3750 bandwidth limitation between the same vlan over the trunk

Hi All,
I have 2 3750G series switches on the trunk link. some machines are part of vlan1 on the switch 1 and some machines are the part of the same vlan1 on the other switch2. I need to limit the bandwidth between the switches for the vlan1. picture is attached.
I tried to do through the modulare policy frame work (class-map/service-map and policy-map using the police command) but problems are
1) 3750 does not support output service policy, so i cannot apply the policy on the output of the trunk link.
2) I can apply the input policy but it will be only for one machine but not for the others on the same switch. if i apply the policy on per port basis then every port has separate bw limitation. I require to limit the bandwidth on per vlan basis on the trunk port. like vlan 1 takes 10 MB, VLAN2 takes 10 MB on the trunk link when communicating between the same vlans.
Is there any solution for that scenario? your help in this case will be higly appriciated. As its the layer 2 communication, its hard for me to find the solution. if it was layer 3 then i can do it easily by using the rate-limit commmand on the interface.
thanks

On the 4500 series we use vlan-range for this,
conf t
qos aggregate-policer 10MB 10 mbps 1250000 byte conform-action transmit exceed-action drop
policy-map 10MB
class class-default
police aggregate 10MB
interface GigabitEthernet1/1
switchport trunk encapsulation dot1q
switchport trunk allowed vlan 1,10,12,15
switchport mode trunk
switchport nonegotiate
vlan-range 1
service-policy input 10MB
service-policy output 10MB
end
dunno if the 3750's have the same options

Similar Messages

  • Cataylst 3750 Bandwidth limiting

    Hi,
    on cat3750 you can limit the Bandwidth on a n egress interface using the SRRcommand:
    srr-queue bandwidth limit "weight1"
    the weight1 is a variable in the range from 10 to 100 (default)
    This means that in a 3750G a giga interface the egress queue can be limited only to 100Mbit/s (setting the weight1=10)...or the siwtch is able to interpret the weight in correlation of the port settings
    for example a gigabit port is connected to a device and the settings are 100FD
    if the srr weight1 is set equal to 10 then the egress BW is 100Mbits, seeing it's a giga interface, or 10Mbit/s seeing it's a giga interface BUT connected as 100FD ?
    thanks for replay
    Omar

    Under which IOS image could you find this command?
    For example, using a stack of three 3750G, running under the 12.2 (25)-SEC2, the command is as follows:
    Switch(config)#mls qos srr-queue input bandwidth ?
    <1-100> enter bandwidth weight for queue id 1
    and there are 2 queues
    or
    Switch(config)#mls qos srr-queue output ?
    cos-map Configure cos-map for a queue id
    dscp-map Configure dscp-map for a queue id
    1-100 are weights that act on a port settings. Seeing that traffic is serviced depending upon
    its class of service (CoS) or differentiated services code point (DSCP) designation and this command is from commands conditioning delivery.

  • Private vlan over dot1q trunks with etherchannels

    Dear Freinds,
    I need to know whether can i use trunks in etherchannel for Private Vlans.
    regards
    Manish Shamjee

    Hello manish,
    You would need to elaborate more on that.
    Are you trying to 'trunk' primary private vlan's or secondary private vlans? Or are you trying to configure private vlans on ports that are etherchannels?
    Read this "Do not configure private VLAN ports as EtherChannels. While a port is part of the private VLAN configuration, any EtherChannel configuration for it is inactive"
    The above is from the pvlan guidelines and restrictions found here:
    http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/122sx/swcg/pvlans.htm#wp1090979

  • Configure Trunk carrying same Vlans on two separate uplinks on Cisco 3845

    Hi,
    I need to carry 2 vlans(x & y) in a trunk to two separate redundant devices uplinked to Cisco 3845 on Fa1/0 and Fa1/1. I know I can create sub-interfaces on one of the uplink interfaces(i-e Fa1/0) with 2 distinct 802.1q vlans(Fa1/0.x & Fa1/0.y). But is there a way I can carry same vlans(x & y) trunked to my 2nd redundant device uplinked on 3845 from Fa2/0 ? If not then how should I get the 2nd redundant device uplinked to this 3845 router.
    Any tips.. ?
    Thanks for your help and suggestions.

