I need to all icmp through the ACE to servers behind the ACE

I have been trying to figure this out and I've made several attempts at a configuration that will work, but I just don't get it.  Here's what I have configured.  I'm trying to ping from a server outside of the ACE to a server on vlan 308.  I send my ICMP it should ingress through vlan 302 and hit the server on vlan 308.  Instead I get nothing and I see no traffic hits on my policy or from the show icmp statistics.  I am able to ping the IP addresses on vlan 302 but nothing on the inside.
access-list icmp line 10 extended permit icmp any any
class-map match-all icmp-allow-inspect
  2 match access-list icmp
policy-map multi-match icmp-allow-inspect-mmpl
  class icmp-allow-inspect
    inspect icmp error
interface vlan 302 --------- public facing VIPs- ingress
  ip address 71.113.93.37 255.255.255.224
  alias 71.113.93.36 255.255.255.224
  peer ip address 71.113.93.38 255.255.255.224
  service-policy input mgmt
  service-policy input icmp-allow-inspect-mmpl
  no shutdown
interface vlan 308 ---------- server - L2
  ip address 10.60.22.130 255.255.255.192
  alias 10.60.22.129 255.255.255.192
  peer ip address 10.60.22.131 255.255.255.192
  service-policy input icmp-allow-inspect-mmpl
  no shutdown

I ran a capture and I see the traffic hit the ingress interface of the ACE, but it never gets passed to the backend server vlan.  The icmp is recieved and the connection is closed, but then I get 4 more packets marked PKT_XMT then the packet is dropped.  The capture was done on the ingress vlan.  If I do a capture on the server side vlan I get nothng at all in the capture.
0001: msg_type: PKT_RCV
ace_id: 6809            action_flag: 0x13
src_addr: 74.113.193.34            src_port: 53575
dst_addr: 10.62.222.136            dst_port: 2048
l3_protocol: 0          l4_protocol: 1
0002: msg_type: CON_CLOSE
con_id: 1345505684       out_con_id: 271763861
src_addr: 74.113.193.34            src_port: 53575
dst_addr: 10.62.222.136            dst_port: 2048
l3_protocol: 0          l4_protocol: 1
0003: msg_type: PKT_XMT
con_id: 1345505684              other_con_id: 0
0011: msg_type: PKT_XMT
con_id: 1345505684              other_con_id: 0
0019: msg_type: PKT_XMT
con_id: 1345505684              other_con_id: 0
0029: msg_type: PKT_XMT
con_id: 1345505684              other_con_id: 0
0037: msg_type: PKT_DROP
con_id: 1345505684           reason: 0
src_addr: 74.113.193.34            src_port: 53575
dst_addr: 10.62.222.136            dst_port: 2048
l3_protocol: 0          l4_protocol: 1
This is my access list and its applied globally with the access-group input ALL command.  I also have my default gateway pointing back to my upstream router and there are no other routes on the ACE.  I can ping the ingress interface from my upstream router and I can ping my gateway from the ACE.  I can ping my backend server from the ACE, but not from anything outside the ACE.  I can not ping anything behind my ACE module.
access-list ALL line 12 extended permit icmp any any
access-list ALL line 18 extended permit ip any any

Similar Messages

  • The dropdown menu in the banner should be behind the text fields.

    Hi Andy,
    In our Application we have three Menus...The problem we are facing in that when ever we move the cursor, a drop down list will appear.. which is covering the text fields...
    The dropdown menu in the banner should be behind the text fields.
    Can u pls help me in this...
    anoo..

    Hi Anoo,
    (You can actually ask questions to everyone, not just me!)
    Normally, dropdown menus are supposed to be on top of all other items, so the user can pick an option from the menu. In fact, usually the problem is that select lists in IE appear on top of menus, not the other way around!
    What you may have to look in to is adding a z-index value to items. Have a look at: http://msdn.microsoft.com/en-us/library/ms531188(VS.85).aspx
    z-indexes determine the order in which items appear when two or more occupy the same space on the page. The higher the number the nearer to the top that item is. You can use negative or positive numbers. So, if item A has a z-index of 1 and item B has a z-index of 2, then item B will appear on top of item A.
    A z-index can be set as a style on your menus:
    <........ style="z-index:-1".....>Andy

  • Exchange Web Services are not currently available for this request because none of the Client Access Servers in the destination site could process the request.

