ACE in routed mode

My first question, can anyone recommend some very heavy reading discussing the ACE modules and associated traffic flows and order of operations?  Not just how-to scenarios.
And the primary question that brings me here:
I've got an ACE module in a 6500 chassis that's configured for routed mode.  For the purpose of this question we'll say that on the ACE I have a single VLAN for vIPs and a single VLAN for rservers.  vIP VLAN is 12 and rserver VLAN is 101.  I have a pair of App servers being load balanced, and a pair of Web servers being load balanced.
When user devices send traffic to the Web servers vIP, traffic hits the SVI for VLAN 12 and the service-policy is applied manipulating that traffic and sending it to the VLAN 101 SVI and on down to an rserver.  The same if user devices are sending traffic to the App servers vIP.
When a Web server tries to send over to the App servers vIP, I get no response.  In fact, from the Web server I can't even ping my gateway (SVI for VLAN 101).  How do I get the Web server to send traffic loadbalanced across the App servers?
Here's an example ACE config:
access-list ALL line 8 extended permit ip any any
probe tcp 5555
  port 5555
  interval 5
  passdetect interval 30
probe http HTTP
  interval 5
  passdetect interval 30
  expect status 200 200
rserver host APP01
  description App Server 1
  ip address 10.10.101.15
  probe 5555
  inservice
rserver host APP02
  description App Server 2
  ip address 10.10.101.16
  probe 5555
  inservice
rserver host WEB01
  description Web Server 1
  ip address 10.10.101.17
  probe HTTP
  inservice
rserver host WEB02
  description Web Server 2
  ip address 10.10.101.18
  probe HTTP
  inservice
serverfarm host APP-SERVERS
  predictor leastconns
  rserver APP01
    inservice
  rserver APP02
    inservice
serverfarm host WEB-SERVERS
  predictor leastconns
  rserver WEB01
    inservice
  rserver WEB02
    inservice
sticky ip-netmask 255.255.255.255 address both WEB-STICKY
  replicate sticky
  serverfarm WEB-SERVERS
sticky ip-netmask 255.255.255.255 address both APP-STICKY
  replicate sticky
  serverfarm APP-SERVERS
class-map match-any APP-VIP
  description App Servers VIP
  2 match virtual-address 10.10.12.21 tcp eq 5555
class-map match-any WEB-VIP
  description Web Servers VIP
  2 match virtual-address 10.10.12.20 tcp eq https
  3 match virtual-address 10.10.12.20 tcp eq www
policy-map type loadbalance first-match L7-APP-SERVERS
  class class-default
    sticky-serverfarm APP-STICKY
policy-map type loadbalance first-match L7-WEB-SERVERS
  class class-default
    sticky-serverfarm WEB-STICKY
policy-map multi-match L4-CONTEXT-A-VLAN
  class WEB-VIP
    loadbalance vip inservice
    loadbalance policy L7-WEB-SERVERS
    loadbalance vip icmp-reply
  class APP-VIP
    loadbalance vip inservice
    loadbalance policy L7-APP-SERVERS
    loadbalance vip icmp-reply
interface vlan 12
  description ACE-CONTEXT-A-vIPs
  ip address 10.10.12.5 255.255.252.0
  alias 10.10.12.4 255.255.252.0
  peer ip address 10.10.12.6 255.255.252.0
  access-group input ALL
  service-policy input MGMT-ACCESS
  service-policy input L4-CONTEXT-A-VLAN
  no shutdown
interface vlan 101
  description ACE-CONTEXT-A-SERVERS
  ip address 10.10.101.2 255.255.255.0
  alias 10.10.101.1 255.255.255.0
  peer ip address 10.10.101.3 255.255.255.0
  access-group input ALL
  no shutdown

