ACE balancing problems
Hi everyone.
We have a customer who has a server farm formed by 3 servers with the following real ip address:
10.10.24.5-6-7 and a virtual 10.10.24.3 as configured in the ace module.
We found the following behavior in the session number of the servers. We can conclude that there is a server with much more sessions than the others (10.10.24.6):
Can sombody help me telling why can happen that?
I am attaching the ACE config as a reference
Thanks
ACE-DIGENERAL/OCS# sh serverfarm Herramientas_Col
serverfarm : Herramientas_Col, type: HOST
total rservers : 3
----------connections-----------
real weight state current total
---+---------------------+------+------------+----------+--------------------
rserver: SP1
10.10.24.5:0 8 OPERATIONAL 390 296043280
rserver: SP2
10.10.24.6:0 8 OPERATIONAL 1003 3371471400
rserver: SP3
10.10.24.7:0 8 OPERATIONAL 354 164816790
Como se puede observar el sever 10.10.24.6 posee mas del doble de conexiones que los otros 2.
5. En el siguiente pantallazo también se observan conexiones detalladas y los puertos por donde habla:
ACE-DIGENERAL/OCS# sh conn serverfarm Herramientas_Col
conn-id np dir proto vlan source destination state
----------+--+---+-----+----+---------------------+---------------------+------+
70 1 in TCP 951 10.10.22.13:3837 10.10.24.3:80 ESTAB
17239 1 out TCP 324 10.10.24.7:80 10.10.22.13:3837 ESTAB
76 1 in TCP 951 10.83.21.32:1419 10.10.24.3:80 ESTAB
5531 1 out TCP 324 10.10.24.6:80 10.83.21.32:1419 ESTAB
95 1 in TCP 951 10.20.7.51:1702 10.10.24.3:80 ESTAB
16237 1 out TCP 324 10.10.24.6:80 10.20.7.51:1702 ESTAB
98 1 in TCP 951 10.80.31.55:3188 10.10.24.3:80 ESTAB
11995 1 out TCP 324 10.10.24.6:80 10.80.31.55:3188 ESTAB
32749 1 in TCP 951 10.80.21.23:1926 10.10.24.3:80 ESTAB
108 1 out TCP 324 10.10.24.7:80 10.80.21.23:1926 ESTAB
110 1 in TCP 951 10.25.14.231:1705 10.10.24.3:80 ESTAB
37994 1 out TCP 324 10.10.24.6:80 10.25.14.231:1705 ESTAB
7438 1 in TCP 951 10.31.102.32:2329 10.10.24.3:80 ESTAB
141 1 out TCP 324 10.10.24.7:80 10.31.102.32:2329 ESTAB
31247 1 in TCP 951 10.81.36.32:1650 10.10.24.3:80 ESTAB
151 1 out TCP 324 10.10.24.5:80 10.81.36.32:1650 ESTAB
176 1 in TCP 951 10.20.208.124:2598 10.10.24.3:80 ESTAB
13219 1 out TCP 324 10.10.24.7:80 10.20.208.124:2598 ESTAB
32576 1 in TCP 951 10.233.9.40:1577 10.10.24.3:80 ESTAB
233 1 out TCP 324 10.10.24.6:80 10.233.9.40:1577 ESTAB
27499 1 in TCP 951 10.218.16.28:2902 10.10.24.3:80 ESTAB
244 1 out TCP 324 10.10.24.5:80 10.218.16.28:2902 ESTAB
248 1 in TCP 951 10.85.19.55:1540 10.10.24.3:80 ESTAB
14014 1 out TCP 324 10.10.24.7:80 10.85.19.55:1540 ESTAB
27166 1 in TCP 951 10.25.22.90:1766 10.10.24.3:80 ESTAB
254 1 out TCP 324 10.10.24.6:80 10.25.22.90:1766 ESTAB
380 1 in TCP 951 10.23.22.62:1855 10.10.24.3:80 ESTAB
11563 1 out TCP 324 10.10.24.6:80 10.23.22.62:1855 ESTAB
397 1 in TCP 951 10.212.35.30:1540 10.10.24.3:80 ESTAB
15491 1 out TCP 324 10.10.24.7:80 10.212.35.30:1540 ESTAB
35588 1 in TCP 951 10.100.30.5:1773 10.10.24.3:80 ESTAB
405 1 out TCP 324 10.10.24.6:80 10.100.30.5:1773 ESTAB
31392 1 in TCP 951 10.216.27.41:1524 10.10.24.3:80 ESTAB
449 1 out TCP 324 10.10.24.6:80 10.216.27.41:1524 ESTAB
592 1 in TCP 951 10.25.21.219:1364 10.10.24.3:80 ESTAB
2988 1 out TCP 324 10.10.24.5:80 10.25.21.219:1364 ESTAB
614 1 in TCP 951 10.25.42.221:1517 10.10.24.3:80 ESTAB
18877 1 out TCP 324 10.10.24.6:80 10.25.42.221:1517 ESTAB
21553 1 in TCP 951 10.80.39.123:1634 10.10.24.3:80 ESTAB
652 1 out TCP 324 10.10.24.6:80 10.80.39.123:1634 ESTAB
13640 1 in TCP 951 10.206.2.34:1385 10.10.24.3:80 ESTAB
708 1 out TCP 324 10.10.24.6:80 10.206.2.34:1385 ESTAB
26959 1 in TCP 951 10.100.30.7:1289 10.10.24.3:80 ESTAB
719 1 out TCP 324 10.10.24.5:80 10.100.30.7:1289 ESTAB
29277 1 in TCP 951 10.100.202.50:1248 10.10.24.3:80 ESTAB
758 1 out TCP 324 10.10.24.5:80 10.100.202.50:1248 ESTAB
6185 1 in TCP 951 10.25.27.222:1497 10.10.24.3:80 ESTAB
760 1 out TCP 324 10.10.24.6:80 10.25.27.222:1497 ESTAB
767 1 in TCP 951 10.97.21.28:1821 10.10.24.3:80 ESTAB
23511 1 out TCP 324 10.10.24.7:80 10.97.21.28:1821 ESTAB
826 1 in TCP 951 10.31.105.140:3810 10.10.24.3:80 ESTAB
13460 1 out TCP 324 10.10.24.6:80 10.31.105.140:3810 ESTAB
21987 1 in TCP 951 10.25.31.213:1855 10.10.24.3:80 ESTAB
839 1 out TCP 324 10.10.24.5:80 10.25.31.213:1855 ESTAB
874 1 in TCP 951 10.88.29.27:1503 10.10.24.3:80 ESTAB
29839 1 out TCP 324 10.10.24.6:80 10.88.29.27:1503 ESTAB