    Hi,
    I am using EWS Java APIs and passing OAuth tokens to fetch data from office 365 mailboxes.
    Because I am developing Web APIs I preferred using "Application Permissions" defined in Azure active directory application for Office 365, and used "client credential flow" OAuth flow to fetch OAuth token specific to application which will
    allow "Have full access via EWS to all mailboxes in the organisation".
    After fetching token with the procedure specified in the document "http://blogs.msdn.com/b/exchangedev/archive/2015/01/21/building-demon-or-service-apps-with-office-365-mail-calendar-and-contacts-apis-oauth2-client-credential-flow.aspx"
    I passed this token to EWS Java APIs,
    it gave me error saying:
    microsoft.exchange.webservices.data.ServiceResponseException: Exchange Web Services are not currently available for this request because none of the Client Access Servers in the destination site could process the request.
    I tried similar thing with EWS managed APIs for .net. Got similar error.
    Can anyone provide some help and direction to resolve this error.
    Thanks & Best Regards,
    Pranjal

    I see you found an answer with the X-AnchorMailbox header on StackOverflow:
    http://stackoverflow.com/questions/29554724/exchange-web-services-are-not-currently-available-for-this-request-because-none

  • When a window is open and I try to go to a new bookmark or a link in an existing site, the new window opens behind the old window.

    It isn't every time, and sometimes doesn't happen for a long time, then I'll go to a bookmark or toolbar link and the new window opens behind the one I was on. Example: I just opened a second window (CTRL N) and clicked on a bookmark. It opened a new window behind the one I'm on as I type this. I did the same steps again and it opened the new window in front of this one. It doesn't seem to make any difference which site I start from or go to or if I use CTRL N or let the bookmark do the opening.

    This can happen if you have a tab open in the main browsing window that uses the plugin-container process (e.g. Flash).
    *[[/questions/977544]]

  • Clicking on a link often causes the link to open behind the window with the linik.

    Clicking on a link often causes the link to open behind the window with the link.
    This occurs most frequently when only one or two windows are open.

    Work around found.
    The problem was occurring in links on a web page I created for my home page with "target=_new". Changing this to "target=_blank" fixed the problem. The old links worked fine before version16.

  • When I click on a hyperlink on a page, the destination page opens BEHIND the source page. ????

    I use open Google News every morning. If click on a hyperlink, the destination page loads BEHIND the source page. ????

    If the Menu Bar is not visible, press the Alt key. Then select Tools -> Options.
    Under the "Tabs" tab, make sure the following option is checked:
    "When I open a link in a new tab, switch to it immediately"
    If that option is already checked, I'm at a loss.

  • IPad (1) bluetooth only "searches".. doesn't find. All works on my IPhone 4, but the IPad can't "find" the devices. Using Motorola behind the head and Rocketfish behind the head headphones.

    I have both Motorola and Rocketfish behind-the-head earphones.  Both work fine on my IPhone 4.  But the bluetooth setting on my IPad only "searches" and doesn't find the devices.  Any ideas? (Using Latest OS for IPad

    I had the same problem for the last 2 weeks and today it just started working with nothing changing.  I've also read reports of others having it just start working today.  Give it a shot again.  I think it was a problem that AT&T sorted out.

  • One-armed ACE with servers gateway to ACE (no SNAT?)

    Hello ACE experts, I have two questions;
    Design;
    One-armed ACE appliance where the servers use the ACE as default gateway? (and ACE of course a default route to the router)
    Apparently it works in my lab… But since it’s not documented I wonder what the gotcha’s are?
    (This would eliminate the SNAT requirement for one-armed)
    I know I need;
    -no icmp-guard                 to allow ‘asymmetric icmp’
    -no normalisation            to allow asymmetric traffic when not using VIP (router to server is direct, but server response uses the ACE)
    And other question;
    Bandwidth license, apparently ALL traffic counts to this limit, even only routed traffic, is this true?
    So In routed mode, all traffic from server backend that needs to be routed over ACE - a backup!? - counts?
    Regards Kristof

    Hi
    the reason I use "process every packet" was it was one of the advantage being offerd by one arm mode to not to process every packet. The main reason for one arm deployment, as i mentioned previously also, is ease in placement of ACE. We can have servers in any vlan and can put ACE altogther iin different VLAN. i guess this advantage is of no use for you because servers are already in same segment as that of ACE.
    The main cause ,which i understand, customer don't like the concept of SNAT is because of its restriction on reporting and security. Client IP will be hide, so any reporting on servers for sessions source (or for monitoring attacks) will not be fruitfull. Although with feaures like XFF we can overcome this fault for HTTP traffic, but still customers don't like the consept of hiding details of IP accessing their servers.
    regarding B/w count in bridge mode i am not 100% sure but beleive here again every passing traffic will count as ACE still monitor every packet and decide whether its a passing traffic or part of loadbalancing or hitting any of its confiugred policy.

  • MAC Voice Over: Why does the screen view lag behind the voice over audio?

