ACE implementation with servers at remote locations

Hi,
We are having two ACE appliances in the datacenter in failover mode. Currently, we using route mode with two servers placed in the DC which are getting load balanced. Now, we are planning to move the servers to a new location and this location is reachable via WAN from the DC. Is there any challenge in moving the servers to a new location.
1. Do we need to do any natting ?
2. Is there any configuration document for ACE appliance using route mode with NAT ?
Any help would be appreciated.
Rgds./
Sck

There are 2 things to look at.
1/ Make sure the ACE can reach the server (ping)
2/ Make sure the return traffic from the server goes back to the ACE
This 2nd point can be tricky when the servers are not directly connected to ACE.
The servers will see the connections coming from clients (not ACE ip address), therefore they will use a default gateway to send the response which does not necessarily send traffic back to ACE.
You may need policy routing on the gateway.
Or you may have to configure client nat (in this case, the servers see the connections coming from ACE itself), but then you lose information about client source ip.  This can be solved by doing header insert but this is only possible for HTTP and it has a cost in terms of performance.
The best option is to keep the servers close to the loadbalancer.
If you want to move both servers, see if you can also move the loadbalancer to the same remote location.
Gilles.

Similar Messages

  • Accessing multiple macs with ARD from remote location with Airport Extreme

    We have an office with a newer Airport Extreme and three macs on the network. We have turned on the Apple Remote Desktop in the port forwarding, but we can only access one computer at a time, and only if we port map it to the local IP of that computer (Ex 10.0.1.2).
    We would like to be able to access all three computers from a remote location. My question is this -
    Can I have a wildcard IP, or is there an IP I should use for ARD?
    Do I set up multiple port mapping with different ports and IPs?
    All computers are running 10.6.1 with the latest ARD updates.
    Any assistance would be appreciated.

    Great answer by Dave Sawyer:
    "To be able to connect to a workstation from outside it's network, the ports that ARD uses must be open on both ends of the connection. ARD uses ports 3283 and 5900 so those must be open.
    If your workstations get their addresses from an NAT device rather than being "real", the ports also need to be forwarded in the router to the workstation's internal IP address. ARD uses port 3283 for the reporting and updating function, so if your Macs are getting their IP addresses through NAT, since you can only forward a port to a single workstation, you can only get reports, push package/files to etc. for a single workstation.
    ARD uses the VNC protocol for observation and control, though, and there are a range of IP addresses for that protocol, starting with 5900. ARD uses 5900 by default, so that port would be forwarded to the first workstation. To be able to control more than one system, though, you would need to install VNC servers on the systems (since the ARD client cannot listen on any port other than 5900 while VNC servers can be set for other ports such as 5901, 5902, etc. You would then forward 5901 to the second workstation (and on to 5902, 5903, etc.). You can then use the following information:
    Remote Desktop 2: How to specify a port number for a VNC client to connect. -http://support.apple.com/kb/TA22880
    The only other options are: 1) to run the ARD administrator on a workstation on the network, and then take control of that system from outside, either via VNC or another copy of ARD, or 2) set up a virtual private network (VPN) so that when you connect from outside, your admin system is officially part of the local network.
    Hope this helps."

  • ACE implementacion with servers Lan in other Router

    Hi,
    I need help in this topology, I need to design an escenario, where the Lan Servers  are  in other Router, the conexion between the ACE module and the Lan Server is throught a routing protocols using a Layer 3 device like an ASA.
    I have a confusion of using a Context in routed mode or One Armed mode. i dont know what is the best option.
    I need help.
    Attached a Diagram of the  escenarios.
    Regards,
    Fidel Gonzalez

    Hi Fidel,
    This should work in Routed or One-Armed, the only thing you need to be sure is that the response of the servers is going back to the ACE instead of going directly to the client.
    You probably will need to use source nat when the ACE sends the traffic to the servers.
    Cesar R
    ANS Team

  • Acessing home iMac with MacBook from remote location via internet????