945 1 in TCP 951 10.27.122.13:1286 10.10.24.3:80 ESTAB
32298 1 out TCP 324 10.10.24.6:80 10.27.122.13:1286 ESTAB
24330 1 in TCP 951 10.40.21.50:2368 10.10.24.3:80 ESTAB
954 1 out TCP 324 10.10.24.6:80 10.40.21.50:2368 ESTAB
961 1 in TCP 951 10.80.26.76:1414 10.10.24.3:80 ESTAB
11176 1 out TCP 324 10.10.24.5:80 10.80.26.76:1414 ESTAB
28989 1 in TCP 951 10.91.22.38:1408 10.10.24.3:80 ESTAB
985 1 out TCP 324 10.10.24.5:80 10.91.22.38:1408 ESTAB
1006 1 in TCP 951 10.217.4.20:1522 10.10.24.3:80 ESTAB
26946 1 out TCP 324 10.10.24.5:80 10.217.4.20:1522 ESTAB
8360 1 in TCP 951 10.11.3.28:1679 10.10.24.3:80 ESTAB
1020 1 out TCP 324 10.10.24.6:80 10.11.3.28:1679 ESTAB
9498 1 in TCP 951 10.25.42.221:1519 10.10.24.3:80 ESTAB
1031 1 out TCP 324 10.10.24.6:80 10.25.42.221:1519 ESTAB
18510 1 in TCP 951 10.165.55.51:1232 10.10.24.3:80 ESTAB
1072 1 out TCP 324 10.10.24.7:80 10.165.55.51:1232 ESTAB
5583 1 in TCP 951 10.25.14.12:2086 10.10.24.3:80 ESTAB
1142 1 out TCP 324 10.10.24.6:80 10.25.14.12:2086 ESTAB
39713 1 in TCP 951 10.25.36.58:1663 10.10.24.3:80 ESTAB
1144 1 out TCP 324 10.10.24.7:80 10.25.36.58:1663 ESTAB
8601 1 in TCP 951 10.217.26.34:1677 10.10.24.3:80 ESTAB
1167 1 out TCP 324 10.10.24.6:80 10.217.26.34:1677 ESTAB
17209 1 in TCP 951 10.165.40.45:1526 10.10.24.3:80 ESTAB
1173 1 out TCP 324 10.10.24.5:80 10.165.40.45:1526 ESTAB
18708 1 in TCP 951 10.31.105.137:3714 10.10.24.3:80 ESTAB
1175 1 out TCP 324 10.10.24.6:80 10.31.105.137:3714 ESTAB
1180 1 in TCP 951 10.201.18.40:4777 10.10.24.3:80 ESTAB
6528 1 out TCP 324 10.10.24.6:80 10.201.18.40:4777 ESTAB
1214 1 in TCP 951 10.31.104.46:1501 10.10.24.3:80 ESTAB
5924 1 out TCP 324 10.10.24.6:80 10.31.104.46:1501 ESTAB
1228 1 in TCP 951 10.231.37.32:1161 10.10.24.3:80 ESTAB
15171 1 out TCP 324 10.10.24.6:80 10.231.37.32:1161 ESTAB
28431 1 in TCP 951 10.25.5.76:2317 10.10.24.3:80 ESTAB
1293 1 out TCP 324 10.10.24.5:80 10.25.5.76:2317 ESTAB
1328 1 in TCP 951 10.201.2.26:1293 10.10.24.3:80 ESTAB
19276 1 out TCP 324 10.10.24.7:80 10.201.2.26:1293 ESTAB
1356 1 in TCP 951 10.80.23.27:1396 10.10.24.3:80 ESTAB
4141 1 out TCP 324 10.10.24.6:80 10.80.23.27:1396 ESTAB
1368 1 in TCP 951 10.80.36.124:1428 10.10.24.3:80 ESTAB
19905 1 out TCP 324 10.10.24.6:80 10.80.36.124:1428 ESTAB
30280 1 in TCP 951 10.25.8.11:4836 10.10.24.3:80 ESTAB
1438 1 out TCP 324 10.10.24.6:80 10.25.8.11:4836 ESTAB
1478 1 in TCP 951 10.216.6.46:4153 10.10.24.3:80 ESTAB
12312 1 out TCP 324 10.10.24.6:80 10.216.6.46:4153 ESTAB
23389 1 in TCP 951 10.211.30.38:1593 10.10.24.3:80 ESTAB
1527 1 out TCP 324 10.10.24.6:80 10.211.30.38:1593 ESTAB
1562 1 in TCP 951 10.90.21.58:2889 10.10.24.3:80 ESTAB
36398 1 out TCP 324 10.10.24.7:80 10.90.21.58:2889 ESTAB
1587 1 in TCP 951 10.84.22.29:2121 10.10.24.3:80 ESTAB
37031 1 out TCP 324 10.10.24.6:80 10.84.22.29:2121 ESTAB
1624 1 in TCP 951 10.25.21.218:1465 10.10.24.3:80 ESTAB
4941 1 out TCP 324 10.10.24.6:80 10.25.21.218:1465 ESTAB
Hello!
A "show connection serverfarm Herramientas_Col detail" and "show sticky database group POOL3" would be handy in this situation. You have sticky configured which will intentionally throw off the loadbalancing predictor. My guess at this point is that rserver SP2 might not close connections in the same manner that SP1 and SP3 do. If that was true, that would result in a longer connection time, which means the sticky database would not idle out as fast, hence more connection for SP2.
Regards,
Chris
Similar Messages
-
Hi,
I have ACE 4701 with c4710ace-mz.A3_2_2.bin image. In the current setup ACE is located in the center of network where all the WAN, Intenret and LAN is connected and ACE has default towards Internet and All other segment has default route towards ACE appliance. ACe is only redirecting the port 80 traffic to my Proxy server and bypass my lan subnet on port 80.
Internet
i
i
i
i
i
ACE--------------------------------WAN
i
i
i
i
LAN
I want to use ACE for the load balancing of two servers. Today I did the load balancing configuration but as soon as I applied the policy map on the interface vlan 200 and 300, my complete network reachability went down. When I remove the policy my network came back to normal.
192.168.200.66 FAX Server-1
192.1168.200.67 FAX Server-2
192.168.200.65 Virtual IP address
Attached is the configuration that I did on ACE for the load balancing and below is the current configuration of the ACE appliance.