    IF both links are going to the same device then you can create a Layer 3 Etherchannel. 

  • Is there a album limitation on the IPad?

    This a first for me.  I never had a problem importing a new Album/photos into my IPad 2 -- until now.   I could not find an answer in the User Guides provided by Apple.  This may have nothing to do with it, but yesterday I updated the OS on my MacBook with the latest security update.   I was able to create a new Album in IPhoto and imported photos into it.   This problem is not with IPhoto.  I connected my Ipad2 to my Macbook.   I interrupted the sync process  to select the new album in Itunes.  Again no prolem.  The Itunes sync appears to work.   When I completed the sync, I ejected the IPAD 2.  I then attempted to view the new album (with photos) on my Ipad2.  Nothing was visible.  The album never appeared.   In an attempt to troubleshoot the problem, I created a "dummy" album in Iphoto and dragged the photos from the real album into the test album.   I then deselected the real album.   I again performed a "Sync" opraion in Itunes.   I was able to locate the test album on Ipad but only two photosin it.   They were not the photos I loaded in IPoto.   Has anyone else had issues with Ipad2 photo syncs with their computer?
    Is suspect there a bug or somekind of album and/or photo limitation between the IPad 2 and Itunes/Iphoto on my MacBook.  

    Photo synching has always been a complete nightmare with iTunes + iOS. There are a lot of dedicated threads on it.
    I recommend abandoning it entirely and going to third-party image viewers / slideshowers like Photo Manager Pro. They, in addition to getting rid of the abundant sync problems when using the "Photos" tab in iTunes, have a lot of additional features like unlimited-depth folder support, sorting by date etc. See http://www.iphonelife.com/blog/87/all-one-photo-viewer-roundup-70-price-drop-bes t-image-viewer for a quick review.

  • Cant communicate between nodes on the same vlan but on different switches (cat/nexus)

    Very odd situation that I cant quite figure out.
    I have two nexus switches connecte together with PO5
    Each Nexus has PO6 which connects to a Cat3750
    The nodes are all on vlan 46.
    Nodes that are connected to the nexus switches can ping each other but cant ping other nodes on the cat. switch.
    Here is an oddity. Nodes on the CAT switch CAN ping nodes on the nexus switches.
    It would appear that the nodes on the nexus (or the switches themselves) do not get the arp requests.
    Oddity 2. When I do show vpc I see on one of the nexus vlan 46 is active
    id     Port        Status Consistency Reason                     Active vlans
    6      Po6         up     success     success                    1,31,34,46,200,600-605
    When I look at the other switch I dont see vlan 46.
    id     Port        Status Consistency Reason                     Active vlans
    6      Po6         up     success     success                    1,31,34,200,600-605
    Comparing the configs I dont see a difference between the two (eyeballing sho run)
    Here are the running configs for PO6 on both switches (identical)
    MTL-N3548COLO-1# sho run int po6
    interface port-channel6
      switchport mode trunk
      spanning-tree port type normal
      speed 1000
      vpc 6
    Not sure what I am missing. Any help is appreciated.
    Thanks
    Drew

    Your setup with vMotion on a separate subnet is absolutely correct. For the vMotion issues I'd suggest you google for vMotion 14% which will list a couple of KB articles with possible issues and resolutions/workarounds.
    André

  • Confussed between the vlan mode and switch mode AToMPLS

    Folks,
    Could someone explain to me in simple terms the difference between the 2. I am very confussed about how the VC concepts works.
    So i Dot1q tagged packet comes into the switch, the switch applies 2 lables to it, outer and inner, and then it gets to the egress switch where the switches checks the dot1q tag again to decide what to do with the packet?
    in vlan rewrite example have have difference vlans on both sides (ingress and egress) how does the switch or MPLS know that the packet is going from one vlan to the other?
    Thanks,