    MAC Mac OS X 10.6.8 (10K549)
    When using voice over on a MAC with DE 1.8 - most times when paging thru a pdf file/book the voice and the view are inconsistent.  When using VO -  moving to the next page with the right arrow key - the audio starts to read the next page (correct), but the display is one page behind (not correct).  For readers - especially those that have significant visual impairment  - this will not work for them.  Is this a defect - and if so - I would be very happy to re-test this feature if a new revision of DE 1.8 is provided.
    I am unsure this is the correct forum to raise issues such as this one.  I am in the process of evaluating Adobe DE 1.8 - my sister is blind and I am trying to move her to a MAC with VO.  I really appreciate Adobe's effort in supporting JAWS and MAC VO - thank you on behalf of all disabled folks out there.
    Below is a detailed list of steps to re-produce this audio/screen inconsistency issue.
    - Install DE 1.8 and add to the dock
    - Add a pdf file/book to DE 1.8.  For my issue, I am adding the "Voice Over Getting Started" guide. 
    - Turn on Voice Over - Cmd+F5
    - Using VO - Go to the dock and select DE and start it.  The "Last Read Book" typically is the focus for the VO cursor.  Then using VO next item (VO+right arrow) - move the VO cursor to "Library Content Table".  This is the list of books that are displayed in DE.
    - Using the up/down keyboard arrows - move up and down thru the books in the content list.  At this point - you should already see that the VO audio announcing the title of a book is not synchronized with the row in the table that is displayed.  The voice is announcing a book that you selected, but the display is showing the previous book. 
    - Once you hear (not see) the book you want to test with, hit <enter>.  DE will open the book and start to read using VO.  At this point the screen and audio for the first page in the book are the same. 
    - Once the book has been opened by DE - Using the right arrow key navigate to the next page in the pdf/book.  Normally the right arrow key is the short cut to allow a user to move forward or backwards thru a book, one page at a time. 
    - With DE and VO - what happens is that VO responds to the right arrow key and starts to read the next page.  But the screen is still showing the previous page.  Hence the screen and the VO audio are out of sync. 
    - For anyone that uses MAC VO - this will prevent them from using Adobe DE 1.8.
    If I am doing something incorrect - please let me know. If you need any assistance or further information regarding this issue - please email me. 
    Best Regards
    Mike R

    hi, Mike R:
         Thanks for your information. We have tested several Mac machines, iMac and MBP (use the same version as yours). But we can't reproduce the issue. Actually working with VoiceOver is a fundamental request for our application, we did test them before releasing the build.
         We suggest you test other applications, e.g. Finder, Preview and iTunes, to make sure if VoiceOver works fine with them. Or can you please check if your VoiceOver settings are correct?  

  • External ip adress at the server network interface behind the router

    Hello to all!
    I am installing MacOSX Snow Leopard Server and using it behind my AirPort router as a mail and web server. I was setup Airport at the NAT section with 'Enable default host at' option and all services workning well, but one thing that i want to understand is the 'network interfaces' at the 'Server admin' of Leopard Server. There is listed only internal ip adress (10.0.1.2) that use the my server, but there is no my static external ip adress. Is it correct ? Or i should manualy also to add a external ip adress which is now actually used with my AirPort router?
    If i should, so how do it correctly, using virtual interfaces at the network section or somewhere else?

    So, with any Airport routers i can't to route my public static IP adress to the MacOSX Server machine? I need another router device for this, am i right?
    Your Airport uses your public static IP address.
    Your Airport is typically then configured to port-forward inbound traffic along to your server at your own private static IP address via NAT. The mechanism known as port-forwarding is (once it is configured) how traffic routing to your public static IP address gets routed to your private static IP address.
    In general (and unless something like NAT is involved), there's only one host box active at one IP address at a time.
    I am not sure, but i think that at the server network interface i should has a public static IP adress, but with this configuration i can't see it.
    If you would so kind as to tell me what particular part(s) of [this article|http://labs.hoffmanlabs.com/node/275] are confusing and why, and I'll see if I can address the confusion and to update the article.

  • Allowing Multicast to work between real servers behind the CSM??