access-list acl-in remark ACCESS LIST FOR ACE-INSIDE
access-list acl-in line 1 extended permit ip any any
access-list acl-out remark ACCESS LIST FOR ACE-OUTSIDE
access-list acl-out line 1 extended permit ip any any
access-list acl-proxy remark ACCESS LIST FOR PROXY SEGMENT
access-list acl-proxy line 1 extended permit ip any any
access-list acl-wan remark ACCESS LIST FOR WAN SEGMENT
access-list acl-wan line 1 extended permit ip any any
probe tcp PROBE_5050
port 5050
interval 15
passdetect interval 60
open 1
probe tcp PROBE_5101
port 5101
interval 15
passdetect interval 60
open 1
probe tcp PROBE_TCP
port 80
interval 15
passdetect interval 60
open 1
parameter-map type http PARAMAP_CASE
case-insensitive
no persistence-rebalance
rserver host RS_BCPR01
ip address 192.168.0.103
inservice
rserver host RS_BCPR02
ip address 192.168.0.104
inservice
rserver host RT_fax1
description Right Fax Server-1
ip address 192.168.200.66
rserver host RT_fax2
description Right Fax Server-2
ip address 192.168.200.67
serverfarm host SF_BCPR
transparent
probe PROBE_5050
probe PROBE_5101
probe PROBE_TCP
rserver RS_BCPR01
inservice
rserver RS_BCPR02
inservice
serverfarm host SF_RT_fax
rserver RT_fax1
rserver RT_fax2
sticky ip-netmask 255.255.255.255 address source STICKY-SOURCE
replicate sticky
serverfarm SF_BCPR
sticky ip-netmask 255.255.255.255 address source FAX-STICKY
replicate sticky
serverfarm SF_RT_fax
class-map type management match-any CM_ALL
2 match protocol snmp any
3 match protocol http any
4 match protocol https any
5 match protocol icmp any
6 match protocol telnet any
class-map match-any CM_BYPASS_FOR_LAN
3 match virtual-address 100.1.1.0 255.255.255.0 tcp eq www
8 match virtual-address 10.0.0.0 255.0.0.0 tcp eq www
9 match virtual-address 172.16.0.0 255.255.0.0 tcp eq www
10 match virtual-address 192.168.0.0 255.255.0.0 tcp eq www
class-map match-any CM_BYPASS_SUBNET
9 match virtual-address 100.0.0.0 255.0.0.0 tcp eq www
13 match virtual-address 10.0.0.0 255.0.0.0 tcp eq www
14 match virtual-address 172.16.0.0 255.255.0.0 tcp eq www
15 match virtual-address 192.168.0.0 255.255.0.0 tcp eq www
class-map match-any CM_IM
2 match virtual-address 0.0.0.0 0.0.0.0 tcp eq 5050
3 match virtual-address 0.0.0.0 0.0.0.0 tcp eq 1080
4 match virtual-address 0.0.0.0 0.0.0.0 tcp eq 5101
class-map match-all CM_SF_BCPR
255 match virtual-address 0.0.0.0 0.0.0.0 tcp eq www
class-map match-any RT_FAX
2 match virtual-address 192.168.200.65 0.0.0.0 any
policy-map type management first-match PM_ALL
class CM_ALL
permit
policy-map type loadbalance http first-match PM_L7_BYPASS_FOR_LAN_HTTP
class class-default
forward
policy-map type loadbalance http first-match PM_L7_BYPASS_HTTP
class class-default
forward
policy-map type loadbalance first-match PM_LB_RT_FAX
class class-default
sticky-serverfarm FAX-STICKY
policy-map type loadbalance http first-match PM_LB_SF_BCPROXY
class class-default
sticky-serverfarm STICKY-SOURCE
policy-map multi-match PM_BYPASS_FOR_LAN_HTTP
class CM_BYPASS_FOR_LAN
loadbalance vip inservice
loadbalance policy PM_L7_BYPASS_FOR_LAN_HTTP
policy-map multi-match PM_BYPASS_HTTP
class CM_BYPASS_SUBNET
loadbalance vip inservice
loadbalance policy PM_L7_BYPASS_HTTP
policy-map multi-match PM_MAIN_BCPROXY
class CM_SF_BCPR
loadbalance vip inservice
loadbalance policy PM_LB_SF_BCPROXY
loadbalance vip icmp-reply active
appl-parameter http advanced-options PARAMAP_CASE
class CM_IM
loadbalance vip inservice
loadbalance policy PM_LB_SF_BCPROXY
policy-map multi-match PM_RT_FAX
class RT_FAX
loadbalance vip inservice
loadbalance policy PM_LB_RT_FAX
service-policy input PM_ALL
interface vlan 100
description FW-INSIDE CONTEXT RACK1
ip address 192.168.0.5 255.255.255.224
alias 192.168.0.11 255.255.255.224
peer ip address 192.168.0.6 255.255.255.224
mac-address autogenerate
no icmp-guard
access-group input acl-out
no shutdown
interface vlan 200
description WAN-VLAN CONTEXT RACK1
ip address 192.168.0.33 255.255.255.224
alias 192.168.0.43 255.255.255.224
peer ip address 192.168.0.34 255.255.255.224
mac-address autogenerate
access-group input acl-wan
service-policy input PM_BYPASS_HTTP
service-policy input PM_MAIN_BCPROXY
no shutdown
interface vlan 300
description ACE-INSIDE CONTEXT RACK1
ip address 192.168.0.65 255.255.255.224
alias 192.168.0.73 255.255.255.224
peer ip address 192.168.0.66 255.255.255.224
mac-address autogenerate
access-group input acl-in
service-policy input PM_BYPASS_FOR_LAN_HTTP
service-policy input PM_BYPASS_HTTP
service-policy input PM_MAIN_BCPROXY
no shutdown
interface vlan 301
description BC-VLAN CONTEXT RACK1
ip address 192.168.0.97 255.255.255.224
alias 192.168.0.107 255.255.255.224
peer ip address 192.168.0.98 255.255.255.224
mac-address autogenerate
access-group input acl-proxy
no shutdown
ft track interface TRACKING_FOR_FT_VLAN
track-interface vlan 300
peer track-interface vlan 300
priority 255
peer priority 255
ip route 0.0.0.0 0.0.0.0 192.168.0.1
Please help me out what i am missing. Is there any limitation on policy map or my bypass subnet list is creating problem.I did these changes this time nothing disconnected but I am not able to do the Remote desktop on the virtual IP address. Real IP has Remote desktop enabled even VIP is not ping able for me.
rserver host RT_fax1
description Right Fax Server-1
ip address 192.168.200.66
inservice
rserver host RT_fax2
description Right Fax Server-2
ip address 192.168.200.67
inservice
serverfarm host SF_RT_fax
rserver RT_fax1
inservice
rserver RT_fax2
inservice
policy-map type loadbalance rdp first-match PM_LB_RT_FAX
class class-default
serverfarm SF_RT_fax
policy-map multi-match PM_RT_FAX
class RT_FAX
loadbalance vip inservice
loadbalance policy PM_LB_RT_FAX
loadbalance vip icmp-reply active
interface vlan 200
description WAN-VLAN CONTEXT RACK1
ip address 192.168.0.33 255.255.255.224
alias 192.168.0.43 255.255.255.224
peer ip address 192.168.0.34 255.255.255.224
mac-address autogenerate
access-group input acl-wan
service-policy input PM_BYPASS_HTTP
service-policy input PM_MAIN_BCPROXY
service-policy input PM_RT_FAX
no shutdown
interface vlan 300
description ACE-INSIDE CONTEXT RACK1
ip address 192.168.0.65 255.255.255.224
alias 192.168.0.73 255.255.255.224
peer ip address 192.168.0.66 255.255.255.224
mac-address autogenerate
access-group input acl-in
service-policy input PM_BYPASS_FOR_LAN_HTTP
service-policy input PM_BYPASS_HTTP
service-policy input PM_MAIN_BCPROXY
service-policy input PM_RT_FAX
no shutdown
But nothing is working for me. Please help me out. This time i didnt configure the sticky. But in real I will go with sticky and complete IP protocol will be use a VIP. Please help me out. -
ACE Routing Load-Balance problem
I'm trying to configure a routing load-balance with Cisco ACE Module based on the following scenario:
local users has a router (R1) as it default gateway, this router (R1) has a default route to the VIP that represent the serverfarm with two linux servers that should be used for Data Shaping over the WAN. I need to balance the traffic over the two linux servers and not necessary over the WAN.
The problem is that when I set up the local network router default route to VIP the routing process simply stop work ! If I change the route to the real server ip address everything start working again without any problem.
