ACE Strange setup: catch-all rule and no normalization

Hi,
I have the following setup:
                                                Internet
                                                      |
PC1             ACE                 Default Gateway
|                    |                                |
===================================
I need to fullfull 2 requirements for this one-armed setup:
1)     Incoming requests from the Internet must have visibility on the client source-IP. This has been solved by configuring the default GW of the PC1 server pointing to ACE (and not to the Deafult GW) and by not configuring source-NAT (nat dynamic command on the relevant classes).
2)     PC1  must also initiate traffic to the internet using PC1 source address (and not ACE source address). Therefore we configured a catch-all rule that is intercepting this traffic and sending it to the external world via the Default Gateway and also we disabled normalization.
It works, both point 1 and point 2. My questions are:
1)     Have you ever seen such a design in place and it is a supported Cisco design? I.e. Use a catch-all rule to intercept traffic to send it to the default GW, all this configured in a one-armed design like we have.
2)     Do you think it could create a traffic loop if the catch all rule would intercept other  traffic passing via the ACE? In PROD we have different contexts all configured in the same VLANK0 and I guess we should check that any of this traffic is impacted?
Thanks a lot in advance,
Giulio.
ACE1/Microsoft# sh run
Generating configuration....
access-list ALL line 8 extended permit ip any any
rserver host PC1
  ip address 160.213.122.100
  inservice
rserver host Default_Gateway
  ip address 160.213.122.9
  inservice
serverfarm host TO_INTERNET
  transparent
  rserver Default_Gateway
    inservice
serverfarm host macchine
  rserver PC1
    inservice
class-map match-all DEFAULT_VIP
  2 match virtual-address 0.0.0.0 0.0.0.0 any
class-map match-any PC1
  2 match virtual-address 160.213.122.36 tcp any
policy-map type management first-match remote-access
  class class-default
    permit
policy-map type loadbalance first-match GIULIO-l7slb
  class class-default
    serverfarm macchine
policy-map type loadbalance first-match INTERNET
  class class-default
    serverfarm TO_INTERNET
policy-map multi-match PC1_INTERNET_NAT_PMAP
policy-map multi-match POLICY
  class PC1
    loadbalance vip inservice
    loadbalance policy GIULIO-l7slb
    loadbalance vip icmp-reply active
  class DEFAULT_VIP
    loadbalance vip inservice
    loadbalance policy INTERNET
    loadbalance vip icmp-reply
interface vlan 503
  ip address 160.213.122.50 255.255.255.0
  no normalization
  access-group input ALL
  access-group output ALL
  service-policy input POLICY
  service-policy input remote-access
  no shutdown
ip route 0.0.0.0 0.0.0.0 160.213.122.1

Guilio,
I think a "black hole" configuration (match virtual-address 0.0.0.0 0.0.0.0 any) like this, may cause unexpected behavior sooner or later.
I consider an alternate solution would be either to change the design or perhaps apply a x-forward-for feature where you can inject the original source address no matter you apply NAT.
Please this link:
http://www.cisco.com/en/US/products/hw/modules/ps2706/products_configuration_example09186a00809c3041.shtml
GET /header.html HTTP/1.1
x-forward: 172.16.10.221
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, application/x-shockwave-flash, */*
Referer: http://www.cisco.com/
Accept-Language: en-us
Accept-Encoding: gzip, deflate
If-Modified-Since: Fri, 30 Nov 2007 16:59:08 GMT
If-None-Match: "0164b527233c81:767"
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
Host: www.cisco.com
Connection: Keep-Alive
All these queries should be discussed with your Cisco SE or Cisco Partner anyway to have a better approach.
Jorge

Similar Messages

  • Script to change the priorty of all rules and monitors in a Management Pack

    Script to change the priority and severity  of all rules and monitors in a Management Pack in an override MP .We are deploying an MP in production and don't want the helpdesk to take any action on any alerts, so want to set all of them as informational.Once
    they are reviewed then we will delete that override mp
    Can some one help me with a script
     