    Hi,
    Just want to know if it is possible to use IP Multicast between real servers on a server subnet that is configured on the CSM. If so how could this be setup?
    I've attached a copy of the our CSM config. In particular, the server subnet in question is "vlan 386 server". The Real servers belong to "serverfarm FARM-VISTA-TEST".
    I suspect that maybe an interface vlan 386 needs to be created on the router, with pim sparse-mode enabled?
    Any ideas?
    thanks
    Sheldon

    the CSM does not know ip multicast, so your multicast needs to find another way to reach the servers.
    You will also need a static route on the servers to point 224.x.x.x to the MSFC and keep the rest of the traffic going to the CSM.
    Another solution is to use bridge mode.
    Create a duplicate vlan 386 on the CSM and the MSFC.
    ie:
    MSFC---vlan387-----CSM-----Vlan386
    On the CSM, you configure vlan387 with the same ip as vlan 386 - this will tell the CSM to bridge the 2 vlans.
    Configure an ip from the same subnet on the msfc int vlan 387.
    configure multicast on vlan 387.
    The CSM should normally bridge all unknown traffic including multicast.
    All you have to do on the servers is change the default gateway to be the MSFC instead of the CSM.
    Gilles.

  • Is there a way to keep the cursor from disappearing behind the keyboard when composing an email in iOS 8?

    When composing an email the cursor disappears behind the keyboard using iOS 8.  Is there a way to have it scroll up so that I can see what I am typing?  Was not a problem with iOS 7

    u can slide the message viewer all the way over to the RIGHT, thus hiding the message from view, and then delete at will from the expanded left column.
    Message was edited by: coocooforcocoapuffs: can't tell my left from right yet.

  • The Draft Word is behind the text in Purchase Order

    Hi All expert,
    Do you all have any idea about the watermark draft in SAP Business One 2007 Purchase Order.
    The Purchases Order with draft will display in the center of Purchases Order if the document is in draft.
    However, i found that the work 'draft' in the center of Purchase Order is behind the text. It means the word draft cannot display entire word in the document.
    If i want the 'draft' bring in front of the text. Mean it show entire words 'draft' instead of behind the text in the document.
    Can we be make it?
    Can we change the word 'draft' in the document?
    Regards,
    Eric Tan

    Hi Eric Tan,
    You cannot change the word DRAFT to anything else. Also you cannot make it appear in front of the text. As a workaround what you can do is Using the Document status you display on the header of the PLD you can display the DRAFT word or any other word as required. You can also format the field with font of big size and select color for it.
    Also you can disable the DRAFT word from being displayed in the PLD by configuring the settings in the Administration --> System Initialization --> Print Preference --> General Tab.
    Hopw this will help you.
    Regards
    Reno.

  • When I touch the "photos" icon on my 4th gen iPod Touch, I get a page entitled "Albums" - it's white, with many lines.  At the very top of the screen, almost shadowed behind the word "albums" I can see the thumbnail of my album.  But I can't access it.

    I need help viewing my photos on my 4th gen iPod Touch.  When I choose the "photos" icon, I get a screen called "albums".  At the top of the screen, sort of shadowed behind the word "albums" I can see a thumbnail of where my pictures are.  What can I do to get back my "old" view of my pictures?
    Thanks.
    Judy

    Bring up the Multitask bar by double clicking on the home button, search for the photo app icon, tap on it until it starts to shake, hit the minus icon in the left corner to close the app.
    Close the task bar again and start the photo app again, this time it should work.

  • When I press "reply" the reply email opens BEHIND the main screen so I have to move the main screen aside to get to it....

    It has now started happening with the "change text colour" dialogue box too.
    Windows 7

    Close email app in the multi-task window and re-launch.
    1. Double tap the home button to bring up the multi-tasking view
    2. Swipe the app's windows upwards to close
    3. The app will fly off the screen

Maybe you are looking for

  • SRM 7.0 New custom fields added to view do not appear in the component conf

    Hi I added two custom fields to the view V_QTE_DOFC_I_DESC of the WD componenet /SAPSRM/WDC_DODC_QTE_I_DS. This view gets called when bidder is trying to create a bid and clicks on add Substitute Item in the Item tab. This view is simply a popup wind

  • Slow Boot-Up with 3 monitors after Yosemite

    I updated my Mac Pro 12-Core (40GB RAM) last week to Yosemite. Since then, my Mac takes about 15 minutes to boot up after either a fresh start or Restart. If I remove 1 of my 3 monitors, I get a normal boot (I have an SSD startup drive, so it takes a

  • Reinstalling Mac OS X

    If I do an Archive and Install on my Mac Pro which also has Windows loaded on it will I have reinstall Windows and go through the Boot Camp fiasco again.

  • Charging leads to screen saver mode

    I have a HP Pavillion g6 Notebook Product # C2N5OUA When i plug in charging plug..the screen goes to screen saver mode reducing brightness and visibility but does charge..when i remove the charging plug, the screen goes back to normal visibility...An

  • Converting RAW masters to jpgs without exporting, deleting and importing...

    Is there a way to convert my RAW files that I already imported into Aperture libraries, now into JPGS without exporting versions, then deleting the RAW-master originals and then importing the jpgs again? I would like to save some disk space, after ha