ACE Configuration (urgent)

I am facing problem with ACE configuration. I want to redirect 443 traffic to my Proxy Server.
But I am not able to do this. I want to redirect only subnet 192.168.80.0/24
I have the following configuration
access-list BC line 8 extended permit tcp host 192.168.80.89 any eq https
access-list BC line 16 extended permit tcp host 192.168.80.62 any eq https
probe tcp PROBE_TCP_443
  port 443
  interval 15
  passdetect interval 60
  open 1
serverfarm host SF_BCPR_https
  transparent
  probe PROBE_TCP_443
  rserver RS_BCPR01
    inservice
  rserver RS_BCPR02
    inservice
sticky ip-netmask 255.255.255.255 address source STICKY-SOURCE-HTTPS
  replicate sticky
  serverfarm SF_BCPR_https
class-map match-all CM_SF_BCPR_HTTPS
  2 match access-list BC
policy-map type loadbalance http first-match PM_LB_SF_BCPROXY_https
  class class-default
    sticky-serverfarm STICKY-SOURCE-HTTPS
==================================================================================
policy-map multi-match PM_MAIN_BCPROXY
    class CM_SF_BCPR_HTTPS
    loadbalance vip inservice
    loadbalance policy PM_LB_SF_BCPROXY_https
    loadbalance vip icmp-reply active
    appl-parameter http advanced-options PARAMAP_CASE
==================================================================================
interface vlan 300
  description ACE-INSIDE CONTEXT RACK1
  ip address 192.168.0.65 255.255.255.224
  alias 192.168.0.73 255.255.255.224
  peer ip address 192.168.0.66 255.255.255.224
  no normalization
  mac-address autogenerate
  no icmp-guard
  access-group input acl-in
access-list BC line 8 extended permit tcp host 192.168.80.89 any eq https
access-list BC line 16 extended permit tcp host 192.168.80.62 any eq https
  service-policy input PM_MAIN_BCPROXY
  no shutdown
I am getting error.
DC-ACE01/Rack1(config-cmap)# 10 match access-list BC
Error: Class-map is being used for virtual server definition
=======================================================================
Only if I am putting
class-map match-all CM_SF_BCPR_HTTPS
  2 match virtual-address 0.0.0.0 0.0.0.0 tcp eq https
Then only it is working but I dont have to have this policy to be applied on all the users only one subnet I want to have under HTTPS policy.
Please let me know how can I apply the policy only on specific subnet so that port 443 traffic can be redirect and rest of all subnets can go direclty to Internet.
Waiting for reply.
Thanks in Advance.

Hi, if this is your current configuration in last message - it's wrong, should be :
class-map match-all CM_SF_BCPR_HTTPS
  2 match virtual-address 0.0.0.0 0.0.0.0 tcp eq https
policy-map type loadbalance http first-match PM_LB_SF_BCPROXY_https
  match IT source-address 192.168.80.0 255.255.255.0  <----- If you want to redirect 192.168.80.0/24
    sticky-serverfarm STICKY-SOURCE-HTTPS
And then in Layer 4 (multi-match policy)
policy-map multi-match PM_MAIN_BCPROXY
    class CM_SF_BCPR_HTTPS
    loadbalance vip inservice
    loadbalance policy PM_LB_SF_BCPROXY_https
    loadbalance vip icmp-reply active
    appl-parameter http advanced-options PARAMAP_CASE
However you need to be aware - with such configuration all other traffic to port 443 will be dropped.
The one of the options can be to add forward action to class default in Layer 7 map , like this :
policy-map type loadbalance http first-match PM_LB_SF_BCPROXY_https
  match IT source-address 192.168.80.0 255.255.255.0  <----- If you want to redirect 192.168.80.0/24
    sticky-serverfarm STICKY-SOURCE-HTTPS
class class-default  <--- additional configuration
forward
In this case traffic to port 443 from other than 192.168.80.0/24 sources won't be dropped but will be just forwarded to destination.

Similar Messages

  • L7 ace configuration replace Apache AJP

    Hi team
    i am trying to use teh ACE to replace an apache based load balancer in an jboss application cluster. I am using L7 loadbalancing to load balance between multiple components. the way these jboss application servers work with apache is that ---
    When the jboss application starts up on the on application cluster, it issues a GET opencase/webservices/config-service?wsdl to the loadbalancer IP
    The apache based LB in turn talks to the same box on port 8009 via ajp retrieves the configuration file and provides it back to the application on port 80
    And after 2 has completed the Jboss application comes up. Basically to start the application the Apache loadbalacer will accept requests from the its target list and load balance the request back to them itself
    Not sure how i can use the ACE to accomplish this.
    attached are my topology (logical) and the ace configuration. from my topology file -- the net-cms-1 will issue a get request to teh VIP (on the ace), the ACE accepts the connection but soon resets it.
    Can anyone please help.
    Thanks in advance

    I don't know if the problem I had will help see the link below
    https://supportforums.cisco.com/thread/2149204?tstart=90