    Is there a way to access files on my iMac at home with my MacBook via the internet as I do when I'm at home through my network?
    Thanks, Jason

    Hi Jason,
    Funny, we were just working on this topic. I'm assuming your iMac is behing a router, and it does NAT. An indicator would be if your iMac's IP address was something like 192.168.1.x or 10.0.0.x. In that case, the best way is to set up port forwarding in your router.
    Assuming you want to share files using Apple File Protocol, you need to forward port 548 from your router to port 548 on your iMac. Other protocols use different ports, but you didn't specify. I don't know what router you've got, so I don't how to configure it. It's probably got a web interface.

  • How do I use iCloud to collaborate on a GarageBand project with a remotely located musician?

    How do I use iCloud to collaborate on a GarageBand project with a remotely located musician?  He is in Valencia, Spain, I am in Green Bay, Wisconsin.  We'd like to be able to work on the same GarageBand document together, laying down tracks, etc.
    Is there a tutorial I should look at?

    Are you using GarageBand on a Mac or on an iPad?
    With iCloud you can store your GarageBand projects in iCloud, so you can work on the same project on all your iPads, iPods, iPhones, and transfer it from your iDevices to your Mac.  But you cannot use iCloud to share a project between people with different AppleIDs.  
    To send GarageBand projects back and forth, compress the the ":band" files and mail them, if they are small enough or put them in a Dropbox or other cloud storage and mail the link.

  • Callmanager Conferencing with remote locations Issue

    I am new to using callmanager, and I need a little help.
    I have created a meet me number on my callmanager. Once a session is begun, all local network users are able to join the conference call with no problems..
    If a remote location hosts a meet me call, all my local network users are able to join THAT session with no problems as well.
    But if I host a meet me session on MY local network, remote locations CANNOT reach my session. The line remains silent when they dial in.
    I've been told to check the codecs which seem fine and we are checking for a firewall issue, but all normal calls local and remote work just fine. It's only the conference bridging that causes issues.
    Please help.
    Thanks

    Hello,
    Thank you very much for replying.
    The configurations, I've been told, are correct. G711 for intrasite and G729 for intersite. And region and device pools correct as well.
    I presented the HW conf bridge solution to a coworker who said it makes sense, but at this time, I don't have access to a hardware conference bridge. Is this the only solution? 
    From: prbt
    To: Nichole Ketchum
    Sent: Wednesday, August 3, 2011 1:54 PM
    Subject: - Re: Callmanager Conferencing with remote locations Issue
    Cisco Support Community
    Re: Callmanager Conferencing with remote locations Issue created by Priya B.T in Unified Communications Applications - View the full discussion
    hi,
    please check the following on the call manager,
    -  Check the region configuration on each device pool.
    -  Then check the region configuration between the two regions.
    -  One of the best practices followed by Cisco is, the intrasite region settings should be g711.
    -  And the region settings between inter site should be g729.
    -  G729 is not supported by software conference bridge, it is only supported by hardware conference bridge.
    -  So add the hardware conference bridge to the MRGL of the phone.
    -  And the hardware conference bridge has to be first in the list, that is before the software conference bridge.
    please let me know if this helps or we can do further trouble shooting on this issue.
    Reply to this message by going to Cisco Support Community
    Start a new discussion in Unified Communications Applications at Cisco Support Community

  • Is it possible to have a phone line connected to a Mac Mini (OS X10.8.2) so you can use your computer with Parallels (Windows xp) to dial into a modem to download data being collected and stored at the remote location?

    Is it possible to have a phone line connected to a Mac Mini (OS X10.8.2) so you can use your computer with Parallels (Windows xp) to dial into a modem to download data being collected and stored at the remote location?

    Hi, do you mean a real Dial-up Modem as in the old days?
    As I recall, the Apple USB Modem won't work in 64 bit OSes, but there are others that will, I think this is one of them...
    http://www.zoomtel.com/products/dial_up_external_usb.html
    Or is the Modem on the other end Cable/DSL/FiberOptic?

