With Subject Alternative Names

Sep 6, 2012

I generated a wildcard certificate for my company type *. [URL] in a CSS 11501. For the site [URL] worked fine, for the site [URL] didn't worked. I read on the web that should generate a wildcard certificate with subject alternative names. Is it possible in CSS? how can I do it?

View 5 Replies View Related

Cisco Application :: How To Monitor Status Of Vips On 11503 Through SNMP

Sep 26, 2011

what is the OID  for See the hit status of the spefic VIP and  RIP coming under the VIP .apeart from this  CSS box having any module to moniter the hit status or VIP's and RIP's

View 2 Replies View Related

Cisco Application Networking :: CSS 11501 Reboots When Making Change To Global Keepalive?

May 17, 2010

I've got an issue with a CSS 11501 where, if *any* change is made to a global keepalive (active), the device reboots. The code is 08.10.2.05. I'm unable to search the TAC archive or I would've gone there first.

View 2 Replies View Related

Cisco Application :: CSS 11503 HTTP Keepalive Fails Even Though Server Responds

Nov 29, 2011

I recently "inherited" a CSS 11503 - I've only used ACEs before - and I want to get HTTP keepalives working.To start, I created a test service:
 
lb-1# show run service sunbird-http-7025-test
!************************** SERVICE **************************
service sunbird-http-7025-test
  port 7025
  ip address 141.211.229.168

[code].....

View 2 Replies View Related







Copyrights 2005-15 www.BigResource.com, All rights reserved