    Is this MP sealed?  Doesn't really matter..  Unseal the MP if it is sealed.  Now you have access to the RAW XML.  Alert severity and priority have xml tags.  You should be able to do a search and replace and change all the various
    levels (0-3 or whatever they are) to the levels and priority you want.
    Then you can seal the mp with your own key, or just roll it into prod as an unsealed MP.
    This seems, to me, like the quickest and easiest way to make all of these changes at once.  To bulk override everything, not even sure it's still around or even works, there was a tool called Override Explorer, and you could select multiple monitors/events
    and create overrides.  I can't remember very much about the tool because we didn't use it much, but I think it did this with live data, meaning it connected to your management server, and you made the changes in real time.  
    Of course you wouldn't want to do this in production, so do it in a lab, then export the override mp and put it in prod.
    There is probably some snazzy way to do this with PoSh, but I am not aware of any atm.
    Regards, Blake Email: mengotto<at>hotmail.com Blog: http://discussitnow.wordpress.com/ If my response was helpful, please mark it as so, if it answered your question, then please also mark it accordingly. Thank you.

  • Catch all emails and multiply email adresses

    How can you manage multiply email adresses by one user.
    example:
    ROBERT has two email adresses : [email protected] and [email protected]
    these two adresses must be sent from OS X Server to the client 'Robert'.
    And how can you set up 'catch all email' to one specific adres. We would like to deliver all the emails with a different name for the *@domein.com to one client of our OS X Server.
    And is there a way to send one email to multiply users, example:
    email: [email protected] must be sent to [email protected], [email protected], [email protected] and so on, and so on.
    Does anybody knows how to set this up in the new OS X Server?????

    We thought about that also, but we noticed that it is not working.
    For example, i have the email adres [email protected] but i make the alias 'twitter' and 'info' in my client account.
    So i send a test email from outside the office with our iPhone on the [email protected] account. to [email protected] but nothing is happening, even not with the [email protected] mail.
    What i know where the aliasses for stand is when you login to the server, example.
    Username = myfirstnamewithmysurname
    the alias lets you make a short name to login quickly, so if you make the alias like 'firstname' you now can login to your client account with that alias, but it is not working for emails.

  • How can i get list of all monitors and rules that assigned to a node ?

    Hello,
    We r using the scom 2012 sp1
    i need to get list of monitors and rules that have assigned to nodes.
    for example :
    nodename - type - name
    node1 - monitor - montiorname1
    node1 - monitor - monitorname2
    node1 - rule - rule1
    node1 - rule - rule2
    can i get this list by using sql or powershell script ?
    thanks

    Hi,
    Please refer to the link below:
    How to View All Rules and Monitors Running on an Agent-Managed Computer
    https://technet.microsoft.com/en-us/library/hh212748.aspx
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Subscriber Support, contact [email protected]

  • Setting Overrides on all relevant Rules and Monitors

    Can someone please help me with the following question? I was reading the post below (I believe written by
    Cameron
    Fuller) detailing some best practice around overrides. It stated if you override a ‘parameter’ for one rule/monitor (e.g. let’s say a parameter
    dealing with a threshold) you should override the parameter for ‘all’ rules and monitors 'that use this parameter'. More information from the post below
    Make sure that an overridden parameter is set for every rule and for every monitor that uses the parameter
    When you override a parameter, make sure that the parameter is configured for each rule that uses the parameter and for each monitor that uses the parameter. There may be more than
    one rule or monitor that uses the particular parameter. For example, the following rules and monitors use the
    Intersite Expected Max Latency parameter: Monitors
    AD Replication Monitoring
    Rules
    AD Replication Performance Collection - Metric Replication Latency
    AD Replication Performance Collection - Metric Replication Latency: Maximum
    AD Replication Performance Collection - Metric Replication Latency: Minimum
    AD Replication Performance Collection - Metric Replication Latency: Average
    Now my question is:
    How do I discovery all the rules/monitors that are using this particular ‘parameter’?
    For example using either PowerShell or SQL query. If PowerShell I assume you would have to
    use Get-Rule or Get-SCOMRule with the –Criteria filter. Does anyone have an example please?
    As a side note I could do the following in PowerShell as one way to find all cmdlets what use the –path parameter as one of their parameters
    Get-Command -CommandType cmdlet | where {$_.parameters.keys -eq "path"}
    So to recap: As above if I want to set an override on ‘Intersite Expected Max Latency’
    for a given rule or monitor how do I find all other rules/monitors also use ‘Intersite Expected Max Latency’
    as I can override these too?
    Thanks All
    AAnotherUser__
    AAnotherUser__