Follow the configs:
Local network Router - Static route
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
ip route 0.0.0.0 255.255.255.0 10.0.0.1 (VIP address)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Follow the ACE configs:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
access-list 100 line 8 extended permit ip any any
rserver host rout001
ip address 10.0.0.32
inservice
rserver host rout002
ip address 10.0.0.31
inservice
serverfarm host BLC_ROUTING
predictor leastconns
rserver rout001
inservice
rserver rout002
inservice
class-map match-any VIP
2 match virtual-address 10.0.0.1 any
class-map type management match-any mgmt
2 match protocol icmp any
3 match protocol telnet any
4 match protocol ssh any
policy-map type management first-match access
class mgmt
permit
policy-map type loadbalance first-match INT_router
class class-default
serverfarm BLC_ROUTING
policy-map multi-match VIP
class VIP
loadbalance vip inservice
loadbalance policy INT_router
loadbalance vip icmp-reply
interface vlan 6
bridge-group 10
access-group input 100
service-policy input access
service-policy input VIP
no shutdown
interface vlan 8
bridge-group 10
access-group input 100
service-policy input access
service-policy input VIP
no shutdown
interface bvi 10
ip address 10.0.0.5 255.255.255.0
no shutdown
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
I tried to change some parameters like "transparent" at serverfarm config and change the "predictor" method to "hash address source" but there was no good results at all.
Anyone has any idea why this process is not working ?
Is there any special configuration for this scenario ?
Regards,
RicardoRicardo,
What is this route ??
ip route 0.0.0.0 255.255.255.0 10.0.0.1 (VIP address)
You can't have 0.0.0.0/24.
You must be missing something ?
Also, since the vip is part of a vlan with subnet 10.0.0.0/24 you don't need to add a static route to reach that vip.
It should normally be directly connected to your router.
With the static route, do you see traffic coming to the ACE module ?
Does it loadbalance to the server ?
'show service-policy detail' check the packet counters
Gilles. -
ACE balance cookie + https
Hello Everyone,
i have a ACE 4400 Appliance, for balance some applications on the network.
i have one application(citrix), the connection to this site is https(443).
I had a balance of cookie, plus this only worked if I left only one server in "inservice" on Serverfarm if I add the second, the application showed me a scree saying "your web interface session is in an inconsistent state."
Since the above problems, I set the cookie for connection to work with "persistence rebalance," but the problem continued.
After I passed the Serverfarm to be balanced by source IP, the troubles are over, I kept the persistence rebalance.
Now comes the question, why not work with cookie? https does not work if the balancing change something in the package, such as information inside a cookie?
Old configuration:
sticky http-cookie NFUSE-COOKIE STICKY-HIAE-NFUSE-COOKIE
cookie insert browser-expire
replicate sticky
serverfarm SF-HIAE-NFUSE
Current Configuration:
sticky ip-netmask 255.255.255.255 address source STICKY-HIAE-TESTE-NFUSE
replicate sticky
serverfarm SF-HIAE-NFUSE
Class/Policy and Parameter map.
class-map match-all VS-HIAE-NFUSE
2 match virtual-address 192.168.16.30 tcp any
policy-map type loadbalance first-match VS-HIAE-NFUSE-l7slb
class class-default
sticky-serverfarm STICKY-HIAE-TESTE-NFUSE
class VS-HIAE-NFUSE
loadbalance vip inservice
loadbalance policy VS-HIAE-NFUSE-l7slb
loadbalance vip icmp-reply active primary-inservice
appl-parameter http advanced-options HTTP-OPTS
parameter-map type http HTTP-OPTS
persistence-rebalance
Tks a lot.
Rafael MendesRealized the configuration as specified in the link.
Apparently, everything ok.
However, I can not access the page using internet explorer. I tested with firefox, safari, opera, everything works with internet explorer not.
Configuration follows below, is something wrong?
Thanks.
serverfarm host SF-HIAE-NFUSE
description Servidores nfuse.einstein.br
rserver WPVAP06
inservice
rserver WPVAP07
inservice
parameter-map type generic sslidparam
set max-parse-length 70
sticky layer4-payload STICK-L4-NFUSE-SSL
serverfarm SF-HIAE-TESTESSLTERM
response sticky
layer4-payload offset 43 length 32 begin-pattern "\x20"
class-map match-all VS-L4-NFUSE-SSL-TERMINATOR
2 match virtual-address 192.168.16.254 tcp eq https
policy-map type loadbalance generic first-match VS-HIAE-TESTESSLTERM
class class-default
sticky-serverfarm STICK-L4-NFUSE-SSL
policy-map multi-match int10
class VS-L4-NFUSE-SSL-TERMINATOR
loadbalance vip inservice
loadbalance policy VS-HIAE-TESTESSLTERM
loadbalance vip icmp-reply active primary-inservice
appl-parameter generic advanced-options sslidparam -
ACE : Stickyness problem with http cookies
Hi,
I am facing a serious problem with stickyness in a e-commerce configuration.
Here is the setup :
An ACE load balance user requests on two Apache servers
cookie-insert is used to stick a user on one Apache server
The home page is accessed via http on port 80
On the Home page, there is a link to allowing the user to login
The login process uses SSL
During the login, backend SSL is required between the ACE and the selected Apache server
The login is a POST request to the Apache server
After a successful login, the home page is reloaded on port 80 and the name of the user should appear on the top of the page
The ACE configuration :
Two sticky groups are configured : one for HTTP acess and another for HTTPS access
Two server farms are defined, both using the same real servers, but with different ports (80 and 441)
sticky http-cookie STICKED-TO ECOM_STICKY_TEST_HTTP
cookie insert browser-expire
timeout 240
replicate sticky
serverfarm ECOM_FARM_TEST_HTTP
sticky http-cookie STICKED-TO ECOM_STICKY_TEST_HTTPS
cookie insert browser-expire
timeout 240
replicate sticky
serverfarm ECOM_FARM_TEST_HTTPS
serverfarm host ECOM_FARM_TEST_HTTP
description *** e-Commerce Test Server Farm ***
probe ECOM_PROBE_TEST
rserver HQCHECOM01 80
inservice
rserver HQCHECOM02 80
inservice
serverfarm host ECOM_FARM_TEST_HTTPS
description *** e-Commerce Test Server Farm ***
probe ECOM_PROBE_TEST
rserver HQCHECOM01 443
inservice
rserver HQCHECOM02 443
inservice
The problem :
Let analyse the sequence of events and the value of the http cookie for each of them :
When the the home page is originally loaded, the ACE selects SERVER-1
The ACE inserts the cookie "A" in the server responses
The user is sticked to SERVER-1
Then, the user tries to login and an SSL session is established with the ACE
The user sends a POST request containing the cookie "A"
A backend SSL session is established with SERVER-1
The POST request is forwarded to SERVER-1
SERVER-1 responds with a 200 OK and the ACE generates another cookie "B" as it belongs to the sticky group ECOM_STICKY_TEST_HTTPS
The client browser reloads the page on port 80 and provides the cookie "B" (the last received) !!
The ACE sees the cookie "B" but does not find it in its database for the sticky group ECOM_STICKY_TEST_HTTP
The ACE perform another load balancing decision and selects SERVER-2 ! (instead of SERVER-1)
The page is reloaded, but the name of the user does not appear on it
The question :
As it is not possible to have only one sticky group in this configuration what would be the solution to make sure that the same server is selected for http and https ?