  • ACE - configuring script probes (tclsh)

    Hey guys
    I'm looking for exampels about writing script probes for the ACE module.
    In the cisco's ACE configuration guide i already found one, but i'd be happy to have a few more. Does anybody knows where i can get some other examples?
    cheers
    patrick

    Tach auch and Hello!
    If you check the software section for the ACE Module you will find some ace scripts you can download.
    http://www.cisco.com/cgi-bin/Software/Tablebuild/doftp.pl?ftpfile=cisco/crypto/3DES/lan/catalyst/6500/ace/ace_scripts.tgz&app=Tablebuild&status=showC2A
    Viel Erfolg
    Roble

  • Regarding DMS configuration - urgent help

    Hi,
    I need urgent help with the below scenario.
    I created one document,attached a drawing,now i want to submit to a higher level authority using workflow who can approve/reject.how do i do this.
    Also i would like to create  two vaults Vault A and Vault B ,user A has read/write to vault A and user B has read/write to only Vault B ,but user C has read.write to both vaults.
    Please let me know how do i create users,configure vaults and give permissions.
    thanks
    prasad suresh

    first u have to create  status for approval
    i give u one example of it
    first u have to create different stauts  for approval process
    for this u have to configure in SPRO with the relevant document type
    and give the  proper authorization in PFCG to relavant user , who create the doc and who chek and who released the doc
    read this carefully , i made this kind of approval process in my project
    1 --- "CR"   means "Create"  by document Creater
    2 --- "Ch"   "Checked" by X authority    /  if any mistake found then  "R1"    "Rework"  by X authority
    3 ---  "Re"   " Released" by Y authority / if any mistake found then "R2"    "Rework"  by Y authority
    think that there is three  stage for approval of any drawing
    first stage  -
    document creat   (Draft Man Creat Drawing and attached )
                              at that time document status is "Cr" after creating doc , that DIR info is sent to higher
                              authority using document distribution functionality
    second stage----- document checker (Receive document from Draft Man in SAP Inbox)
                               he chek that drawing (DIR) . if there is not any other mistake than it again
                              follow the cycle of document distribution to his higher authority. this time
                                document status updated from " Cr "  to " Ch" means from "creat" to "checked "
                                if any mistake found than he change status "Cr"  to "R1" means
                                create to rework  and send it back to drafts man
                                 and drafts man again modify drawing and modify status "R1" to "Cr"
                                 and send it to higher authority
    third stage -
        document aprover  (Receive document from document checker in SAP Inbox)
                               he chek that drawing (DIR) . if there is not any other mistake than he update
                                document status  from  " Ch" to "Re"  means from  "checked " to "Released"
                                if any mistake found than he change status "ch"  to "R2" means
                                checked  to rework  and send it back to drafts man
                                 and drafts man again modify drawing and modify status "R2" to "Cr"
                                 and send it to higher authority
    and in second question , pls tell me clear what u wana do
    vaults means what ?
    is it Repository or what ?
    give me idea by some example

  • ACE Configuration Issue.

    We would like to configure on ace like below:
    the virtual ip address and port like this
    : 10.10.10.10:8000,this ip address will be use to outside user request servie
    and we have to configure server farm like below
    real server 10.10.10.1:8001, 10.10.10.1:8002, 10.10.10.1:8003 ...
    the ip address is same on 10.10.10.10:8000's serverfarm, but real server service is different, and this port should be loadbalanced and healchecked.
    Is it possible solution? F5 big ip , Nortal is possible, but I don't know on ACE above issue.
    If you ok. could you give me a sample configuration?