  • Delete from remote location with where clause between the two databases

    I want to delete records from a source database using dblink. The criteria for the delete is a where clause, that
    looks for the values between a table at source and the remote location. I get an invalid sql statement error.
    When i do a count(*) instead of a delete, I get rows returned.
    Can anyone see an the problem here ? I've tried qualifying the delete
    delete from tabl1@remote a, tabl1_temp b where (a."id" =b."id") and (a."title" = b."title) and (a."key" = b."key");
    the error I get is ORA 00933 SQL command not properly ended....
    The * is between the 2 ands ...
    Edited by: sgonos on Nov 6, 2009 6:46 AM
    Sorry the * moved when I save it ...
    delete from tabl1@remote a, tabl1_temp b where (a."id" =b."id") and (a."title" = b."title) and (a."key" = b."key");
    it's flagging the middle and ... a.title = b.title ... seems to like key ....
    Edited by: sgonos on Nov 6, 2009 6:51 AM

    You have 2 tables specified in the delete clause of your statement.
    It should maybe be something like:
    delete from tabl1@remote a
    where exists (select 'x' from tabl1_temp b where (a."id" =b."id") and (a."title" = b."title) and (a."key" = b."key"));
    {code}                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               

  • Cloning a Mac OS X Server to a remote location

    Scenario: A Mac Mini running Mac OS X Server is in location A and a second Mac Mini running Mac OS X Server is to be acquired and setup at a remote location.
    Desire: Do a nightly backup of Server A to the second Mac Mini so that Server B is a bootable clone of the primary server.
    Question: What is the best software/approach to do this?
    Discussion: I'm familiar with and use SuperDuper, Synchronize Pro and Carbon Copy Cloner for performing file by file backups and synchronization where the hard drives are on the same server ... but I'm not sure if any of these are the best alternative to backup a MAMP Pro installation on the Server (along with other applications and data) to a remote server box.
    I realize that particularly within the Moodle VLE (that will be running on the servers) that absolute links will still point to the primary server but that is not an issue for me. In the event of a catastrophic failure of Server A at least there would be an offsite clone that could be accessed if a few settings were changed.
    BTW: Server A is hosted by a commercial hosting service and no backup drive is available on-site for a file x file backup/synchronization. We do have full access to the server via ARD, Timbuktu Pro, AFP, etc.

    Can you expand your info on the use of these two approaches, particularly the mysql replication
    Well, my approach requires that there's some kind of connectivity between the two machines - preferably a VPN network to secure the traffic, but it doesn't have to be done that way.
    rsync essentially takes two directories - one local and one remote - and compares the differences. Depending on the switches you use it will copy the changes from one system to the other (or both if that's what you prefer). In this case I'd set it to copy the local web directory to the remote machine, so the remote machine has a copy of all the files.
    rsync works best for static files (e.g. .html, .php, etc. in the case of a web application), but shouldn't be used for dynamic files such as your database files.
    As for the data, MySQL has substantial built-in replication routines that are designed to keep multiple database servers in sync. There's far more to it than I can go into here, suffice to say it can maintain a real-time copy of your data on a second, remote machine, and you should read the documentation for the specifics.

  • Hardware Requirements for a SCCM 2012 CAS with SQL Server Remote

    The hardware requirements for a CAS server with SQL Server Enterprise locally installed are:
    16 cores (Intel Xeon L5520 or comparable CPU)
    64 GB of RAM
    1.5 TB of disk space for the operating system, Configuration Manager, SQL Server, and all database files.
    Does anyone know what the hardware requirements are if SQL Server Enterprise is remote from the CAS server?  It's not listed.  -Shane