    Hello,
    in AToM - as you described - there will be two labels involved, very much like in MPLS L3VPN. The top label will allow the transportation to the proper PE and the VC-label will identify the interface/port/VLAN.
    With EoMPLS in VLAN mode the PEs will be able to transport dot1Q tagged frames from a CPE on a per-VLAN basis. The configuration includes the VLAN tags at both end of the MPLS VC. So the dot1Q header is stripped and transported and a new dot1Q header is created by the egress PE. The VLAN tags to be used are directly configured at each PE in the form of a subinterface with encapsulation dot1Q.
    The decision where to forward the frame in the egress PE is solely determined from the VC label. Therefore one could even have the same VLAN for many customers. This is similar to IP address overlap in the MPLS L3VPN case.
    I am not familar with the term "switch mode" you use above. The other option with EoMPLS is called "port mode" afaik. See f.e.
    http://www.cisco.com/en/US/products/hw/routers/ps368/products_configuration_guide_chapter09186a00801e5c06.html#wp1128955
    "Ethernet over MPLS
    Ethernet over MPLS works by encapsulating Ethernet PDUs in MPLS packets and forwarding them across the MPLS network. Each PDU is transported as a single packet. There are various ways to configure Ethernet over MPLS:
    •VLAN mode—transports Ethernet traffic from a source 802.1Q VLAN to a destination 802.1Q VLAN through a single VC over an MPLS network.
    •Port mode—allows all traffic on a port to share a single VC across an MPLS network.
    In port mode there will be no subinterfaces and VLAN tags defined at the PE routers. Instead all incoming ethernet frames will be "copied" from one port to another. I personally refer to this as an MPLS cloud playing the role of a "Cat5 cable simulator". The only thing a PE does besides transportation of ethernet frames is error checking (and dropping if the FCS is not correct).
    Hope this helps! Please rate all posts.
    Regards, Martin

  • Itunes keeps downloading the same songs over and over again on a shared library

    I have a share library on a NAS box, and until now, little problem. But now, iTunes keeps downloading the same songs etc, when I go to another PC, even though the library is shared between the other PC, is the same.
    Plus, iTunes repeatably asks for my Password to log in, even though it is correct.
    Share Library on NAS box, mapped drive paths to drive letters.
    Keeps re-downloading songs and podcasts I all ready have on the NAS box, if I open iTunes on different computer.
    This is new behaviour. Has not happend like this till today.
    Keeps asking for my iTunes ID and Password, over and over again, evertime I run iTunes, or my iPod.
    Thanks in advance.

    Adriana,
    If your .mac account is set to be type .mac (don't laugh, it can be set to be POP, or IMAP), it functions essentially like an IMAP. As a .mac, the Inbox is actually on the server, and when you display the Inbox, you are displaying everything on the server. Any downloading you observe is purely for purposes of display, according to what selections you have made in Mail Preferences. What you report seems perfectly normal, for a .mac account, and for an IMAP account.
    Often an exchange account is also an IMAP account, and thus the behavior would seem normal for that type of account.
    Again the Inbox is on the Server, and not on your Mac. Do not confuse this with selecting to Keep copies for Offline viewing -- those copies are refreshed from the server whenever you sign on.
    Neither a .mac nor IMAP account folder will contain a MessageUidsAlreadyDownloaded file . However, your POP folder should have such a file or two, to control duplicate downloads of messages remaining on the server -- POP was originally designed to remove upon download, but now that many people use more than one computer, it is logical to sometimes leave messages on the server to be download onto other computers.
    In the Finder, open Home/Library/Mail and look for a folder named to begin with POP and including the server and/or email address in the name. If there is not a POP folder, then the account has NOT been set up to be something other than POP. If there is a POP folder, it should contain the MessageUidsAlreadyDownloaded.
    More info, please.
    Ernie

  • ACE30-MOD-k9 in bridge mode. Individual server in the same vlan of Real Servers not reacheable.