Thank you for any hints,
YvesHi Gilles,
I followed your recommendation to configure static cookie entries in each sticky group, but I still experience the problem of sessions getting re-load balanced to the second server when returning from HTTPS to HTTP :
It seems that the ACE ignores the static entries !
To make my question clear, I repeat hereafter the setup and the encountered problem :
Here is the setup :
An ACE load balance user requests on two Apache servers
cookie-insert is used to stick a user on one Apache server
The home page is accessed via http on port 80
On the Home page, there is a link to allowing the user to login
The login process uses SSL
During the login, backend SSL is required between the ACE and the selected Apache server
The login is a POST request to the Apache server
After a successful login, the home page is reloaded on port 80 and the name of the user should appear on the top of the page
The ACE configuration :
Two sticky groups are configured : one for HTTP acess and another for HTTPS access
Two server farms are defined, both using the same real servers, but with different ports (80 and 443)
In the ECOM_STICKY_TEST_HTTP stick group the two following cookies are automatically generated :
R105816849 for the server HQCHECOM01
R105852786 for the server HQCHECOM02
In the ECOM_STICKY_TEST_HTTPS stick group the two following cookies are automatically generated :
R355972695 for the server HQCHECOM01
R357158616 for the server HQCHECOM02
I statically configured in the each sticky group the cookies used by the other sticky group, to allow stickiness when the browser switches from HTTP to HTTPS and vice versa :
sticky http-cookie STICKED-TO ECOM_STICKY_TEST_HTTP
cookie insert browser-expire
timeout 240
replicate sticky
serverfarm ECOM_FARM_TEST_HTTP backup WEB_REDIRECT_001
56 static cookie-value "R355972695" rserver HQCHECOM01
64 static cookie-value "R357158616" rserver HQCHECOM02
sticky http-cookie STICKED-TO ECOM_STICKY_TEST_HTTPS
cookie insert browser-expire
timeout 240
replicate sticky
serverfarm ECOM_FARM_TEST_HTTPS backup WEB_REDIRECT_001
72 static cookie-value "R105816849" rserver HQCHECOM01
80 static cookie-value "R105852786" rserver HQCHECOM02
serverfarm host ECOM_FARM_TEST_HTTP
description *** e-Commerce Test Server Farm ***
probe ECOM_PROBE_TEST
rserver HQCHECOM01 80
inservice
rserver HQCHECOM02 80
inservice
serverfarm host ECOM_FARM_TEST_HTTPS
description *** e-Commerce Test Server Farm ***
probe ECOM_PROBE_TEST
rserver HQCHECOM01 443
inservice
rserver HQCHECOM02 443
inservice
The problem :
Let analyse the sequence of events and the value of the http cookie for each of them :
When the the home page is originally loaded, the ACE selects SERVER-1
The ACE inserts the cookie "A" in the server responses
The user is sticked to SERVER-1
Then, the user tries to login and an SSL session is established with the ACE
The user sends a POST request containing the cookie "A"
A backend SSL session is established with SERVER-1
The POST request is forwarded to SERVER-1
SERVER-1 responds with a 200 OK and the ACE generates another cookie "B" as it belongs to the sticky group ECOM_STICKY_TEST_HTTPS
The client browser reloads the page on port 80 and provides the cookie "B" (the last received)
The ACE sees the cookie "B" and should use the static cookie entry to select the SERVER-1
But instead, the ACE perform another load balancing decision and selects SERVER-2 !
The page is reloaded, but the name of the user does not appear on it
LiveHTTP Trace on Firefox :
GET /ecom/medias/sys_master/8800775602206/Home-page-main-banners-video.jpg HTTP/1.1
Host: ecom.test.toto.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.8) Gecko/20100202 (CK-IBM) Firefox/3.5.8
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://ecom.test.toto.com/uk/en/home
Cookie: STICKED-TO=R105816849;
HTTP/1.1 200 OK
Set-Cookie: STICKED-TO=R105816849; path=/
Date: Mon, 18 Oct 2010 15:31:37 GMT
Server: Apache/2.2.13 (Red Hat)
Connection: close
Transfer-Encoding: chunked
Content-Type: image/jpeg
Here we switch on HTTPS :
https://ecom.test.toto.com/uk/en/j_spring_security_check
POST /uk/en/j_spring_security_check HTTP/1.1
Host: ecom.test.toto.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.8) Gecko/20100202 (CK-IBM) Firefox/3.5.8
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://ecom.test.toto.com/uk/en/home
Cookie: STICKED-TO=R105816849; JSESSIONID=089DCF987DC03CAE0F516298EB886DAB.node1;
Content-Type: application/x-www-form-urlencoded
Content-Length: 75
spring-security-redirect=&j_username=yves144%40yahoo.com&j_password=junon01
Here we see cookie for the same server but for the HTTPS sticky group :
HTTP/1.1 302 Moved Temporarily
Set-Cookie: STICKED-TO=R355972695; path=/
Set-Cookie: _hybris.tenantID_=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/; HttpOnly
Date: Mon, 18 Oct 2010 15:31:39 GMT
Server: Apache/2.2.13 (Red Hat)
Location: http://ecom.test.toto.com/uk/en/home
Content-Length: 0
Connection: close
Content-Type: text/plain; charset=UTF-8
Here we switch back to HTTP :
http://ecom.test.toto.com/uk/en/home
GET /uk/en/home HTTP/1.1
Host: ecom.test.toto.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.8) Gecko/20100202 (CK-IBM) Firefox/3.5.8
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://ecom.test.toto.com/uk/en/home
Cookie: STICKED-TO=R355972695; JSESSIONID=089DCF987DC03CAE0F516298EB886DAB.node1;
Here we see that the second server has been wrongly selected !
HTTP/1.1 200 OK
Set-Cookie: STICKED-TO=R105852786; path=/
Set-Cookie: _hybris.tenantID_=""; Expires=Thu, 01-Jan-1970 00:00:10 GMT; Path=/; HttpOnly
Set-Cookie: JSESSIONID=5A0F6EB8FBF63D5D0590FECEC62A302E.node2; Path=/; HttpOnly
Date: Mon, 18 Oct 2010 15:31:40 GMT
Server: Apache/2.2.13 (Red Hat)
Pragma: no-cache
Expires: Thu, 01 Jan 1970 00:00:00 GMT
Cache-Control: no-cache, no-store
Content-Language: en-GB
Connection: close
Transfer-Encoding: chunked
Content-Type: text/html;charset=UTF-8
http://ecom.test.toto.com/ecom/medias/sys_master/8796174057502/uk.gif
GET /ecom/medias/sys_master/8796174057502/uk.gif HTTP/1.1
Host: ecom.test.toto.com
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.1.8) Gecko/20100202 (CK-IBM) Firefox/3.5.8
Accept: image/png,image/*;q=0.8,*/*;q=0.5
Accept-Language: en-us,en;q=0.5
Accept-Encoding: gzip,deflate
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.7
Keep-Alive: 300
Connection: keep-alive
Referer: http://ecom.test.toto.com/uk/en/home
Cookie: STICKED-TO=R105852786; JSESSIONID=5A0F6EB8FBF63D5D0590FECEC62A302E.node2;
HTTP/1.1 200 OK
Set-Cookie: STICKED-TO=R105852786; path=/
Date: Mon, 18 Oct 2010 15:31:40 GMT
Server: Apache/2.2.13 (Red Hat)
Content-Length: 382
Connection: close
Content-Type: image/gif
Hypothesis :
It seems that the static entries are not considered by the ACE... -
Hi Folks,
We have ITS 6.20 Patch level 33 installed which connects to our R/3 system. We are trying to add multiple Agate servers (not multiple Agate processes) to one Wgate. We installed agates on two hosts, host1 and host2. We then installed wgate on host1 which we connected during the time of installation to agate on host2. It connected fine and we were able to get the webgui and also able to login to R/3 system. At that time we had problem in going to native ADM instance as we were getting http 500 error (we had re-installed ADM instance on both the hosts after the whole exercise of installating agate and wgate). Hoping that we can solve native ADM problem later, we added the the second agate which is on hosts1(the same host on which wgate is) by adding the entry for agate 2 in the wgate registry xml file.
