Cisco Application :: Slow HTTPs Response Time Through CSS After Applying KB2585542?

Feb 9, 2012

Having issues with HTTPS sites being very slow after applying KB2585542? Once you remove this Microsoft patch everything returns to normal.   It appears that the CSS does not handle the split-ssl requests properly.  I have opened a TAC case but am not really getting anywhere as we seem to be the only company that is having this issue.

View 2 Replies


Cisco Firewall :: ASA 5510 - Response Is Very Slow While Applying ACL

Nov 27, 2012

I am managing a firewall over remotely in my LAN itself. I started a continous ping to the Firewall IP and the response is less than 1 ms.
While applying some access control list to the firewall via putty ...Suddenly the latency is going hing and it is hitting xxxx ms. And also the acl are getting pasted on the screen by word by word. Sometimes i used to get some RTO for the Firewall IP Address inth eping response.
find the Firewall Version:
Cisco ASA 5510
Version : 7.2
Having more than 600 ACL's.

View 4 Replies View Related

Linksys Wireless Router :: E3200 Ping Is Getting Slow TTL Response During Time

Nov 9, 2012

Each time I'm rebooting my E3200 device my ping to my ISP is 20ms. Few hours later the ping goes up to 300-500ms.Than I reboot again and the ping is going down to 20ms again.

View 5 Replies View Related

Cisco Application Networking :: Int827 / Applying ACE Connection Parameter Map?

Oct 24, 2011

How do I apply the connection parameter map in a configuration like this to the service policy int827?  Do I need to define the traffic?  Can I specify only one source destination flow to apply the set tcp half-closed TCP normalization against?
policy-map type loadbalance first-match wss-1100-l7slb
class class-default
sticky-serverfarm sticky-srcip-1100
policy-map type loadbalance first-match wss-1101-l7slb
class class-default
sticky-serverfarm sticky-srcip-1101


View 1 Replies View Related

Cisco Application :: Ace 4710 Response Sticky Only

Dec 15, 2011

I've been using my pair of ACE-4710s for quite some time and have usually stuck to the Class C Subnet sticky settings, as that's what we migrated from in Windows NLB.  In one instance of load balancing I'm trying to create an L4 inspection policy that looks for a certain payload (much like a http header) and would like to persist on this.  The problem is that the client portion of the conversation starts with a 'SessionID' of 0, and the server responds with a unique 'SessionID'.  If I setup the sticky policy with 'Enable Sticky For Response', I get entries populated in the sticky database, but they all go to the same server as there is a sticky session setup for the SessionID = 0.  Is there a way to setup sticky entries on server response only.Currently using ACE DM v4(1.0).

View 8 Replies View Related

Cisco Switching/Routing :: Track Down An Application Response

Nov 28, 2012

I am trying to track down an application response problem on my network (the traffic goes through a 6509 and FWSM).I noticed in one of my WireShark captures, that the client at times seems to be sending ackowledgements (ACKs) over and over again, and I'm not sure if this indicates a problem/ retransmission.
 Basically, a web server is delivering images to the client, but end users are complaining of slowness and freezes.Wire-Shark has not flagged this as a problem (comes up "green")

View 2 Replies View Related

Cisco Routers :: SA520W Response Time In Replacing A Defective Unit

Apr 17, 2013

Our company just recently bought a CISCO SA520W Security Appliance from a distributor here in the Philippines.  Unfortunately, after a month of use, the LAN ports on the appliance started losing power.  We reported this to the distributor and they sent a CISCO engineers to check on the unit.  The engineers found the unit to be defective and need to be replaced.
Three weeks after the distributor pulled-out the unit, I have followed-up the status with them.  They told me that they got no definite ETA from CISCO for the replacement unit.  I followed-up with them again after a week.  This time, they told me that the device is already in transit and it is coming from CISCO USA but they still don't have an expected time of arrival to give me.Does it really take more than a month for CISCO to replace a brand new defective unit? The serial number of our appliance is DNI1610G0G7.

View 1 Replies View Related

Linksys Wireless Router :: WRT160N Ping Response Time?

Aug 31, 2009

I have a brand-new WRT160N router (just installed FW v3.0.02) that I am using in mixed mode, 20MHz only, Channel 11, not filtering anonymous requests, beacon at 2306, RTS at 2307, fragmentation at 2346, MTU at 1400.
These settings bring the response from a simple ping command over the wireless network down to approximately 6ms on average, which is good. However, when I still noticed inconsistency with my internet response over wireless, I decided to do a test. 
By simply running the "ping" command on (the router address) over the wireless network repeatedly (approx 3 seconds between commands), I can see that approximately every 65 seconds or so, router response time increases to over 100ms for a few seconds, then decreases down to 6 ms or so for another 65-70 seconds. See the chart below. The interval looks pretty consistent to me, with the exception of one stretch where it goes for over two minutes without a spike. I see this pattern regardless of what else I'm doing over the network. I do not see this behavior running the same test when physically wired to the router (ping response time is a flat line at 0ms).