    page 2....
    Also i forget to tell you to
    8.create resourse-class
    9. create context othr then admin context if you need multiple contexts:
    (inside context add resource class)
    10 class map type management (for remote access)
    as follows:
    Kindly find some config sample as follows:
    ACE/Admin# sh run
    Generating configuration....
    resource-class ABCD_Resource
    limit-resource all minimum 5.00 maximum unlimited
    limit-resource sticky minimum 5.00 maximum unlimited
    boot system image:c4710ace-mz.A3_2_1.bin
    hostname ACE
    context Admin
    member ABCD_Resource
    access-list everyone line 10 extended permit icmp any any
    access-list everyone line 20 extended permit ip any any
    access-list for-cap line 8 extended permit ip any any
    probe http HTTP-Probe
    port 8000
    interval 2
    faildetect 2
    passdetect interval 15
    request method head
    probe icmp ICMP-Probe
    interval 2
    faildetect 2
    passdetect interval 60
    probe tcp TCP-8000
    port 8000
    interval 2
    faildetect 2
    passdetect interval 15
    passdetect count 2
    open 1
    rserver host A
    ip address 10.10.10.1
    inservice
    rserver host B
    ip address 10.10.10.2
    inservice
    rserver host C
    ip address 10.10.10.3
    inservice
    rserver host D
    ip address 10.10.10.4
    inservice
    serverfarm host SF-8000-1
    probe ICMP-Probe
    probe TCP-8000
    rserver A 8000
    inservice
    rserver B 8000
    inservice
    serverfarm host SF-8000-2
    probe HTTP-Probe
    probe ICMP-Probe
    probe TCP-8000
    rserver C 8000
    inservice
    rserver D 8000
    inservice
    class-map match-all L4-CLASS-REDIRECT-1
    2 match virtual-address 10.10.60.10 tcp eq www
    class-map match-all VIP-PORT-8000-1
    2 match virtual-address 10.10.60.10 tcp eq https
    class-map match-all VIP-PORT-8000-2
    2 match virtual-address 10.10.60.12 tcp eq https
    class-map type management match-any remote-mgmt
    10 match protocol ssh any
    20 match protocol telnet any
    30 match protocol icmp any
    40 match protocol http any
    50 match protocol https any
    class-map match-any server-initiated
    3 match source-address 10.10.10.4 255.255.255.255
    4 match source-address 10.10.10.3 255.255.255.255
    policy-map type management first-match remote-access
    class remote-mgmt
    permit
    policy-map type loadbalance first-match VIP-POLICY-8000-1
    class class-default
    policy-map multi-match Service-Policy-8000-1
    class VIP-PORT-8000-1
    loadbalance vip inservice
    loadbalance policy VIP-POLICY-8000-1
    loadbalance vip icmp-reply
    nat dynamic 1 vlan 60
    class L4-CLASS-REDIRECT-1
    loadbalance vip inservice
    loadbalance policy VIP-POLICY-8000-1
    policy-map multi-match Service-Policy-8000-2
    class VIP-PORT-8000-2
    loadbalance vip inservice
    loadbalance policy VIP-POLICY-8000-2
    loadbalance vip icmp-reply
    nat dynamic 1 vlan 60
    ssl-proxy server SSL-Offload-Proxy-2
    policy-map multi-match server-side
    class server-initiated
    nat dynamic 1 vlan 60
    interface vlan 10
    description APPPROD-Client-Vlan
    bridge-group 10
    mtu 1500
    access-group input everyone
    access-group output everyone
    service-policy input remote-access
    no shutdown
    interface vlan 30
    description management-vlan-interface
    ip address 10.10.30.22 255.255.255.0
    access-group input everyone
    access-group output everyone
    service-policy input remote-access
    no shutdown
    continued page 3......

  • ACE Configuration Guide

            I am new to ACE in our company there is ACE modules installed  on 6509 switches as VSS configured and we are running ver A4(2.3) for ACE. Please guide me some good http link to start reading about ACE.
    -Atul           