    Hi,
    We may use the specific word to filter out those proper rules and monitors, to filter out all monitors that which name contains latency:
    get-scommonitor -name “*latency*”
    Please refer to the below links to find more details about the get-scomrule and get-scommonitor command:
    Get-SCOMRule
    http://technet.microsoft.com/en-us/library/hh918556(v=sc.20).aspx
    Get-SCOMMonitor
    http://technet.microsoft.com/en-us/library/hh918469(v=sc.20).aspx
    Regards,
    Yan Li
    Regards, Yan Li

  • Mail 4.5 not retrieving catch-all mail from Pop Server.

    I use email fowarding for a domain (hosted at Godaddy) to forward to my verizon email account. For example: [email protected], [email protected], and [email protected] are forwarded to [email protected]  The Mail 4.5 client on my MacBook Pro (OSX 10.6.8) retrieves all this forwarded email correctly from the Verizon Pop3 server.
    I also have one of the domain email aliases setup as a catch-all account. For example [email protected] is configured as the catch all. Mail addressed to [email protected] is also retrieved from the Pop3 server correctly.
    But any mail directed to the catch-all account because the email address is invalid such as [email protected] is not retrieved by Mail 4.5 client.
    The 'catch-all' email is being forwarded correctly to my Verizon Pop server. If I log in to Verizon Webmail I can see the forwarded 'catch-all' emails in the Webmail Inbox. Also if I use Outlook 2010 on my PC to retrieve my Pop mail, it correctly brings down the 'catch-all' email.
    It certainly appears like something internal to Apple Mail is filtering the 'catch-all' email and not retrieving it from the Pop3 Server.
    If you can understand what I'm trying to report - can you help me figure out what is wrong?

    I now do want to catch all email as it has become my lives work to report spam.
    So I figured out an easier way to catch all email using simply the serveradmin command-line tool (this only takes email that would otherwise bounce):
    sudo serveradmin settings mail:imap:lmtp_luser_relay_enabled = yes
    sudo serveradmin settings mail:imap:lmtp_luser_relay = catchallusername
    sudo postfix reload

  • Configure a Catch-All Mailbox in Exchange 2013

    Is it possible to create a catch-all rule which delivers mail sent to a non- existing mail address inside the organization (*@contoso.com), to a specific
    mailbox?
    Exchange 2013 Standard

    Hi All
    I have also used the Catch all agent from Codeplex, with great success.
    The only issue is, that the catch all transport agent HAS TO be installed, while your still at level CU3 or lower.
    We are now at exchange 2013 CU7, and the Catch all agent still works like a charm.
    Forget about journaling rules, these doesn´t work, in my experience

  • Catching all errors

    Hi
    is there a way to catch all errors, I know you can do try and
    catch fro your code
    about how about errors that come from built in Flex component
    I am trying to catch all errors and show it to the user in
    better format
    but most important, it seems flex will be frozen and you can
    do anything if the error is not caught and the only way around it
    to restart your browser
    Please help
    Thanks
    Kasem

    Everything I read suggests that this isn't possible in Flex.
    It seems that uncaught exceptions are handled by the Flash player.
    This link discusses the problem in Flex 1.5 and it notes the
    problem is not fixed in Flex 2.
    http://www.mail-archive.com/[email protected]/msg25874.html
    I'm going to continue to look. I really can't imagine that
    Adobe spent all that time reworking Flex and didn't address this
    problem.

  • How can I hide "Taxonomy Catch All Column" without using PowerShell?

    After having moved some files around, I find that my view and edit properties forms include the field "Taxonomy Catch All Column" and the field IDs which are just going to be confusing gobbledegook to my end users.
    I can't seem to find a way to get rid of it. I can't delete it and I can't see where to hide it. Searches only seem to turn up PowerShell script solutions, and I can't use PowerShell.
    It's SharePoint 2010 Server, I'm a site admin and I can use SharePoint Designer, but not powershell, no server access, no central admin access.
    Can anyone help please?