View 4 Replies View Related

Cisco Switching/Routing :: ICMP High Response Time To SVI Interface 3750X

Mar 13, 2011

I am in the process of installing a 3750x (IOS 12.2 (53r) SE2 IP Base) Cisco Catalyst switch in a new network of just 2 PC's (2 hosts, OS windows7 64Bits). I have enabled SVI interfaces with the both hosts installed in 2 different network segments.  We then start connectivity test.  The response time for the PING command between both hosts remain below 1 millisecond, whereas the response time between the hosts and their correspondent SVI interface is variable, and at all time is higher than 1 millisecond, sometimes it reaches 17 milliseconds. (Note that the switch CPU usage is only 8% at the time of testing)  We have performed this same connectivity test changing the 3750x switches  and in two different locations obtaining the same results. 

View 2 Replies View Related

Cisco Application Networking :: ACE 4710 - How To Configure HTTP Rewrite Request / Response

Sep 18, 2011

We want to mask part of the path prefix to hide development content: For example: the site(s) are: [URL]However we don't want anything with acme we would want the loadbalanced url to be: [URL] ...for requests and responses. I think this would be an http re-write request/response scenario?Is this possible to configure this on the ACE Device? We've got the load balance configuration down...not sure how to do this re-write type scenario?

View 2 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.3 Slow CLI Response After Implementing TACACS

Sep 30, 2012

After implementing TACACS, one of our routers takes about 8 seconds to response to any CLI command. We have no problems with other devices in the same location with the same AAA configuration. The router is talking to the ACS server (ACS 5.3) and the logs on the ACS server look normal for the router as well.

View 5 Replies View Related

Cisco WAN :: Periodic Slow Response 2821 (300+ms / 1 Minute)?

Mar 10, 2011

Periodic Slow Response 2821 (300+ms, 1 minute) My solarwinds NPM reports very slow response times from my satellite clinic.Often times it is 300ms to 600ms when it should be 10-15ms. CPU does not seems to spike, the memmory does not seem to spike The bandwidth does not spike.It happens mostly during work hours about 10 times a day Solarwinds reports the delay and then 2 minutes later it reports normal activity
I have broadcast/multicast control on the switches? We have static route for our network meaning no routing protocols ?We have 12 other clinics with the same configs and they are fine?I have double checked the configs but I am not holding my breath on that item?I have rebooted the router without affect
I have not replaced the cable to the demarc on either side of the WAN connection?I have not reseated the service provider T1 cards?I have not reseated the T1 card on either router.

View 1 Replies View Related

D-Link DIR-615 :: Slow Response Commands In FIFA

Jul 13, 2012

I'm using a cable connection with my router and most of the time I'm playing FIFA12 on PS3 i feel like the commands takes a second to respond, like if was a delay. I tried most of everything in firewall settings, port foward, internet settings...

View 4 Replies View Related

Cisco Switching/Routing :: WS-C3750G-24TS-S1U Slow Response Between VLAN’s

Jan 20, 2013

Inter-VLAN applications are slow and same VLAN it is working fine.(i.e.VLAN to VLAN applications and File transfer response was Slow).Switch Model number: WS-C3750G-24TS-S1U

View 3 Replies View Related

Cisco AAA/Identity/Nac :: ACS 5.1 - Can't Contact AD Server Slow TACACS Auth Response

Sep 28, 2011

Running ACS 5.1 appliance, and am seeing slow repsonse on TACACS authentications due to the ACS trying to reach overseas AD servers and failing.  Is there any way to configure a /etc/host/ file locally on the ACS in order to force the appliance to use specific AD servers for authentication?  As I understand the process currently, the ACS appliance will query the top-level domain and get a list of all the AD servers in DNS.  In my case, this would include the AD servers overseas that we do not want to use.