    I configured ACE30-MOD-K9 in bridge mode and I configured a server farm with his real servers. The traffic passes and is balanced correctly between all RSERVER. But I can not contact a server that is on the same vlan of the serverpharm but doesn't belong at this serverfarm.
    I Thought that the traffic directed to this "spare" server shouldn't  be balanced but the bridge should permit traffic to pass. (trasperent mode) Is it correct ?
    What does ACE in bridge mode with traffic directed to servers that do not belong to any server farm but are present on the same VLAN (same bridge group)?
    In rispect at the following configuration 10.10.10.168 isn't reacheable
    access-list INBOUND line 8 extended permit ip any any
    access-list INBOUND line 16 extended permit icmp any any
    probe http HTTP_PROBE1
      expect status 200 200
    rserver host RS_WEB1
      ip address 10.10.10.163
      inservice
    rserver host RS_WEB2
      ip address 10.10.10.164
      inservice
    rserver host RS_WEB3
      ip address 10.10.10.165
      inservice
    rserver host RS_WEB4
      ip address 10.10.10.167
      inservice
    serverfarm host SF_FIREGROUP
      rserver RS_WEB1
        inservice
      rserver RS_WEB2
        inservice
      rserver RS_WEB3
        inservice
      rserver RS_WEB4
        inservice
    sticky ip-netmask 255.255.255.255 address source sticky-ip
      replicate sticky
      serverfarm SF_FIREGROUP
    sticky http-cookie myCookie sticky-cookie
      cookie insert browser-expire
      serverfarm SF_FIREGROUP
    class-map match-any VS_FIREGROUP
      2 match virtual-address 10.10.10.169 tcp eq www
      4 match virtual-address 10.10.10.169 tcp eq 8081
      5 match virtual-address 10.10.10.169 tcp eq 8082
      6 match virtual-address 10.10.10.169 tcp eq 8083
      7 match virtual-address 10.10.10.169 tcp eq 8084
      8 match virtual-address 10.10.10.169 tcp eq 8085
      9 match virtual-address 10.10.10.169 tcp eq 8097
    class-map match-any VS_FIREGROUP_HTTPS
      2 match virtual-address 10.10.10.169 tcp eq https
    policy-map type loadbalance first-match HTTP
      class class-default
        sticky-serverfarm sticky-cookie
    policy-map type loadbalance first-match HTTPS
      class class-default
        sticky-serverfarm sticky-ip
    policy-map multi-match HTTP_HTTPS_MULTI_MATCH
      class VS_FIREGROUP
        loadbalance vip inservice
        loadbalance policy HTTP
        loadbalance vip advertise active
      class VS_FIREGROUP_HTTPS
        loadbalance vip inservice
        loadbalance policy HTTPS
        loadbalance vip advertise active
    interface vlan 4
      bridge-group 1
      access-group input INBOUND
      service-policy input HTTP_HTTPS_MULTI_MATCH
      no shutdown
    interface vlan 700
      bridge-group 1
      access-group input INBOUND
      no shutdown
    interface bvi 1
      ip address 10.10.10.150 255.255.255.0
      no shutdown
    ip route 0.0.0.0 0.0.0.0 10.10.10.1
    Thanks a lot
    Francesco

    Hi Francesco,
    Just to add more a bit, A bridge group is very similar to routed mode except ACE cannot NAT pass through traffic, vlan's cannot be shared and couple of other things but client's should be able to access the server as in before.
    But also whether in bridge or routed mode, ACE does create flows and applies other security parameters if configured to the traffic. This is for security. Also, ACE should know the MAC of the device to forward the traffic to. Can you check if ACE has the MAC of the destination? You can also put a route for testing purpose and see if that resolves the issue. That should probably be the quickest way to check if ACE is creating any issue here.
    Regards,
    Kanwal