    I can not get rservers up or the VIPs active.... Help Me....
    logging enable
    logging timestamp
    logging trap 5
    logging history 5
    logging buffered 6
    logging persistent 5
    logging monitor 5
    logging queue 5000
    boot system image:c4710ace-t1k9-mz.A5_1_2.bin
    hostname x86ACE03
    interface gigabitEthernet 1/1
    switchport access vlan 700
    no shutdown
    interface gigabitEthernet 1/2
    switchport trunk allowed vlan 701,704
    no shutdown
    interface gigabitEthernet 1/3
    shutdown
    interface gigabitEthernet 1/4
    shutdown
    ntp server 157.127.103.139
    access-list ACL_10 line 8 extended permit ip any host 10.22.6.117
    access-list ACL_10 line 16 extended permit icmp any host 10.22.6.117
    access-list ACL_10 line 24 extended permit ip any host 10.22.6.116
    access-list ACL_10 line 32 extended permit icmp any host 10.22.6.116
    access-list ACL_10 line 34 extended permit icmp any host 10.22.6.118
    access-list ACL_10 line 38 extended permit ip any host 10.22.6.118
    access-list ACL_10 line 40 extended permit ip any host 10.22.6.119
    access-list ACL_10 line 48 extended permit icmp any host 10.22.6.119
    access-list ACL_20 line 8 extended permit ip any any
    access-list ACL_20 line 16 extended permit icmp any any
    access-list ACL_40 line 16 extended permit ip 10.22.7.2 255.255.255.224 any
    access-list ACL_50 line 16 extended permit ip 10.22.7.34 255.255.255.224 any
    access-list FILTER line 10 extended permit tcp any any eq https
    access-list FILTER line 20 extended permit tcp any any eq www
    probe icmp SERVICE_ICMP_PROBE
    interval 10
    passdetect interval 5
    rserver host vsuiteFrontEnd-A
    ip address 10.22.6.116 ! 10.22.7.2
    probe SERVICE_ICMP_PROBE
    inservice
    rserver host vsuiteFrontEnd-CoreA
    ip address 10.22.6.118  ! 10.22.7.34
    probe SERVICE_ICMP_PROBE
    inservice
    serverfarm host rule-vsuiteFrontEnd-A
    rserver vsuiteFrontEnd-A
       conn-limit max 4000000 min 1
       inservice
    serverfarm host rule-vsuiteFrontEnd-CoreA
    rserver vsuiteFrontEnd-CoreA
       conn-limit max 4000000 min 1
       inservice
    parameter-map type http CASE_PARAM
    case-insensitive
    persistence-rebalance
    parameter-map type connection rule-vsuiteFrontEnd-A_CONN_PARAM
    set timeout inactivity 6400
    parameter-map type connection rule-vsuiteFrontEnd-CoreA_CONN_PARAM
    set timeout inactivity 6400
    class-map type management match-any REMOTE_ACCESS_CLASS
    description Enable remote management
    2 match protocol xml-https any
    4 match protocol icmp any
    5 match protocol telnet any
    6 match protocol ssh any
    8 match protocol https any
    class-map match-any SERVERSOURCED
    2 match access-list ACL_40
    class-map match-any SERVERSOURCED-CoreA
    2 match access-list ACL_50
    class-map match-all rule-vsuiteFrontEnd-A_CLASS
    2 match virtual-address 10.22.6.117 tcp eq https
    class-map match-all rule-vsuiteFrontEnd-CoreA_CLASS
    2 match virtual-address 10.22.6.119 tcp eq https
    policy-map type management first-match REMOTE_ACCESS_POLICY
    class REMOTE_ACCESS_CLASS
       permit
    policy-map type loadbalance first-match rule-vsuiteFrontEnd-A_POLICY
    class class-default
       serverfarm rule-vsuiteFrontEnd-A
    policy-map type loadbalance first-match rule-vsuiteFrontEnd-CoreA_POLICY
    class class-default
       serverfarm rule-vsuiteFrontEnd-CoreA
    policy-map multi-match POLICY
    class rule-vsuiteFrontEnd-A_CLASS
       loadbalance vip inservice
       loadbalance policy rule-vsuiteFrontEnd-A_POLICY
       loadbalance vip icmp-reply active
       connection advanced-options rule-vsuiteFrontEnd-A_CONN_PARAM
    policy-map multi-match POLICY-CoreA
    class rule-vsuiteFrontEnd-CoreA_CLASS
       loadbalance vip inservice
       loadbalance policy rule-vsuiteFrontEnd-CoreA_POLICY
       loadbalance vip icmp-reply active
       connection advanced-options rule-vsuiteFrontEnd-CoreA_CONN_PARAM
    policy-map multi-match SERVERSOURCED
    class SERVERSOURCED
       nat dynamic 1 vlan 700
    policy-map multi-match SERVERSOURCED-CoreA
    class SERVERSOURCED-CoreA
       nat dynamic 2 vlan 700
    service-policy input POLICY
    service-policy input POLICY-CoreA
    interface vlan 700
    ip address 10.22.6.2 255.255.255.224
    no icmp-guard
    access-group input ACL_10
    nat-pool 1 10.22.6.117 10.22.6.117 netmask 255.255.255.255 pat
    nat-pool 2 10.22.6.119 10.22.6.119 netmask 255.255.255.255 pat
    service-policy input REMOTE_ACCESS_POLICY
    no shutdown
    interface vlan 701
    ip address 10.22.7.2 255.255.255.224
    no icmp-guard
    access-group input ACL_20
    service-policy input SERVERSOURCED
    no shutdown
    interface vlan 704
    ip address 10.22.7.34 255.255.255.224
    no icmp-guard
    access-group input ACL_20
    service-policy input SERVERSOURCED-CoreA
    no shutdown
    ip route 0.0.0.0 0.0.0.0 10.22.6.1
    x86ACE03/Admin#
    x86ACE03/Admin# sh probe
    probe       : SERVICE_ICMP_PROBE
    type       : ICMP
    state       : ACTIVE
       port     : 0          address   : 0.0.0.0
       addr type : -           interval : 10     pass intvl : 5
       pass count: 3           fail count: 3       recv timeout: 10
                   ------------------ probe results ------------------
       associations     ip-address         port porttype probes failed passed health