<key name="Agates">
<key name="Agate1">
<value name="Host" type="text">host2</value>
<value name="PortAGate" type="text">sapavw00_******</value>
<value name="PortMManager" type="text">sapavwmm_******</value>
<value name="Type" type="text">1</value>
<value name="SncNameAGate" type="text"/>
<value name="SncNameWGate" type="text"/>
<value name="MultiProcess" type="text">no</value>
<value name="Available" type="text">yes</value>
</key>
<key name="Agate2">
<value name="Host" type="text">host1</value>
<value name="PortAGate" type="text">sapavw00_******</value>
<value name="PortMManager" type="text">sapavwmm_******</value>
<value name="Type" type="text">1</value>
<value name="SncNameAGate" type="text"/>
<value name="SncNameWGate" type="text"/>
<value name="MultiProcess" type="text">no</value>
<value name="Available" type="text">yes</value>
</key>
The second agate added fine and is doing load balancing as well as we can see requests getting routed to both the agate in the load balancing screen. However we are not able to access the global.srvc file under configuration->Performance->global services->All settings as we are getting the following message:
Error loading service file "global.srvc"!
Also when we go to services under configuration, we are getting a message "error accessing services directory!"
In default R/3 system also all the fields are empty although we had given the application server details while installing both the agates.
We are getting the below messages in diagnostics.log file:
2010-11-22T12:30:04.401 --- log opened -
A 2010-11-23T13:55:53.346 [agate,sapdiag ] 00, s00000000061DB140, CsRead returned rd=-100
2010-11-23T14:17:06.863 --- log closed -
2010-11-23T14:17:07.753 --- log opened -
A 2010-11-23T14:30:48.618 [agate,sapdiag ] 00, s00000000061DB220, Cannot handle request from login
A 2010-11-23T14:38:45.615 [agate, ] 00, s0000000000000000, WorkDoGetReq: ContReceiveContainer() failed, rc=0xffffffff
A 2010-11-23T14:38:45.615 [agate, ] 00, s0000000000000000, WorkDoWork: WorkDoGetReq() failed, rc=0xffffffff
A 2010-11-23T14:38:45.677 [agate,sapxgdk ] 00, s0000000000000000, ContSendContainer: FAILED, send length is 0
A 2010-11-23T14:38:50.958 [agate, ] 00, s0000000000000000, WorkDoGetReq: ContReceiveContainer() failed, rc=0xffffffff
A 2010-11-23T14:38:50.958 [agate, ] 00, s0000000000000000, WorkDoWork: WorkDoGetReq() failed, rc=0xffffffff
A 2010-11-23T14:38:50.974 [agate,sapxgdk ] 00, s0000000000000000, ContSendContainer: FAILED, send length is 0
Please let me know if this procedure of adding the agate was wrong or there are some parameter settings that we may have missed. Would it have been better to go for a single host wgate+agate installation on host1 and then add agate2 on host2?Hi Edgar,
Thanks for the reply. I had re-installed ADM instance on both the hosts after the whole exercise of installing agate and wgate.
Anyways, Now we have uninstalled the earlier instances on both hosts and installed wgate+agate on host1 as a single host installation and agate2 on host2. Then we added agate2 to wgate1 and load balancing is working fine. Now the issue of not being able to access the service file and directories, etc has also been resolved. The only problem that remains is that we are not able to go into the native ADM. We get a http 500 error, although the redirect URL is correct. Is the any additional setting required for that to happen? -
We need a load balancing setup that share the load for many web applications on multiple backend servers, but we don’t want the web apps to be activated on all backend servers at the same time. We want to configure all apps as “lazy” on all backend servers. They will then be activated when the first request to their DNS is made. Then the app is started on that backend server.
We have hundreds of apps and each backend server will become very slow if all apps are activated on all backend servers. The preferred solution would therefore be to not call all DNS names on all backend servers but to share the balance based on the DNS name in the requests. Sticky-session or sticky source-IP won’t be enough to solve this as they only stick to each user session.
If User-A request www.siteA.com he may be redirected to backend server 1 and then be kept there. But if User-B then requests the same www.siteA.com he may be redirected to backend server 2 and then be kept there. This means that the web application for siteA will be activated and loaded in both the backend servers. When we host hundreds of sites this will be a problem. We may have hundreds of backend servers but they will all end up loading all web apps over time and get out of memory.
The theory to get this work is a load balancer with the following logic:
1. A request for a certain DNS comes in. For example: www.siteA.com
2. Load balancer checks if this certain DNS has been redirected to a certain backend server before and if this server is alive
2.1. (If not redirected before): Redirect the request to the backend server with least load. Store the selected backend route based on the DNS name.
2.2. (If redirected before): Redirect the request to the assigned backend server for siteA.
3. If a backend server is down then all DNS requests to this server will be redirected to another backend server with least load. All requests to these DNS names will be assigned to this backend server instead.
h3. Example of set up
Many DNS to one IP
192.168.1.1 www.siteA.com
192.168.1.1 www.siteB.com
192.168.1.1 www.siteC.com
Frontend load balancer
192.168.1.1 (load balancer)
Backend app servers
192.168.2.2 (App server 1)
192.168.2.3 (App server 2)
192.168.2.4 (App server 3)
h3. Snapshot of servers during load
App server 1
www.siteA.com (Activated)
www.siteB.com (Lazy)
www.siteC.com (Lazy)
App server 2
www.siteA.com (Lazy)
www.siteB.com (Activated)
www.siteC.com (Lazy)
App server 3
www.siteA.com (Lazy)
www.siteB.com (Lazy)
www.siteC.com (Activated)Only from load balancing point of view cluster is not really needed.
apart from session replication and failover capabilities, few more benefits are there with clustering only if you are using a web server also.
Stuck threads can be due to lot's of problems like application issues, load issues etc, So first make sure you are getting stuck thread on both servers or only on one, if on one, then in this case your load balancing not working properly and sending more load to that server, and if you are getting stuck threads on both then try to add one more managed server.
Regards
Mukesh Negi
http://weblogicserveradministration.blogspot.com -
Load Balance Problem in Oracle RAC 10.2.0.4 (two nodes with CRS)
Hi all,
I have an Oracle RAC 10.2.0.4 with two nodes and I'm having problems with sessions load balance.
The problem is that all connections are going to the node which is enabled as 'master' in RAC, the node who has located .db resource in CRS.
If .db resource is located in node1 all connections are made in node1. In the same way, all connections are made in node2 when .db resource from CRS stack is located in node2.