  • Problem in 3750 with multiple IP segment in same VLAN

    Hi,
    I've problems in 3750 and would like to ask for help.
    I've 3750 switch with standard image. Because of lacking IP addresses, I'm going to redesign the IP scheme. Before complete migrate to new IP range, I've to let new IP segment co-exist with old IP segment for a while (I've 3 VLANs that have same situation). For example, 10.10.13.0/24 (old) will co-exist with 10.10.32.0/21 (new) in same VLAN (let say VLAN 32).
    Below is the partial configuration in 3750:
    interface VLAN 32
    ip address 10.10.13.2 255.255.255.0 secondary
    ip address 10.10.32.2 255.255.248.0
    standby 14 ip 10.10.13.3
    standby 40 ip 10.10.32.3
    I've two PCs. PC-A is 10.10.13.250 and PC-B is 10.10.33.250, both are using HSRP IP as default gateway (the subnet mask are correct).
    My problem is:
    Two PCs can not ping to each other. I can not ping to both PCs from 3750. But if I'm using physical IP as their gateway (such as 10.2.13.2 for PC-A and 10.2.32.2 for PC-B), then both PCs can be ping each others.
    How can I solve the problems if I've to use HSRP IP as default gateway?

    I don't get it. What is the significance of standby 1 and 2 VS standby 14 and 40? The only difference I noticed is the lower number of standby group goes with primry and higher goes with secondary.
    If possible, can you also try the same config you used before except swapping the group number?
    e.g.
    interface VLAN 32
    ip address 10.10.13.2 255.255.255.0 secondary
    ip address 10.10.32.2 255.255.248.0
    standby 40 ip 10.10.13.3
    standby 14 ip 10.10.32.3

  • When ever  enter the date start date up to next year same date between the days divided into 8 parts

    when ever  enter the date start date up to next year same date between the days divided into 8 parts
    Q1.1 (YYYY) = 1st half of Quarter 1 for year YYYY
    Q1.2 (YYYY) = 2nd half of Quarter1 for year YYYY
    Q2.1 (YYYY) = 1st half of Quarter 2 for year YYYY
    Q2.2 (YYYY) = 2nd half of Quarter 2 for year YYYY
    Q3.1 (YYYY) = 1st half of Quarter 3 for year YYYY
    Q3.2 (YYYY) = 2nd half of QuarterQ3 for year YYYY
    Q4.1 (YYYY) = 1st half of Quarter 4 for year YYYY
    Q4.2 (YYYY) = 2nd half of Quarter 4 for year YYYY
    Here YYYY depicts the year.
    e.g. Q1.2 (2014) depicts the 2nd half of Quarter 1 for year 2014.
    The description of these values are explained below.
    The table below provides the description about each value:
    Quarter     Quarter Range      Start Date
    Q1.1      1 Jan - 15 Feb         1st  Jan
    Q1.2      16 Feb-31 Mar         16th Feb
    Q2.1      1 Apr- 15 May          1st Apr
    Q2.2      16 May-30 June       16th May
    Q3.1      1 Jul-15 Aug             1th Jul
    Q3.2      16 Aug -30 Sep       16th Aug
    Q4.1      1 Oct -15 Nov           1st Oct
    Q4.2      16 Nov – 31 Dec      16th Nov
    The dropdown values in time window needs to be updated as per date entered by the user in the Audit Plan start date and
    should display the next four Quarter (each divided in 2 half  i.e. Eight values ) along with the year  from the selected Audit plan start date.
    for eg. If the Plan start date is given as August 10 2013 then the Time window will display the following options:                      
    Q3.2 (2013)                
    Q 4.1 (2013)               
    Q 4.2 (2013)               
    Q 1.1 (2014)               
    Q1.2 (2014)                
    Q2.1 (2014)                
    Q 2.2 (2014)               
    Q 3.1 (2014)               
    You can refer to the Table above and look that 10 Aug 2013 falls under the Q3.1 so Time window will display the next next 8 half Quarters ( Total 4 Quarter) till Q 3.1 for the year 2014.