View 1 Replies View Related

D-Link DIR-655 :: Wireless Network Gets Slow Time To Time

Sep 1, 2011

i have had my dir-655 one year now, have never had wireless problems with it until notebook's internet gets very slow somedays, i just restart my router and then internet speed works normally.i have:

Hardware Version: A4 - Firmware Version: 1.32EU

View 5 Replies View Related

Cisco Application :: ACE 4710 With HTTPS Redirect

Sep 20, 2011

i have ACE 4710 appliance that terminate SSL and the connection to the servers is http.
The ACE (one Armed) is load balancing between two web servers and i am using stickness in order to take the connection on the same server based on cookie.I can access the website either by http or https., where on the web page there is a login credential to access using username and password.
When i access the website using https everything works fine and i can login to my account in https mode.When i access the website through http and login to my account the URL is redirected to https...normal because i am using action-list to rewrite the http into https. But when i exit the browser and access the website again using http it is not redirected to https(although i see that i am still login into my account i can see all the inforamtion in my account).
The customer wants the connection to be https even when i exit the browser and access the website again (within short time before the cookie exipres)

View 3 Replies View Related

Cisco Application :: Accessing ACE30 Through Https For Management

Jun 11, 2012

I am new to the ACE30. I a basic configuration from the CLI and I am trying to use the device manger. I am able to get to the web informational page rather then accessing the login page.    I have rest the password for both the admin and www and still no go. my question is how to go into enabling the GUI access.

View 1 Replies View Related

Cisco Application :: 3500 - Enable XML-HTTPS Protocol In ACE

Mar 9, 2011

I'm configuring ACE to enable the XML-HTTPS interface so I can import it into ANM, when I try to do a "match protocol xml-https any", I get a invalid command detected. When I tab at the match protocol command, I don't see xml-https listed (http, https, icmp, etc. is listed).

View 2 Replies View Related

Cisco Application :: CSS Or ACE 4710 Redirect HTTPS To Http

Feb 27, 2012

For a CSS with a SSL module (performing SSL termination) - is it possible to impliment a redirect on https URL to send to equivalent http URL.If my understanding is correct, the CSS will do SSL termination and then use an http content rule on the resultant http stream as it is recursively handled by the CSS ? This would mean that the SSL module has no way of seeing/acting on layer 5 and above data (i.e. picking up on a specific URL) and can not itself issue a redirect - i.e. you could not associate a redirect statement or service with the following ssl content rule ? [code]The CSS would instead rely on a http content rule to impliment a redirect - i.e. you would have to associate a redirect statement or service to the following http content rule instead?
But if the CSS is already handling traffic for existing url...  traffic that is going to cause a loop when a client goes direct to. url...I realise the requirment is uncommon / a bit convoluted, its one of those don't ask type scenarios - aimed at achieving a specific requirement.Would the ACE 4710 be able to handle such a scenario any differently ?

View 7 Replies View Related

Cisco Application :: ACE 4710 - Redirect HTTP To HTTPS?

Jun 21, 2012

I am trying to make a redirect from http to https. the goal is whenever a user writes in it should be redirected to I am just haveing some trouble making it work.

View 4 Replies View Related

Cisco Application :: How To Configure HTTPS Head On GSS-4492-k9 Ver 3.2 (0)

Jul 3, 2011

I have upgraded gss to version 3.2(0) because I need to track a server that uses only https.I configured a https head KA VIP answer type but the answer never goes on-line.I tried using url... as the VIP address but not go online too.The gss is behind a firewall.I suspected of the firewall but from the gss CLI it seems that the firewall is open for the https traffic: [code]

View 1 Replies View Related

Cisco Application :: ACE 4700 Redirect HTTP To HTTPS?

Feb 6, 2013

How to configure a redirection on the ACE from HTTP to HTTPS using specific URL example [URL] to [URL], the SSL certificates were installed on the servers.

View 7 Replies View Related

Cisco Application :: 6509 Provide Access For Clients Over HTTPS

Jun 15, 2011

I have a ace board(Acsm) in my switch 6509.I need provide access for clients over https, my scenario looks like this post [URL] .But, i have only one interface, and need to configure nat for inbound clients, to access the server with ip address of the interface vlan of my ace(if i set ace gateway in a rserver, the ssl termination works). The Topology is: Client(https) -> Ace(Https) -> Ace(http) -> rserver (http). Need to configuring this nat? I  need that external clients arrive at the server with the ip of the same  network as him, he did not right back the packet to the default  gateway, but the origin of the same network as him, so that the  communication function successfully, end order.

View 1 Replies View Related

Cisco Application :: ACE 4710 HTTPS Load Balance Configuration

Apr 16, 2012

Have two ACE 4710 in HA setup. We would like to setup HTTPS loadbalance(actually just a primary and standby configuration in the serverfarm). Initially this would be for Exchange OWA connections but may expand to more HTTPS connections later. I know there are several ways to do SSL with the ACE( client, server, end-to-end). I am just wanting to know the easiest way to deploy this? Is a certificate always needed on the ACE for each connection? In HA mode would a certificate be needed for both or does it replicate in some way to the other ACE?