    Hi,
    For your issue, it seems to be related to use Content & Structure. 
    If you choose to move content that contains managed metadata columns (or presumably enterprise keywords), the Taxonomy Catch All column shows up after you use the "Content and structure" tool. It shows up as a column in the library and is visible
    in "Edit Properties" on every document.
    Why are you can’t use power shell? It is convenient to solve your problem with power shell.
    Here is a similar post, you can use as a reference:
    https://social.msdn.microsoft.com/Forums/en-US/896cea1d-dc40-47f1-80f4-7a01f2d23fd9/what-is-the-significance-of-taxonomy-catch-all-column-lookup-column
    http://blogs.c5insight.com/Home/tabid/40/entryid/385/Why-Do-Hidden-Taxonomy-Catch-All-Columns-Become-Visible.aspx
    Besides, here is an article, you can have a look at:
    http://www.andrewconnell.com/sharepoint-2010-managed-metadata-in-depth-look-into-the-taxonomy-parts
    Best Regards,
    Lisa Chen
    Lisa Chen
    TechNet Community Support

  • Catching all the exceptions at once

    Can we catch all exception and throw it all at once?
    Here's what i want to do..
    Say i have a class in which i have around 4 sql statements
    which i'm putting it in a try. I do not want to throw execptions one by one.
    instead
    try{
    some statements
    catch{
    goto Error -->
    catch{
    goto Error -->
    Error:
    Show all the statements here..
    I do not want to do this manually..is there already an exists9ing class or something that we need to implement. Please reply
    Tahnks,
    Anjana

    Just catch Exception. its the motherclass of all exceptions.
    put everything in one big try/catch.

  • How to setup a catch all email accounts on a domain?

    I am currently hosting several different domains on our server. On one of the domains, we would like to set up a catch all email account. Right now we have [email protected], and [email protected], but would like emails sent to any other address ('anything'@domain.com) to be directed to the [email protected] Is there a way to set up a wild card email address entry for a specific user account?

    Don't do this. Seriously.
    Your wildcard account will get inundated with every dictionary-based spam directed at your domain.
    Many spambots just try common names at every domain they can find - alex@, andrew@, joe@, john@, etc. sometimes generating tens of thousands of messages in the hope that one or two names match legitimate accounts.
    If you setup a wildcard account, all these messages will be accepted and dumped into this mailbox. If you don't have a wildcard account the messages will be rejected with a 'no such user' error (or dropped silently, depending on your mail server setup).
    If you really do want to do it, then you need to get under the hood and configure postfix manually (Server Admin won't do this for you). The specifics are covered in the Postfix virtual accounts documentation.

  • My macbook pro's screen display has suddenly gone into a strange colour setting where everything appears in a kind of infrared colour palette an I can;t seem to change it back.  It's the same for all icon and websites, does anyone know how to restore?

    My macbook pro's screen display has suddenly gone into a strange colour setting where everything appears in a kind of infrared colour palette an I can;t seem to change it back.  It's the same for all icon and websites, does anyone know how to restore?

    Wow!  I think I had this same issue just last night.
    I was cleaning my macbook pro retina on the outside.  Then I opened it up and was wiping dust off the monitor and I can't pinpoint exactly when, but the colors changed suddenly.  It looked super strange, it was like green halo's and it looked worse when looking at it at an angle.  Of course I took no pictures!!!  I was freaking out that my 2 grand laptop was busted and I somehow removed a protective film or something.
    But I digress...  The image looked very green and spacey, it was almost a neat effect.  After about 5 minutes it started to look a little more digital though.  There were straight lines of this halo effect on the edges and top.  After about 10 minutes it turned into a predominate issue with the blacks on screen.  I could open a web browser and it was unnoticable on a white background.  After about 15 minutes, you could only barely see the green cloud effect if you looked at the monitor from an extreme angle.  After about 20 minutes, it was completely back to normal, I almost feel paranoid like I see a halo or something strange.  But I believe that might be all in my head now.
    So yerp, lemme know what you guys figure out.

  • My husband and I both have iPads and somehow when they were setup the both we're setup using the same email I'd address. When I go to delete and rename one iPad it says all info and pictures will be erased from my iPad. Is there a way to keep the info iPa

    My husband and I both have iPads and somehow when they were setup the both we're setup using the same email I'd address. When I go to delete and rename one iPad it says all info and pictures will be erased from my iPad. Is there a way to keep the info IPad when doing this?