    Even though I am going to be strung up for even saying this, I do agree there is a use for a CAS outside of 100,000 users.  If you do indeed have distinct admins managing their own images and apps in remote
    locations then I see the benefit of a CAS.  A remote ConfigMgr console connecting to a primary site would perform poorly.  Admin A at the primary site would not experience any issues but Admin B would be in for a lot of work and waiting.  Any
    time Admin B needed to add an app or image it would have to be copied up to the remote primary site and then distributed back down.  This is not the best scenario.
    There are scenarios in company merger situations (and others I am sure) where the management of both locations has not been consolidated down to one location yet and is not going to be done as part of the deployment or upgrade.  If you had a 2007 environment
    it is going to be very hard to convince the admin at the remote location that this upgrade is going to be a good thing for him/her.  There is an option for the remote admin to RDP into a server in the primary site but the image and apps still need
    to be distributed down to the remote location.  During testing this can be very time consuming. 
    I do agree that adding a CAS adds additional complexity but in some cases such as the one I described it is the right decision. 
    Thank you for the reply. And i totally agree that in some cases a design like that is a necessary evil (but not by our personal wants). 
    We had that design with 2007 (implemented before my time), and as you predicted EU admins complained about difficulty using the console RDP-ed into a box close to the primary site. The bandwidth to and from different regions is out of scope for me so I do what
    I can with what I have. We too will be moving forward with a CAS hierarchy. 
    Administratively the other IT depts in other regions operate on their own. I dont handle any of the EU computers on a day to day basis whatsoever, etc. We're not merging but our IT shops operate with near independence. 

  • Domain Admin Account cannot logon to member servers by remote. It can only logon to Domain Controllers

    Our environment has both 2008R2 and 2012R2 Domain Controllers. Recently one of our Domain Admins started having problems logging onto all servers by remote desktop except for domain controllers. The error message is as follows:
    "To log on to this remote computer, you must be granted the Allow log on through Terminal
    Services right. By default, members of the Remote Desktop Users group have this right. If you are not a member of the Remote
    Desktop Users group or another group that has this right, or if the Remote Desktop Users group does not have this right, you must be granted this right manually"
    All the other Domain Admin Accounts do not have this problem. Suggested solutions recommend checking local policies on the individual servers however I feel that is not
    right. Also there many servers hence doing that in each member server would be cumbersome. There must be solution that requires a single action for all servers and also does not  involve creating a new account. The account was recently used to implement
    a Windows 2012R2 WSUS server and besides the DC's, it is the only other server the account can remote into. This is strange. Help please.

    Hi,
    Does that user has permission for remoting before?
    To start with, there are two types of user rights; Logon rights & Privileges. In simpler terms these are: 
    1) Remote Logon: rights to machine
    2) Logon: privileges for access to the RDP-TCP Listener
    The Remote Logon is governed by the “Allow Logon through Terminal Services” group policy. This is under
    Computer Configuration\Windows Settings\Security Settings\Local Policies\User Rights Assignment.
    Also check RDP-TCP listener properties. More information.
    “Allow Logon through Terminal Services” group policy and “Remote Desktop Users” group.
    http://blogs.technet.com/b/askperf/archive/2011/09/09/allow-logon-through-terminal-services-group-policy-and-remote-desktop-users-group.aspx
    Hope it helps!
    Thanks.
    Dharmesh Solanki
    Please remember to mark the replies as answers if they help and unmark them if they provide no help. If you have feedback for TechNet Support, contact [email protected]

  • 9971 SIP Phones at remote location status REJECTED

    Hi,
    I have 10 locations, Site 1, 2, ....10. All these locations have 10 phones each. These phone are configured with default SIP Profile. Were registered and working fine. While adding a subscriber I downgraded the cluster. After bringing back to regular version. I find all my phones status shows unknown. 
    I tried to change dhcp option 150 on dhcp router to point different server and reconfigured with the correct tftp ip address. Also I tried to shutdown the interface where phones are connected and bring it back up. Restarted tftp server many times. Even after all these I find my phones in REJECTED state. 
    I know personal reset on each phone will fix this issue. But is there any other way to fix this, since these phones are at remote locations.
    Any help is appreciated.
    Thanks,
    MR

    Hello!
    I think, that the most possible issue is problem with CTL/ITL.
    Certificates were regenerated while downgrading/upgrading and were not propagated to the phones.
    So u should try to delete ITL on the phones.
    Regards,
    Kirill