       ------------ ----------------------+----+--------+------+------+------+------
       rserver     : vsuiteFrontEnd-A
                               10.22.6.116   0 --     78   78     0     FAILED
       rserver     : vsuiteFrontEnd-CoreA
                               10.22.6.118   0 --     459   459   0     FAILED
    x86ACE03/Admin#
    x86ACE03/Admin# sh service-policy
    Policy-map : POLICY
    Status     : ACTIVE
    Context Global Policy:
    service-policy: POLICY
       class: rule-vsuiteFrontEnd-A_CLASS
         loadbalance:
           L7 loadbalance policy: rule-vsuiteFrontEnd-A_POLICY
           VIP ICMP Reply       : ENABLED-WHEN-ACTIVE
           VIP state: OUTOFSERVICE
           VIP DWS state: DWS_DISABLED
           Persistence Rebalance: DISABLED
           curr conns       : 0         , hit count       : 0
           dropped conns   : 0
           conns per second   : 0
           client pkt count : 0         , client byte count: 0
           server pkt count : 0         , server byte count: 0
           conn-rate-limit     : -         , drop-count : -
           bandwidth-rate-limit : -         , drop-count : -
         compression:
           bytes_in : 0                         bytes_out : 0
           Compression ratio : 0.00%
                   Gzip: 0               Deflate: 0
         compression errors:
           User-Agent : 0               Accept-Encoding   : 0
           Content size: 0               Content type       : 0
           Not HTTP 1.1: 0              HTTP response error: 0
           Others     : 0
           Parameter-map(s):
             rule-vsuiteFrontEnd-A_CONN_PARAM
    Policy-map : POLICY-CoreA
    Status     : ACTIVE
    Context Global Policy:
    service-policy: POLICY-CoreA
       class: rule-vsuiteFrontEnd-CoreA_CLASS
         loadbalance:
           L7 loadbalance policy: rule-vsuiteFrontEnd-CoreA_POLICY
           VIP ICMP Reply       : ENABLED-WHEN-ACTIVE
           VIP state: OUTOFSERVICE
           VIP DWS state: DWS_DISABLED
           Persistence Rebalance: DISABLED
           curr conns       : 0         , hit count       : 0
           dropped conns   : 0
           conns per second   : 0
           client pkt count : 0         , client byte count: 0
           server pkt count : 0         , server byte count: 0
           conn-rate-limit     : -         , drop-count : -
           bandwidth-rate-limit : -         , drop-count : -
         compression:
           bytes_in : 0                         bytes_out : 0
           Compression ratio : 0.00%
                   Gzip: 0               Deflate: 0
         compression errors:
           User-Agent : 0               Accept-Encoding   : 0
           Content size: 0               Content type       : 0
           Not HTTP 1.1: 0              HTTP response error: 0
           Others     : 0
           Parameter-map(s):
             rule-vsuiteFrontEnd-CoreA_CONN_PARAM
    Policy-map : SERVERSOURCED
    Status     : ACTIVE
    Interface: vlan 1 701
    service-policy: SERVERSOURCED
       class: SERVERSOURCED
         nat:
           nat dynamic 1 vlan 700
           curr conns       : 0         , hit count       : 0
           dropped conns   : 0
           client pkt count : 0         , client byte count: 0
           server pkt count : 0         , server byte count: 0
           conn-rate-limit     : 0         , drop-count : 0
           bandwidth-rate-limit : 0         , drop-count : 0
    Policy-map : SERVERSOURCED-CoreA
    Status     : ACTIVE
    Interface: vlan 1 704
    service-policy: SERVERSOURCED-CoreA
       class: SERVERSOURCED-CoreA
         nat:
           nat dynamic 2 vlan 700
           curr conns       : 0         , hit count       : 0
           dropped conns   : 0
           client pkt count : 0         , client byte count: 0
           server pkt count : 0         , server byte count: 0
           conn-rate-limit     : 0         , drop-count : 0
           bandwidth-rate-limit : 0         , drop-count : 0
    x86ACE03/Admin# sh serverfarm
       serverfarm           type     rservers predictor         current conns
    +--------------------+---------+--------+------------------+---------------
       rule-vsuiteFrontEnd-A
                           HOST     1       ROUNDROBIN         0
       rule-vsuiteFrontEnd-CoreA
                           HOST     1       ROUNDROBIN         0
    x86ACE03/Admin# sh serverfarm rule-vsuiteFrontEnd-A
    serverfarm     : rule-vsuiteFrontEnd-A, type: HOST
    total rservers : 1
    state         : INACTIVE
    DWS state     : DISABLED
                                                   ----------connections-----------
           real                 weight state       current   total     failures
       ---+---------------------+------+------------+----------+----------+---------
       rserver: vsuiteFrontEnd-A
           10.22.6.116:0         8   PROBE-FAILED   0         0         0
    x86ACE03/Admin# sh serverfarm rule-vsuiteFrontEnd-A
    serverfarm     : rule-vsuiteFrontEnd-A, type: HOST
    total rservers : 1
    state         : INACTIVE
    DWS state     : DISABLED
                                                   ----------connections-----------
           real                 weight state       current   total     failures
       ---+---------------------+------+------------+----------+----------+---------
       rserver: vsuiteFrontEnd-A
           10.22.6.116:0         8   PROBE-FAILED   0         0         0
    x86ACE03/Admin#