View 6 Replies View Related

Cisco Application :: ACE 4710 - Load Balance Https Based On Url

Nov 15, 2011

I am trying to configure ACE 4710 to load balance base on the URL, If it matches the specific URL ( /456/ ), the traffic will be sent to server farm 456 else the traffic will be sent to server farm 123.
I attached an image of the topology.
Ace Config: 
rserver host SRV01_123
ip address


View 4 Replies View Related

Cisco Application :: A3 (1.0) Default HTTPS Inactivity Connection Timeout

Mar 28, 2012

default inactivity connection time out for A3(1.0) So by defult any tcp connection(http or https) will be timed out in an hour. [code]Was this change in the A4(2.0) code or is it still the same? I heard a TAC engg say that default inactivity timeout for http and https are now 5 mins that is 300 seconds.

View 3 Replies View Related

Cisco Application Networking :: GSS-4492-k9 Does GSS HTTP-HEAD Supports Https

Jun 26, 2011

I am configuring a GSS to check an Web server that responds to https requests.I put 443 as the port but I don´t see replies from the server and the Answer Status is always offline.Other servers using http on port 80 are showing OK.The appliance is a GSS-4492-k9 Version 3.1(0).

View 2 Replies View Related

Cisco Application Networking :: ACE20-MOD-K9 HTTPS Probe Failing Randomly

May 13, 2013

I have a physical server running behind the ACE module ACE20-MOD-K9. The Server has several virtual machines. One of that virtual machines, has a WEB SERVER running virtual https servers. For example, server with IP address, has serveral virtual HTTPs servers as of urll... So, if you nslookup the servers, they all respond with IP address. So if I do url...goes to and read the VIRTUAL SERVER config and replies back to the request.Now, I am trying to verify that the TCP connection (443) and the HTTPS server itself is up and running but only for the url... site and not for the other 2.The problem that I am facing is tha the HTTPS probe fails randomly. The TCP probe works fine.

View 1 Replies View Related

Cisco Application :: ACE 4710 - SSL Configuration / (HTTPS) Access To Server Farm

Aug 31, 2011

I have been tasked to provide SSL(HTTPS) access to a server farm that will be accessible from the internet.  Is this the correct guide to follow?
I am assuming I will need to purchase a certificate to import into the load-balance r as well.

View 1 Replies View Related

Cisco Application Networking :: 4710 Appliance / HTTP To HTTPS Redirection URL

Sep 25, 2011

i have a 4710 appliance (one armed) and i am load balancing with two webservers. In the URL, there are links that need to be redirected to https:

i am using the

rserver redirect REDIRECT-TO-HTTPS[URL] 
The https is working but i have a problem. when i access the Main link "first" it is redirected to https to the Main link.But if i access one of the Sublinks directly(without having to click on the main link first) the page is redirected to https but to the Main Link. i have to click the Sublink again in order to get the page.How can i redirect to https and stay on the same page? What might be the general link in the webserver-redirection?

View 4 Replies View Related

Cisco WAN :: HTTPS Traffic Slow Over 877 Router

Feb 12, 2013

I have reconfigured the router from scratch using all sorts of methods and can not work out whats wrong, basically when the client is going to their bank the login screen takes upto a minute to load, and the same with hotmail. However using a cheap billion router these login screens are instant
Checking the CPU usage shows the CPU is hovering around 5-20% at the worst of timesThere is about 10 machines behind this router and they do not do that much intensive work over the link besides Outlook Anywhere (HTTPS)I have put a ACL on the LAN connection to only allow 1 machine in and still no luckI have also updated the IOS to c870-advipservicesk9-mz.124-24.T4.binAll other traffic runs fine over the link and there are no complaints on standard HTTP traffic 

View 3 Replies View Related

Cisco Application :: ACE 4710 Deployment - Load Balance HTTPS Requests From Internet

Oct 17, 2012

I’m looking for some notes from the field guidance here from those that have much more deployment experience.
I have a GSS and an ACE, and its the ACE that's primarily giving me something to think about, in terms of placement and what mode to adopt.
The traffic flow will look loosely like this:-
Physically, it's like this. The RED line denotes a boundary, and pretty much anything North of that is not accessible to us, we simply have a L3 trunk between our switches and "their" switches (S3/S4) and talk using EIGRP.
There are other servers in the top tier, some that also require load balancing, some that don’t. Typically, I want to load balance HTTPS requests from the internet, to one of the 3 servers in the top half.
I’m not sure what mode to select, routed, one arm? What about placement of the ACE? At the moment, I’ve just configured 1/1 on it and made it part of the MG MT VLAN, it's S VI exists on the S1/S2 switches, so I’m open to change as it's still all in the lab. 

View 1 Replies View Related

Copyrights 2005-15, All rights reserved