  • Specify Remote Location for PrintWriter (applet question)

    Hello,
    I am trying to use a Java applet to access a URL, read in its text content, and save it to a file. The applet is run off an online host (our school server) so I made it a signed JAR file so I could access other hosts. However, here is my problem. The applet itself is in a remote location (our school server, a unix server). I can edit the directory via SSH to add files, and these files become accessible via my homepage (where I'm running the applet from in my browser). But what I need to do is write a file IN THE SAME DIRECTORY as the applet is being run from (ie, the remote directory). But I find that when I run the applet from my browser, it instead by default saves the file I've written to in the local machine's home directory (the desktop). How can I force the applet to save/write to a file in that remote directory (I have the permissions set up on it so that non-owner can write to the directory).
    Maybe this isn't possible. I wasn't sure. Here is my code:
          //get URL containing the escape table
          URL inputURL = new URL(inputLocation);
          //make connection to the URL
          URLConnection inputCon = inputURL.openConnection();
          //save URL's contents as text file in same directory
          BufferedReader inputStream = new BufferedReader(new InputStreamReader(inputCon.getInputStream(), "UTF-8"));
          //save with same name as URL file
          File file = new File(inputURL.getFile());
          String filename = file.getName();
          PrintWriter outputStream = new PrintWriter(new File(filename), "UTF-8"); //this didn't work either: outputStream = new PrintWriter(filename, "UTF-8");
          //line of current input
          String line = null;
          //output text file to local text file line-by-line
          while((line = inputStream.readLine()) != null)
            System.out.println("line=" + line); //TEST TO MAKE SURE ACTUALLY READING FILE
            outputStream.println(line);
          }According to my System.out.println, it IS actually accessing the URL and reading each line from the URL's text file correctly, and outputStream.println(line) is correctly printing to the file; it's just doing it in the wrong place!
    Also, I should specify: I can't hard encode the file location. It could be anywhere in my html directory. Rather, I want a way to save it in the same directory as the applet was deployed from.

    It's for an assignment. All our assignments have to be applets and run from our unix server. I have to access a URL and get data from it, then create that file, then use that file as a reference table for something else.
    The tragic part is I think I have everything else working, but I've no way to test it, as I cannot figure out how to access URLs in jgrasp (my IDE - just running the java file itself as an applet within the IDE has the error message about being unable to connect to the URL, since the applet is not signed, but I've no way how to get around that within the IDE itself) so I am testing it directly on the server as a signed jar file so I can at least access the urls.
    The requirements stated:
    "make a text file (UTF-8 encoding) of the file name t in the same directory where an applet is deployed; "
    # A program must be written as an applet in Java. Other programming languages such as JavaScript cannot be used.
    # The applet must be deployed on the ITS Web server
    I could be missing something, honestly. >_< I might have a word with the TA. I'm just really frustrated since I have everything else working.

  • OAS 4.0.8.1 Administration from a remote location

    We have installed OAS 4.0.8.1 on NT and it is functioning.
    I am able to access this from a remote place and get a static web page. I don't have a registered domain name
    Can I go into Node manager (OAS Manager) from a remote location (through Internet) and manager the server.
    null

    I increased the severity level for logging to 15 for the Cartridge configuration
    in the OASManager.
    It says init method did not return. For my init method I have that following :
    public void init(ServletConfig config) throws ServletException
    super.init(config) ;
    All the above was generated by the Servlet Wizard.
    Below if the level 15 trace information :
    OWS-10911: Throwing exception for reason: wrkwExecute: Exec callback returned WRB_ERROR `
    OWS-10833: Cartridge HelloServlet/HelloCart init runtime callback did not return WRB_DONE `
    OWS-10911: Throwing exception for reason: wrkwfInit:Error in wrkwfInit `
    OWS-10911: Throwing exception for reason: wrkwfStartOrig:Error at creation time `
    OWS-10911: Throwing exception for reason: wrkwfStart: Cartridge Instance factory creation failed. `
    OWS-10803: Cartridge instance factory for HelloServlet/HelloCart not intialized `
    OWS-10911: Throwing exception for reason: No Carrtridge Instance Factories Initialized Properly `
    OWS-10821: Application HelloServlet failed to deregister with the name server `
    OWS-10850: Cartridge Server HelloServlet received exception IDL:oracle/OAS/Cartridge/InitFailed:1.0 while deregistering
    Can anyone advise why and what needs to be
    done to fix this ??
    Please help.
    Thanks,