Hi Adam,
You can check Gilles'  DC t-shooting guides that should give you a very good overwiew about packet processing on the ACE; also you can check
the Cisco wiki site where you find the scenarios plus a detailed explanation for traffic management.
Now going back to your issue, you problem can be splitted in two parts.
1. Web server not able to ping VLAN 101 ACE's SVI.
ACE is a closed device, meaning that access to each Interface/VLAN needs to be explicitly configured; you need to apply the management policy
to the 101 SVI to allow ICMP or any other management protocol. You can apply the same (service-policy input MGMT-ACCESS) or create a new
one just for ICMP, that's up to you.
2. Web servers not able to communicate with APP servers thorugh VIP.(vise-versa)
Problem here is that servers are trying to communicate through SVI 101 but no VIPs are applied to it so the ACE will simply discard the packets
for 10.10.12.20/10.10.12.21 on that interface, servers have the ARP and everything to reach those VIPs but the ACE has not been instructed to do
load balancing for clients reaching it out through VLAN 101.
In order to do load balancing between APP & Web Servers you need to configure  L4-CONTEXT-A-VLAN on SVI 101 as well.
Also since your servers are sitting all in the same VLAN you're going to need client NAT to prevent assymetric routing on server-to-server communications.
I've attached a sample with NAT based on your config.
HTH
Pablo

Similar Messages

  • ACE module routed mode

    Hi,
    I have a scenario where I have a pair of 6509 switches and I need to add an ACE module on both of them. All clients Default gateway are on internal 5580 ASAs so there are no SVI interfaces on the 6509 switches, it's only doing layer 2 switching.
    I need to add an ACE module to the above setup, what's the ideal scenario in terms of routing without having to modify and add SVIs on the 6509?
    Regards

    http://docwiki.cisco.com/wiki/Basic_Load_Balancing_Using_One_Arm_Mode_with_Source_NAT_on_the_Cisco_Application_Control_Engine_Configuration_Example
    http://www.cisco.com/en/US/docs/interfaces_modules/services_modules/ace/vA2_3_0/configuration/getting/started/guide/one_arm.pdf

  • Ace routing mode desging issue

    need some assistance in configuring an application using routing mode on cisco ace
            clients ---asa--3750--cisco ace--- servers behind vip
                                                                |
                                                              visa card transaction servers
    i am able to setup a vip on ace using routing mode on ACE,as the  servers need to see the client ip ,so we are not  performing SNAT,this  part is working fine
    when a request comes from the client ,it goes to the vip and to one of the backend servers ,and the request will be forwaded back to the ace ,as the default gateway on the servers is pointing to the server vlan on ace.
    but if the transaction from the servers need to go to the visa card transaction servers ,how can we acheive this ,and after fetching the data from visa servers,does the reply will be fwd to the ACE or ASAs directly
    Or do we need to have static routes defined on the visa servers to point to ASA
    please advise me on this

    Clint
    No they are completely in a different network ,
    When a client hits the VIP ,the request goes to the ASA
    ASA fwd the  vip traffic to the ACE (VIP) interface  ,and from there it fwd the traffic to the (server vlan) interface and to the appropriate backend servers.
    Backend server responds back to the (server vlan ) interface and the traffic fwd back to the ASA.
    But when  visa card transaction need to take place ( farm servers ) need to route the traffic to the visa servers which will be in different subnet range .
    Do the farm serevrs send the request back to the ASA and can we configure static routes on ASA to point to the visa servers.
    Are on the farm servers can we have static routes for the visa servers
    Or can I defind static routes on ACEs for the visa servers.