    Hello,
    WITH half_quarters AS(
        SELECT  ADD_MONTHS(TRUNC(DATE '2013-08-15','Q'), 3*(LEVEL - 1)) hq_start
               ,1 part
        FROM    dual
        CONNECT BY ROWNUM <= 5
        UNION ALL
        SELECT  ADD_MONTHS(TRUNC(DATE '2013-08-15','Q'), 3*(LEVEL - 1) + 1) + 15 hq_start
               ,2 part
        FROM    dual
        CONNECT BY ROWNUM <= 5
    ,ordered_half_quarters AS(
        SELECT  hq_start
               ,part
               ,ROW_NUMBER() OVER (ORDER BY hq_start) r
        FROM    half_quarters
        WHERE   hq_start > DATE '2013-08-15'
    SELECT  'Q '||TO_CHAR(hq_start,'Q')||'.'||part||' ('||TO_CHAR(hq_start,'YYYY')||')' q
    FROM    ordered_half_quarters
    WHERE   r <= 8
    ORDER BY r;
    Q       
    Q 3.2 (2013) 
    Q 4.1 (2013) 
    Q 4.2 (2013) 
    Q 1.1 (2014) 
    Q 1.2 (2014) 
    Q 2.1 (2014) 
    Q 2.2 (2014) 
    Q 3.1 (2014) 
    half_quarters generates the start dates of every half of a quarter, starting with the begin of the first quarter that contains the sample date.
    The next step is to order the dates and to select only those after the sample date.
    The last part formats the output and orders the data.
    Regards
    Marcus

  • Load balancing within the same ACE across two different contexts residing on the same vlan

    I'm working on a design that requires traffic be sent to a different context in the same ACE. The question I have is can this be done when both reside on the same VLAN. Would the traffic in this case be handled at layer 2 instead of layer 7. Would I have to create a seperate subnet in order to provide loadbalancing?
    |__________________|
    |   | vlan 5         |         |
        |                  |
        |                  |
    Context A        |
                           |
                           |
                        Context B
    Thanks, Jerilyn

    by design, two contexts on the same box in the same vlan can't communicate. You have to use an external L3 device.
    A workaround may be to use two diferent vlans and then bridge between them with a loopback cable.

  • FCIP Peer in the same VLAN

    Hi,
    I will have 2 data centre connected with a 1gb possibly 2 x 1gb ethernet link.
    There will be some 802.q trunking between location and some traffic will be routed.
    I have the option of having my FCIP peer in the same vlan and carried in the trunk. Or have them in different VLAN and routed between location.
    Initiallay I though routed would be good because I can use QoS to prioritise FCIP traffice.
    But could I still achieve this using single vlan. and is it allowed.
    both site are connect using 6509 with sup720s
    Thanks
    John

    Hi John,
    For the FCIP link it is just an IP connectivity. So, you can do in both ways as you describe. You can route it or use a vlan. Just make sure that you have no too hign RTT. And also there RTT timout setting on FCIP you can play with that according to your RRT in your network.
    Thanks,
    Hakan.

  • ACE30_MOD-K9 in bridge mode. Individual servers in the same vlan of rserver not reach.