The connections are made by a pool in Tomcat 6 using RAC service for made the connections.
Any idea?
Thanks in advance.
Here is an example of my net configuration:
listener.ora in node1:
LISTENER_RAC_NODE1 =
(DESCRIPTION_LIST =
(DESCRIPTION =
(ADDRESS = (PROTOCOL = TCP)(HOST = node1_vip)(PORT = 1525)(IP = FIRST))
(ADDRESS = (PROTOCOL = TCP)(HOST = node1)(PORT = 1525)(IP = FIRST))
tnsnames in node1:
LISTENERS_RAC =
(ADDRESS_LIST =
(ADDRESS = (PROTOCOL = TCP)(HOST = node1_vip)(PORT = 1525))
(ADDRESS = (PROTOCOL = TCP)(HOST = node2_vip)(PORT = 1525))
NODE1 =
(DESCRIPTION =
(ADDRESS = (PROTOCOL = TCP)(HOST = node1_vip)(PORT = 1525))
(ADDRESS = (PROTOCOL = TCP)(HOST = node1)(PORT = 1525))
(CONNECT_DATA =
(SERVER = DEDICATED)
(SERVICE_NAME = rac)
(INSTANCE_NAME = rac1)
RAC =
(DESCRIPTION =
(ADDRESS = (PROTOCOL = TCP)(HOST = node1_vip)(PORT = 1525))
(ADDRESS = (PROTOCOL = TCP)(HOST = node2_vip)(PORT = 1525))
(LOAD_BALANCE = yes)
(CONNECT_DATA =
(SERVER = DEDICATED)
(SERVICE_NAME = rac)
********************************************************It is my fault.
It was the connection service. I had one one with preferred option and one without it. Now is working well. -
Trail balance with legacy balances problem
Hi Experts,
Need yours input for me on trail balance amounts mismatch with Legacy system.
My client using the both systems legacy and sap.
Now client taking the reports from legacy for the legal submissions for this year08-09.
I have done matching each GL with Legacy GL. Some of them were talied and rest of not talied.
this includes recon a/c also.
for the expenses accounts i can make JV postings, but the problem is how to make postings
to the recon accounts.(customers, vendors etc)
we are here having a huge transactions and client doesnt want to dig out all each and every.
client wants to make the JVs differed figure for account heads instead of dig all.
please let me know the easy way or t.codes to adjust the figures in various accounts for trail balance.
Regards,
SomaHi,
My sincere advise is not just to go by an easy way..
Understand where there is a gap and why there is a gap, vendor wise for AP and customer wise in AR..
Then try posting the difference amounts into these accounts as you have done in the first case..
This is a little time consuming job but thats the best way. Dont just post the differences as tommorow reconciliation would be a problem.
Cheers
Redoxcube -
Sir,
My total Debit side & Credit side of Trail Balance is having some difference when i generating 1 day Trail Balance
how to rectify this or track this
Regards & Thanks
Rajesh B KThanks all Experts i good sol to my problem
i.e actually i m creating TB Templete with coreleated GL Acc missing when i run TB with Chart of Account
the result is fruitfull
once again thanks all of you
Regards
Rajesh B K -
Hi,
I have two CSS that I use to load balance RDP connections to two WTS servers. I dont have switch behind CSS so they are connected back-to-back via cable. All server facing ports (including back-to-back ports) are in the same VLAN.
CSS1 is primary for the VIP address and for redundant interface address, and CSS2 is standby.
So, when I connect WTS-1 to CSS-1 and WTS-2 to CSS-2, CSS1 sees both services as active and everything seems fine. If WTS-2 is disconnected, WTS2 service on CSS1 is down etc.
In sticky table, I can see that CSS1 is load balancing request to both servers, but the problem is that only RDP connections to WTS-1(server directly connected to CSS1) work fine , and connections that are load balanced to WTS-2 are dropped??? Direct RDP connection to WTS-2 IP works fine.
If I connect WTS-2 to CSS1, so both WTS servers are connected to CSS1 everything works fine.
Can anyone tell what can be wrong?
Configurations are in the attachment.
Thanks for help.
Regards,
Branimirtry the command 'ip uncond' on both CSS.
It will guarantees that the response from WTS-2 comes back to CSS1.
Gilles. -
Oracle RAC - Load Balancing Problem
Our J2EE application transactions (Container-managed) are using MULTIPLE database connections to complete one business transaction.
Recently we swiched to below Oracle RAC configuration, and it is creating problems.
BEA 8.1 SP5 Multi Pools
Oracle 9i RAC (2 instances) : Active - Active
Algorithm : Load Balancing
Driver (JDBC) : Oracle 10g Release 1 Thin Driver
non-XA transactions
Looks like when LB algorithm is chosen, the load balacing is only **connection-aware** and NOT **transaction-aware**. Because of this, the application gets one connection from one RAC instance, and other from other instance is creating problems.
Is there any work-around exist for this problem?
If we chose, HIGH_AVAILABILTY algorithm, everything is fine. But we would like to make use of both instances.Srinivas Chintala wrote:
Hello Joe,
Here is the configuration:
<JDBCConnectionPool DriverName="oracle.jdbc.OracleDriver"
InitialCapacity="10" MaxCapacity="30" Name="rac_node1"
PasswordEncrypted="{3DES}5M6WvgV8GsA=" Properties="user=apps"
StatementCacheSize="20" Targets="app_cluster"
TestConnectionsOnCreate="true" TestConnectionsOnRelease="true"
TestConnectionsOnReserve="true"
TestTableName="SQL SELECT 1 FROM DUAL" URL="jdbc:oracle:thin:@usplgmnvmdb001.iweb.com:1521:prod_1"/>
<JDBCConnectionPool DriverName="oracle.jdbc.OracleDriver"
InitialCapacity="10" MaxCapacity="30" Name="rac_node2"
PasswordEncrypted="{3DES}5M6WvgV8GsA=" Properties="user=apps"
StatementCacheSize="20" Targets="app_cluster"
TestConnectionsOnCreate="true" TestConnectionsOnRelease="true"
TestConnectionsOnReserve="true"
TestTableName="SQL SELECT 1 FROM DUAL" URL="jdbc:oracle:thin:@usplgmnvmdb002.iweb.com:1521:prod_2"/>
<JDBCMultiPool AlgorithmType="Load-Balancing" Name="appmutlipool"
PoolList="rac_node1,rac_node2" Targets="app_cluster"/>
<JDBCDataSource JNDIName="appdatasource" Name="AppDatasource"
PoolName="appmutlipool" Targets="app_cluster"/>
ChintalaHi, OK, that looks fine, except:
1 - I would define the initial and max capacity = 30, for performance and stability.
2 - For more performance, turn off test-on-release. It's a waste of cycles.
3 - You can change your TestTableName to "SQL BEGIN NULL; END;" which goes
even faster than "select 1 from dual".
And the main problem is:
4 - Your JDBCDataSource doesn't seem to be a transactional one, so any
application code that gets connections from that, will get independent
connections each time, and their work will not be included in any WLS
controlled transactions. You want to make/use a JDBCTxDataSource.