  • ACE Configuration Synchronization failure

    I have defined the FT group on ACE, but i don't see configuration getting update on the other module.
    The response for 'sh ft peer detail' is as follows
    Peer Id : 1
    State : FSM_PEER_STATE_DOWN
    Maintenance mode : MAINT_MODE_OFF
    FT Vlan : 200
    My IP Addr : 1.1.1.1
    Peer IP Addr : 1.1.1.2
    Query Vlan : Not Configured
    Peer Query IP Addr : 0.0.0.0
    Heartbeat Interval : 200
    Heartbeat Count : 20
    Tx Packets : 0
    Tx Bytes : 0
    Rx Packets : 0
    Rx Bytes : 0
    Rx Error Bytes : 0
    Tx Keepalive Packets : 0
    Rx Keepalive Packets : 0
    TL_CLOSE count : 0
    FT_VLAN_DOWN count : 0
    PEER_DOWN count : 1
    SRG Compatibility : INIT
    License Compatibility : INIT
    FT Groups : 1
    Please assist.

    Can you please paste you configuration.
    Did you configure both modules with the FT configuration?
    Is the FT vlan available on both chassis?
    Is the FT vlan trunked between the two chassis?

  • ACE Configuration

    Hi,
    I need some configuration to provide site stickiness with the Help of ACE running in two different sites.
    DNS functionality is handovered to the GSS
    For example
    Once a DNS A record is given back to the user for www.company.com and the request is made to the ACE, the ACE will send a http redirect back to the user for a new domain name of www1.company.com or www2.company.com for the respective
    sites, the user was initial sent to via the DNS response. This insures that the user will alwaysreturn to the same site.

    Gilles,
    Thanks for your response.
    I am after HTTP/HTTPS redirects in the ACE for site stickiness
    Example
    Two sites site1 and site 2
    GSS configuration with 3 DNS Rules
    RULE1 - WWW.MYCOMPANY.COM - 1.1.1.1,1.1.1.2
    RULE2 - WWW1.MYCOMPANY.COM -1.1.1.1(SITE1)
    RULE3 - WWW2.MYCOMPANY.COM - 1.1.1.2(SITE2)
    clinet to the GSS ---> www.mycompany.com hits the Site A (1.1.1.1) the ACE shall redirect the client request to WWW1.MYCOMPANY.COM and further request from the client should stick to the same site till it completes the session i.e www1.mycompany.com.
    Thanks in Advance

  • ACE Configuration Check

    VIP : 10.10.10.10:8000
    rserver server1
    ip address 10.10.10.1
    serverfarm SFARM1
    rserver server1 8001
    probe Probe_8001
    rserver server2 8002
    probe Probe_8002
    rserver server3 8003
    probe Probe_8003
    rserver server4 8004
    probe Probe_8004
    I would like to loadbalance on just one single ip address and multiple ports like
    above configuration on ACE. Is It possible configuration? please check
    thank you.

    ok. thank your response.
    I picked up your configuration as follows:
    rserver Server1
    ip address 10.10.10.1
    inservice
    serverfarm Farm1
    rserver Server1 8001
    inservice
    rserver Server1 8002
    inservice
    rserver Server1 8003
    inservice
    class-map MyVip
    match virtual 10.10.10.10 tcp eq 8000
    policy type loadbalance http first MyPolicy
    class class-default
    serverfarm Farm1
    policy multimatch SLB
    class MyVip
    load policy MyPolicy
    load vip inservice
    interface vlan X
    service in SLB
    I know that there is no problem to configure one real server attached multiple service port for configuring SLB.
    But I must healcheck on each multiple ports although one real server.
    for example:
    rserver Server1 8001
    probe probe_8001
    inservice
    Is it working well?

  • ACE configuration using GUI

    Hi all,
    i configured ACE in multi context for failover. then i configured primary ACE using GUI after configuring server farm and click DM sync and SYNC all.Then i checked secondary ACE whether configuration is synced but its not sync with secondary.what might be the problem.

    do a 'show ft group detail' and make sure you have config synch enabled
    "Running cfg sync enabled : Enabled"
    If not, you need to turn it on.
    Also check the status.
    "Running cfg sync status "
    Sometimes it is enabled but not working because files can't be synched like ssl keys/certs or script probes.
    Gilles.