    I configured ACE30-MOD-K9 in bridge mode and I configured a server farm with his real servers. The traffic passes and is balanced correctly between all RSERVER. But I can not contact a server that is on the same vlan of the serverpharm but doesn't belong at this serverfarm.
    I Thought that the traffic directed to this "spare" server shouldn't  be balanced but the bridge should permit traffic to pass. (trasperent mode) Is it correct ?
    What does ACE in bridge mode with traffic directed to servers that do not belong to any server farm but are present on the same VLAN (same bridge group)?
    In rispect at the following configuration 10.10.10.168 isn't reacheable
    access-list INBOUND line 8 extended permit ip any any
    access-list INBOUND line 16 extended permit icmp any any
    probe http HTTP_PROBE1
      expect status 200 200
    rserver host RS_WEB1
      ip address 10.10.10.163
      inservice
    rserver host RS_WEB2
      ip address 10.10.10.164
      inservice
    rserver host RS_WEB3
      ip address 10.10.10.165
      inservice
    rserver host RS_WEB4
      ip address 10.10.10.167
      inservice
    serverfarm host SF_FIREGROUP
      rserver RS_WEB1
        inservice
      rserver RS_WEB2
        inservice
      rserver RS_WEB3
        inservice
      rserver RS_WEB4
        inservice
    sticky ip-netmask 255.255.255.255 address source sticky-ip
      replicate sticky
      serverfarm SF_FIREGROUP
    sticky http-cookie myCookie sticky-cookie
      cookie insert browser-expire
      serverfarm SF_FIREGROUP
    class-map match-any VS_FIREGROUP
      2 match virtual-address 10.10.10.169 tcp eq www
      4 match virtual-address 10.10.10.169 tcp eq 8081
      5 match virtual-address 10.10.10.169 tcp eq 8082
      6 match virtual-address 10.10.10.169 tcp eq 8083
      7 match virtual-address 10.10.10.169 tcp eq 8084
      8 match virtual-address 10.10.10.169 tcp eq 8085
      9 match virtual-address 10.10.10.169 tcp eq 8097
    class-map match-any VS_FIREGROUP_HTTPS
      2 match virtual-address 10.10.10.169 tcp eq https
    policy-map type loadbalance first-match HTTP
      class class-default
        sticky-serverfarm sticky-cookie
    policy-map type loadbalance first-match HTTPS
      class class-default
        sticky-serverfarm sticky-ip
    policy-map multi-match HTTP_HTTPS_MULTI_MATCH
      class VS_FIREGROUP
        loadbalance vip inservice
        loadbalance policy HTTP
        loadbalance vip advertise active
      class VS_FIREGROUP_HTTPS
        loadbalance vip inservice
        loadbalance policy HTTPS
        loadbalance vip advertise active
    interface vlan 4
      bridge-group 1
      access-group input INBOUND
      service-policy input HTTP_HTTPS_MULTI_MATCH
      no shutdown
    interface vlan 700
      bridge-group 1
      access-group input INBOUND
      no shutdown
    interface bvi 1
      ip address 10.10.10.150 255.255.255.0
      no shutdown
    ip route 0.0.0.0 0.0.0.0 10.10.10.1
    Thanks a lot
    Francesco

    Hi Francesco,
    Just to add more a bit, A bridge group is very similar to routed mode except ACE cannot NAT pass through traffic, vlan's cannot be shared and couple of other things but client's should be able to access the server as in before.
    But also whether in bridge or routed mode, ACE does create flows and applies other security parameters if configured to the traffic. This is for security. Also, ACE should know the MAC of the device to forward the traffic to. Can you check if ACE has the MAC of the destination? You can also put a route for testing purpose and see if that resolves the issue. That should probably be the quickest way to check if ACE is creating any issue here.
    Regards,
    Kanwal

  • Hello! I have configured my Wireless network to support bonjour protocol. When I support mDNS in the same Vlan I can see the Apple TV with my iPhone, but I cannot see it with my iPad.

    Hello! I have configured my Wireless network to support bonjour protocol. When I support mDNS in the same Vlan I can see the Apple TV with my iPhone, but I cannot see it with my iPad. Someone know if there is any different in the Bonjour protocol between the iPhone and the iPad???
    It is like if the iPad changes the process at some point...
    Thank you!

    You don't need to configure anything specific for it to work unless you had some special filtering in place already.
    What do you mean specificly by can not "see" it with your iPad?

Maybe you are looking for