Joe -
Weblogic DB connection pool load balancing problem
hi all,
here is a strange issue. We have a clustered weblogic environment with2 servers. And the application is deployed to cluster. But strangely when we check the active connections for the connection pool that is being used by the application, we see that 2nd server has more connections when compared to 1st server, lets say 1st server has 4 active connections, 2nd server has 50 connections, What might be the problem.
<?xml version='1.0' encoding='UTF-8'?>
<jdbc-data-source xmlns="http://www.bea.com/ns/weblogic/jdbc-data-source" xmlns:sec="http://www.bea.com/ns/weblogic/90/security" xmlns:wls="http://www.bea.com/ns/weblogic/90/security/wls" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://www.bea.com/ns/weblogic/jdbc-data-source http://www.bea.com/ns/weblogic/jdbc-data-source/1.0/jdbc-data-source.xsd">
<name>##########</name>
<jdbc-driver-params>
<url>jdbc:oracle:thin:@hostname:portnumber:Schema</url>
<driver-name>oracle.jdbc.OracleDriver</driver-name>
<properties>
<property>
<name>user</name>
<value>#####</value>
</property>
<property>
<name>portNumber</name>
<value>#####</value>
</property>
<property>
<name>SID</name>
<value>######</value>
</property>
<property>
<name>serverName</name>
<value>hostname</value>
</property>
</properties>
<password-encrypted>##########</password-encrypted>
<use-xa-data-source-interface>false</use-xa-data-source-interface>
</jdbc-driver-params>
<jdbc-connection-pool-params>
<initial-capacity>0</initial-capacity>
<max-capacity>75</max-capacity>
<capacity-increment>5</capacity-increment>
<shrink-frequency-seconds>900</shrink-frequency-seconds>
<highest-num-waiters>2147483647</highest-num-waiters>
<connection-creation-retry-frequency-seconds>0</connection-creation-retry-frequency-seconds>
<connection-reserve-timeout-seconds>10</connection-reserve-timeout-seconds>
<test-frequency-seconds>60</test-frequency-seconds>
<test-connections-on-reserve>true</test-connections-on-reserve>
<profile-harvest-frequency-seconds>300</profile-harvest-frequency-seconds>
<ignore-in-use-connections-enabled>true</ignore-in-use-connections-enabled>
<inactive-connection-timeout-seconds>0</inactive-connection-timeout-seconds>
<test-table-name>SQL SELECT 1 FROM DUAL</test-table-name>
<login-delay-seconds>0</login-delay-seconds>
<statement-cache-size>10</statement-cache-size>
<statement-cache-type>LRU</statement-cache-type>
<remove-infected-connections>true</remove-infected-connections>
<seconds-to-trust-an-idle-pool-connection>10</seconds-to-trust-an-idle-pool-connection>
<statement-timeout>-1</statement-timeout>
<profile-type>0</profile-type>
<pinned-to-thread>false</pinned-to-thread>
</jdbc-connection-pool-params>
<jdbc-data-source-params>
<jndi-name>##########</jndi-name>
</jdbc-data-source-params>
</jdbc-data-source>are you using any front end web server or hardware load balancer ? verify your load balancing if it's happening or not properly between your clustered managed servers.
Regards
Mukesh Negi
http://weblogicserveradministration.blogspot.com/ -
Printer Pool load balancing problem.
We seem to be having a problem with printer load balancing working correctly. I have several computer labs. Each lab has at least 2 printers of the same type. As a result I pool the printers for each lab. We are still running ZCM10.3.4. Most of the clients are running iprint 5.82. With Zenworks 7 and 6.5 load balancing on these printers worked very well and page counts stayed very close on each printer. Now that we are at ZCM10 and have been for about 3 years now we continually see that one printer gets the majority of jobs. Most of the computers are imaged but printers are installed after imaging. Even if we alternate the default printer on the computer print jobs still mostly come out the same printer. All printers except 3 are HP and in our case they are all new HP M602's with a couple older HP4015DN's thrown in when the new HP M602's would print garbage across the wan and the 4015's would print correctly but that is another topic.
Am I misunderstanding how load balancing is supposed to work? Isn't load balancing supposed to be one of the features of printer pooling in addition to sending jobs to the printer that is not busy at the time the job is sent? How is load balancing set up?
Thank you.are you using any front end web server or hardware load balancer ? verify your load balancing if it's happening or not properly between your clustered managed servers.
Regards
Mukesh Negi
http://weblogicserveradministration.blogspot.com/ -
HttpClusterServlet Load Balancing Problem
Hi,
I have a problem with LoadBalancing and HttpClusterServlet.
I have 2 boxes, with a clustered application, deployed on 2 managed servers
box 1 with adminServer and and a managed server (managed1)
box 2 with second managed server (managed2)
on box 1 I have another managed server, which hosts the HttpClusterServlet application
The cluster is made up of managed1 & managed2, and httpClusterServlet is configured
to send requests to boths the managed servers in the cluster.
When I run some tests against the httpClusterServlet web application to see how
it load-balances requests, I can see that all the requests are redirected just
to managed1,
on the same machine.
If I stop managed1, and run some tests, I can see that httpCluster every time
tries to contact managed1 first, and since it's down, sends the requests to managed2(handles
failover correctly).
If I move the httpClusterServlet application to another box, let's call it box
3, and re run the tests, it will load-balances the requests between managed1 (box1)
and managed2(box2) correctly.
I would like to know if httpClusterServlet has some kind of "server affinity"
logic (?) or I'm missing something in the cluster configuration (even if I can't
see clearly how the cluster configuration could affect things, since HttpServlet,
which is not in the cluster, just should route
requests to the specified servers in round-robin fashion, I guess)
Someone in previous posts pointed out http session issues, is it true? and so,
why?
Sorry for the far too long post,
thanks in advance,
Thomas
Only from load balancing point of view cluster is not really needed.
apart from session replication and failover capabilities, few more benefits are there with clustering only if you are using a web server also.
Stuck threads can be due to lot's of problems like application issues, load issues etc, So first make sure you are getting stuck thread on both servers or only on one, if on one, then in this case your load balancing not working properly and sending more load to that server, and if you are getting stuck threads on both then try to add one more managed server.
Regards
Mukesh Negi
http://weblogicserveradministration.blogspot.com
Maybe you are looking for
-
How do I locate multiple files at one time?
I've moved a few songs around in my computer's files, and each time I'd go back to locate the files, it asked me if I would like to locate the original files for other songs. Today I tried to do the exact same thing, but it doesn't give me the same o
-
ORA-27067 Error while restoring database using RMAN
Hi All, I am trying to restore the backups from my production database to an other server. I was able to restore the spfile and control files but at the step where I restore the datafiles I get the following error: RMAN-03002: failure of restore comm
-
How to control volume during call when hard buttons don't work?
I was wondering if there is another way to increase the volume during a call when the hard + volume button does not work. Only the - volume button works. Is there possibly an on screen volume button or another screen I can go to for in call volume co
-
Audio Line In interference problem
I'm using my macbook for Garageband for recording and all was well until last night... now when I connect any 15mm jack to the line in I get noise, regardless of whether the other end is plugged into anything or not. If I reduce the input volume to ~
-
How to change html-css cursor style in Adobe Air?
We all know how to change cursor style in Html pages, of course using css such as, 'cursor: url("move.cur"), move'. But when I use it in Adobe Air, it will not show the standard cursor style in browser, but the special ones in Adobe. For example,