    You can go to Settings/iCloud and delete the account, then create a new iCloud account.  You can still use the same account for the app store though.

  • When using Firefox today a strange page with the title wonderhowto showing video instruction appears and all other open pages are closed. I have minimalised this stranger to the screen base and it now shows there with a mini firefox attached!

    Please bear with me as I am quite new to computers. Early today on start up I was asked to upgrade an Apple app. I declined as I did not have time.
    I opened Firefox as usual and went into several sites mail news etc and all seemed fine. Late morning this strange and quite professional looking video instruction page appeared full of photo's and instructions etc, the page took over the whole screen I thought it was strange so I closed it and all my open Firefox sites had gone. This has now happened several times. I have now noticed that when it is up there is a website address at the bottom of the screen. I tried to copy and paste this but it would not let me. There is a name scorecardresearch.com. Does this strike a bell with anyone?

    Hello,
    My name is Bryan Crow, and I am the CEO of WonderHowTo.com. This problem was brought to my attention this morning by others who have reported the same problem to our contact address: [email protected] I'm very sorry to hear this is happening.
    I assure you this is not something our website created or installed on your computer. Most likely it is some form of spyware or virus that is opening our website in order to hide it's true purpose. We are a large and trusted source for how-to articles and videos, so there is no reason we would choose to annoy people with such an obnoxious and intrusive behavior. Frankly it's very upsetting that someone would create malware that directed people to our website.
    Naturally, our team would like to do whatever we can to try and find the culprit behind this so we can report them. If any of you can provide me with additional information by emailing [email protected], it could help us get to the bottom of this.
    Specifically:
    * Have you installed or updated any Firefox Add-Ons recently (go to Firefox -> Add Ons to see the list of add-ons you have installed)?
    * What Firefox Add-Ons do you have installed?
    * Have you tried running a virus or spyware scan on your system? If so, which software did you use and did it help?
    * What URL is opening up when you see WonderHowTo, and what exact time of day (and in what time-zone) did you see it?
    Thank you for your help.
    Bryan Crow, CEO
    WonderHowTo
    1832 Franklin St
    Santa Monica, CA 90404

  • I recently had my iphone 4s screen repaired because the screen was cracked. It was all ok and then a few weeks later something strange happened. My touchscreen works, but the screen doesnt show, you can see the light in the background but no picture?

    I recently had my iphone 4s screen repaired because the screen was cracked. It was all ok and then a few weeks later something strange happened. My touchscreen works, but the screen doesnt show, you can see the light in the background but no picture? has anyone got any ideas as to what the problem is, is it self-repairable or even repairable at al?

    The LCD Display connector has partially come loose from the logic board connector, and simply needs to be pressed back down into place. Or the front screen assembly is now faulty, and needs to be replaced again.

Maybe you are looking for

  • PCI 7330 not recognized in Windows 7

    When I transferred my 7330 motion controller board to another PC, it is not recognized in MAX. Windows system put it as unknown PCI board.  The PC runs on Windows 7. LabVIEW 2010 and MAX 4.7 were installed. What could be the reason for the 7330 not b

  • HD or Booting problem on MSI K7N2 Delta 2 Platinum

    Hi all, Ive a weird issue which i cant figure out myself. I've 2 HD's..lets call them A and B where A = 60Gb (Master) and B = 80Gb (Slave) It's is like this: A and B are connected to the primary IDE-slot. A will boot when set as Master and B wont sta

  • I'm continuously getting a "connection timeout" on my home network. My iPhone connects without a problem, and I know the password is correct. How do I fix this?

    I've never had a problem connecting to my home network until recently. The desktop computer is connected, and my iphone connects as well. It is not a problem with the wireless router, but rather I believe with my computer or airport. How can I fix th

  • Complex Arrow

    Hi Guys, I got the following issue.. and it seems to be rare too (at least I didn't find any hint yet that works): I want the user to enter a Complex Number by using graphical means (e.g. 2D Compass Plot, or XY-Graph). In end version the user is supp

  • Making mp3 and or file type force download

    I have a a web app that has a sermon and also has a notes you can down load. But I want it so when you click download it opens a save as box or open not stream. How can I use the literature settings to accomplish this in my web app. Shaun Ryan