  • RuntimeException only for one model in configurator-Urgent

    I created a custom web page in OAF to launch Configurator. It was working fine untill this morning , when another co-worker made some changes and published one particular model.
    My application fails to launch that model where as all the models work fine.
    This model launched fine from Quoting/OM and Config Dev.
    Error from the logs is :
    [Sep 17, 2008 1:07:13 PM
    CDT]:1221674833273:Thread[Thread-27248,10,main]:6616:1985801979:s1v1280:10.122.84.1:8101:16010:STATEMENT:[fnd.framework.webui.OAPageBean]:CZInitString=<initi
    alize><param name="database_id">szzzzzzz_macp</param><param name="icx_session_ticket">0DA897D89B5B9415C7975C52278BFF45</param><param
    name="calling_application_id">601</param><param name="responsibility_id">24742</param><param name="ui_def_id">0</param><param
    name="terminate_id">null</param><param name="ui_type">JRAD</param><param name="init_was_saved">true</param></initialize>
    [Sep 17, 2008 1:07:18 PM
    CDT]:1221674838221:Thread[Thread-27248,10,main]:6616:1985801979:s1v1280:10.122.84.1:8101:16010:EXCEPTION:[cz.service.ConfiguratorServiceLocal.From
    processMessage()]:[null_475db5b_b0 # 16171] Cannot find the text with persistent id 33125520 in source ui 23080
    java.lang.RuntimeException: Cannot find the text with persistent id 33125520 in source ui 23080
         at oracle.apps.cz.dio.ui.UiController.getTextByPersistentID(UiController.java:779)-----------
    I saw a few notes on metalink and found some scripts for debugging, but I have no idea what sense to make out of it.
    SELECT * FROM cz.cz_db_logs WHERE message_id='353320'
    - no result
    SELECT model_id,publication_id from cz_model_publications where export_status = 'ERR'
    --no result
    SELECT intl_text_id, persistent_intl_text_id,text_str,ui_def_id FROM cz_intl_texts where persistent_intl_Text_id = 33125520;
    2 rows
    33136901    33125520 . . . . . . .Rewind(s) upgraded to 3HP. . . . . . . 239347
    33125520    33125520 . . . . . . .Rewind(s) upgraded to 3HP. . . . . . . 23080
    select model_id,ui_def_id,intl_text_id,creation_date from cz_intl_texts where persistent_intl_text_id = 33125520
    2 rows
    2409785 239347 33136901 9/17/2008 9:53:29 AM
    21400 23080 33125520 9/17/2008 9:09:28 AM
    SELECT intl_text_id, text_str, persistent_intl_text_id, seeded_flag, ui_def_id, model_id FROM cz_intl_texts where ui_def_id = 23080 AND deleted_flag = 0;
    -- 8 rows
    SELECT * from cz_model_publications WHERE object_type = 'UIT' ;
    24 rowsPlease help, its urgent.
    Thanks

    I investigated more and here are my findings:
    we have 2 publications in production published for different set of applications,
    pub1 is published for applications : asn, qot ,oem
    pub2 is published for applications : mac(custom application) --this was created for changes in future and has effectivityset for future.
    It seems while launching , it picks the ui for pub2 and I want it for pub1
    My query is :
    select distinct
         rep.name name ,
         pub.ui_def_id,
         pub.publication_id
    from cz_model_publications pub,CZ_UI_DEFS defs,CZ_REPOS_TREE_V rep,CZ_PB_CLIENT_APPS apps
    where pub.ui_def_id=defs.ui_def_id
    and apps.publication_id=pub.publication_id
    and rep.object_id=defs.devl_project_id
    and pub.publication_mode='p'
    and rep.object_type='PRJ'
    and pub.organization_id = '101'
    and pub.deleted_flag = 0
    and pub.disabled_flag = 0
    and apps.fnd_application_id=880 --this is available for quoting UI
    order by rep.name
    Can anyone plz help me on this .
    I will appreciate it
    Thanks

  • Switch configuration urgent help (edge and core)

    hi
    i have new project in with the bellow product :
    20 X WS-C2960-24TC-S
    2 X WS-C3750X-48T-S
    2 X WS-C2960S-24TS-S
    i need to configure this switch in order to work without having vlan, first the 2 core switch for redundancy, then each catalyst switch 2960(edge Switch) connected to the two core with 2 uplink each uplink will be connected to single core switch(i have 2 core switch and i want to configure it in stack mode redundancy) 
    i need help to configure this switch to work perfectly with each other in best redundancy mode any configuration for this switch will be very helpfull for me
    thank you

    Hey,
    This is a very open question but i believe the document below is a good point to start:
    http://www.cisco.com/c/dam/en/us/td/docs/solutions/Enterprise/Small_Enterprise_Design_Profile/chap2sba.pdf
    HTH.
    Regards,
    RS.

  • FI-CO Configuration "Urgent Help"

    Hello SAP Gurus,
    Simulate Inventory Mgmt; Entry of Simulation Data
    Plant appears as error. Can any of you help in rectifying this . My plant # is not showing in the drop down menu.
    If the plant was not created let me know the path and how to rectify this in future.
    Thanks !!! [email protected]