  • Can't open HTML files from local or remote location

    Hello Experts,
    I've tried deleting my remote location, and adding it back
    again several times and I still can't open any HTML files. I can
    check out the pages, and check them back in, but nothing shows up
    on the screen. Does anyone know what may be causing this? I'd
    really like to update my website soon. If I click on the web images
    they open up in my photoshop, it's just the Dreamweaver HTML
    portions that won't open up.
    Thank you,
    Calie

    > Unfortunately I can't seem to get any of the pages open
    to check out the code
    > view.
    CLARIFY please.
    You said you open them, but design view is blank.
    The file is either open or not open
    Is the file open? And design view is blank? Or is the file
    NOT open and
    there are error messages?
    If the is open, even if empty design view There should be
    something in code
    view.
    some not random attempts at fixing this:
    open dreamweaver.
    Open this site.
    DON'T open any files.
    open find and replace
    Find in Source Code, sitewide:
    <!-- -->
    replace with: [nothing]
    reason: not much of one, but I've never seen an empty html
    comment. It
    doesn't need to be there.
    Then, i'm trying to think of a way to fix this badly nested
    bold tag
    <p><b>
    <a href="about-me.html">ABOUT ME</a> |
    <a href="contact.html">CONTACT</a> |
    <a
    href="
    http://blog.loveBaRKLee.com/">BLOG</a>
    </p></b>
    the closing </b> needs to be moved to before the
    closing paragraph tag.
    My next guess is that it's a css problem-
    http://jigsaw.w3.org/css-validator/validator?uri=http%3A%2F%2Fwww.lovebarkle
    e.com%2Fdog-bed-accents.html&profile=css21&usermedium=all&warning=1&lang=en
    moz-radius
    http://validator.w3.org/check?uri=http%3A%2F%2Fwww.lovebarklee.com&charset=%
    28detect+automatically%29&doctype=Inline&group=0
    Fix the errors, clarify if the file does or doesn't open in
    dreamweaver, if
    it opens and design view is blank or if it doesn't open and
    crashes the app.
    moosepucky.
    Alan
    Adobe Community Expert, dreamweaver
    http://www.adobe.com/communities/experts/

Maybe you are looking for

  • How do you add a new machine as an agent only to be seen by the server....?

    I'm fairly new to this but I'm starting to get the hang of it. I configured what I call a sysadmin server to serve as a SunMC-4.0, Console, Agent & Server. I can connect to the server and I see all the Modules and what's running to I'm good there. Wh

  • Correcting video flaw in  final cut pro with photo shop or other programs?

    i want to back out some flaws in my movie project. how can i do this... abobe photo shop... or illustrator will work? if not other programs... such as wacom intruso tablet 2, would appreciate any help or advice. thanks ron.

  • How do I get a MSI file for Acrobat Reader DC

    Hello, This is my first time attempting something like this but I'm trying to extract an MSI file from the Acrobat Reader DC exe file in order to deploy it via GPO. I was able to extract the enterprise exe I was given using this command structure in

  • Window doesn't open window all the way using "+" sign

    I made the switch from Windows to Mac a few years back and besides not having a HDD activity light, the biggest pet peeve I have about Apple's OS's is that they don't allow you to click on the "+" sign in the upper left hand corner of an open window

  • Java applet doesn't work

    The website I use for developping my photos use a Java applet for the upload of pictures. When I try to use it with Firefox, it doesn't work but when I tried with Safari it worked. As I use Firefox all the time and not Safari, I would like to make it