    IMG for SAP Plant Maintain
    How to Configure a New Plant in SAP?
    Plant 0001 is the SAP default provide for your reference.
    OX14 - Define Valuation Area (Tick one only- Once your system go live, no more changes)
                 Most company take the SAP recommended choice - Value Material Stock at Plant level
                 Value Material Stock at Plant or Company Level
    If you valuate material stocks at plant level, the plant is the  valuation area.
    If you valuate material stocks at company code level, the company code is the valuation area.
    The decision you make applies to the whole client.
    OX10 - Create / Change / View Plants
    OVXB - Create / Change / View Division
    OX18 - Assign Plant to company code
                  e.g.       0001 - 0001 - All Plants
                                          Px1   - Plant Px1
                                          Px2   - Plant Px2
    OX19 - Assignment of company code to the Controlling Area
    OB38 - Assign company code to Credit Control Area
    OMJ7 - Assign business area to Plant/Valuation area and division
                 e.g. Plant Px1 - Business Area Bx1
                                                                Bx2
                 Assign Valuation area to the Business Area
                 .e.g. Valuation area Vx1 - Business Area Bx1
                                                         Business Area Bx2
    OMS0 - Assign Factory Calendar to the Plant and Business Area
    The plant plays an important role in the following areas:
    Material Valuation - If the valuation level is the plant, the material stocks are valuated at plant level. Each plant can have its own material prices and account determination.
    Inventory Management - The material stocks are managed within a plant.
    MRP - Material requirements are planned for each plant. Each plant has its own MRP data. Analyses for materials planning can be made across plants.
    Production - Each plant having they own production/planning.
    Costing - In costing, valuation prices are defined only within a plant.
    Plant Maintenance  - If a plant performs plant maintenance planning tasks, it is defined as a maintenance planning plant. A maintenance planning plant can also carry out planning tasks for other plants (maintenance plants).
    If you want to use the application PP (production planning) or product costing and job-order costing, you must set valuation at plant level.
    The valuation level that you choose affects
    the maintenance of material master records
    the G/L accounts in which material stocks are managed
    the G/L accounts to which transactions are posted in Materials Management
    Effect on the maintenance of material master records:
    Depending on the valuation level chosen,
    you maintain accounting data in the material master record for each plant or for each company code
    you define a valuation price for the material in each plant or in each company code
    Effect on G/L accounts:
    If material stocks are valuated at company code level, all plant stocks of a material are managed in a joint stock account for each company code.
    If material stocks are valuated at plant level, you can manage the material stocks for each plant in different accounts. For each plant, you can define a separate determination.
    If several plants are to use account determination, you can group these plants in "Valuation and Account Assignment" Customizing.

  • FBZP APP configuration - Urgent

    Hi sap guru's,
    I had encountered with the following problem. 
    Our client has 3 a/c's with a bank SBI at same branch(mumbai) and he issues cheques from all 3 a/c's. Here how the configuration should be done for check payment method for APP.  can any one please explain.
    I had created one house bank and 3 account id's and under account determination-->bank selection how to configure payment method, how to determine the bank sub account under bank a/c determination.     As Under bank a/c’s same pmt method along with same currency not allowed under one house bank but here our client has 3 a/c's at that branch and issues cheques from 3 a/c's so i have to configure the 3 a/c's in whichever way the ranking order may be. I was unable to configure as it is not allowing for same payment method, same currency under one house bank.
    Any one please reply
    Thanks in advance,
    krishna
    Edited by: vamshi krishna on Feb 25, 2008 11:09 AM
    Edited by: vamshi krishna on Feb 27, 2008 6:38 AM

    you need to review how and why your client issues checks for the same currency from three accounts.
    What is the business logic?
    If you had one for Dollar and one you Euro then ranking order and bank accounts.
    You could look at creating two new payment methods and assigning them to the lower level in the bank account section but first I would question how the client knows which account should be paid from.

  • Servlet Configuration - urgent

    I installed
    jdk-6u21-windows-i586.exe
    in my machine (xp s3) and I can run java progrms
    Now I want to know the following things
    1. Which version of jdk is this
    2. I want to run Servlets from my machine
    what additional software to install for this
    in which folder, how to configure?
    kindly give me step by step procedure for this, thanks in advance

    jdk-6u21-windows-i586.exe
    1. Which version of jdk is this1.6.21
    2. I want to run Servlets from my machine
    what additional software to install for thisApache Tomcat for example, Jetty: many other possibilities.
    in which folder, how to configure?Read the documentation for whatever you choose.
    kindly give me step by step procedureThis is a 'New to Java' Programming forum, not a help desk.

Maybe you are looking for

  • How to sort Data in XML template (rtf) file?

    Hi, I have an oracle 11i custom report (rdf) with an xml output to a PDF. There is a formula column in the report. Now I need the data to be sorted on this formula column. As we cannot sort on formula column, i have decided to find a way to sort it i

  • Image formats that can be used directly in PDF

    Hi, after severel hours of searching google, discussion boards and the PDF reference, I could not find an answer, so hopefully you guys can help me . I have written my own little PDF exporter and want to include images. I figured out to include jpegs

  • Firefox freezes until I minimize the window, then restore it. Why?

    Each time I use Firefox now I cannot get it to respond to the mouse until I minimize the browser, then restore it. It will then work for a few selections within a window in the browser, then freeze again. I had even thought it might be the mouse, but

  • 0137 "Formal error: Payment difference given without items to be cleared".

    i have problem bapi BAPI_CTRACCTRCTACCNT_PAYBYCARD i use a bapi to select  the open items (BAPI_CTRACCONTRACTACCOUNT_GOI) and then Via the component ITEM_ACTIVATED, you can select the items to be cleared. In     the component CLEARING_AMOUNT specify

  • Online Phone Number of small business

    What happens when a second caller dials the on line number, and I'm talking to the first caller?   Does it roll to another number? How do you handle 3-4 calls at once? Emad