  • ACE routed mode design issue

    I am configuring ACE in routing mode ,
    Below is my ACE interface config.
    interface vlan 28
      description "CLIENT VLAN"
      ip address 192.168.10.11 255.255.255.248
      peer ip address 192.168.10.12 255.255.255.248
      mtu 1500
      mac-sticky enable
      access-group input ALL
      service-policy input remote_mgmt_allow_policy
      service-policy input POLICY
      no shutdown
    interface vlan 29
      description "SERVER VLAN"
      ip address 192.168.10.19 255.255.255.248
      peer ip address 192.168.10.20 255.255.255.248
      mtu 1500
      mac-sticky enable
      access-group input ALL
      service-policy input remote_mgmt_allow_policy
      service-policy input POLICY
      no shutdown
    When I  configuring my servers in vlan 29 and  point the default gateway to 192.168.10.19  it works fine no issues,but when this ACEs goes down and the standby becomes active ,my servers default gateway will be still pointing to 192.168.10.19  do i need to manually change it .20
    or can I configure HSRP,Please advise me on this

    Hi ,
    Yes the alias should be set as gateway for the servers.
    The alias is a shared address between the peers. This address will be on the ACTIVE ace. 
    Regards
    Dan

  • ACE bridge mode , FWSM routed mode

    i have the following senario:
    MSFC ---vlan 777----FWSM----vlan160---ACE----VLAN180
    FWSM is working in routed mode and vlan 777 is shared between the MSFC and FWSM
    ACE is working in bridged mode and vlan 160 is shared between the FWSM and ACE
    vlan 180 is the server side vlan
    i want he FWSM ip address to be the Server gateway while ACE module in
    bridge mode
    i create bvi interface but i can't ping from ACE to FWSM or from FWSM to
    ACE
    if i change ACE to routed mode , i can ping to FWSM
    any body can help me in this issue?

    The config looks good.
    I would look at the arp table on FWSM and ACE when the ping fails and also capture a sniffer trace of ACE tengig interface and see if the ping request goes out - on which vlan - and if we get a response.
    Is evertyhing else working ?
    Like ping through the ACE module ?
    Your config does not show a 'no shutdown' on the vlan interface, but I assume you fixed that already.
    Gilles.

  • ACE in bridged mode and multicast

    We have configured an ACE SM in bridge mode and have a requirement to enable multicast on one of the networks where the back-end servers are residing. Will ACE support multicast out of the box, or will we need to do any tweaking on the ACE to enable the multicast support?
    Thanks..

    Hi Gilles,
    Is it also supported in routed mode?
    The ace isn't doing multicast routing right?
    Actually, the server-side vlan is being routed on the C6500 and has pim sparse-dense mode enabled.
    We want to move this server-side vlan behind the ace in routed mode. What about the pim?
    Any ideas?
    thanks,
    Dario

  • SNAT on routed mode.

    Hi,
    i have a topology where i have to set up an ACE in routed mode with two context. one for service provider A and one for ISP B.
    what i want to do is when i receive a request coming from service proveder A i would like to SNAT that request to de VIP with a specific IP of the servers LAN to hide the source IP of the cliente in that way a can receive the request on the server with a local IP and the resever can respond to that IP.
    in the same way to handle traffic on the second ISP.
    i have try to set up the configuration in the same way it would work in one arm but it has not worked out for me.
    is there a guide to follow or if someone can help me whit this config.
    best regards.

    Hi Lucas,
    Does your current NAT config like this?
    class-map match-any ISP-1
      2 match virtual-address 20.20.20.10 tcp any
    policy-map multi-match LB
      class ISP-1
        loadbalance vip inservice
        loadbalance policy ISP
        loadbalance vip icmp-reply active
        nat dynamic 7 vlan 10
    interface vlan 10
      description Server VLAN
      ip address 10.10.10.1 255.255.255.0
      nat-pool 7 10.10.10.15 10.10.10.20 netmask 255.255.255.0 pat
      access-group input any
      access-group output any
      no shutdown
    interface vlan 20
      description ISP VLAN
      ip address 20.20.20.1 255.255.255.0
      access-group input any
      access-group output any
      service-policy input LB
      no shutdown
    Pablo

  • Can VIP and Rservers be in the same subnet in ACE Routed Mode

    Good Day,
    Sorry for the lengthy post.
    Currently I have a 6509s running in VSS mode with ACE30 in each chassis.
    I have 5 vlans, which the VSS is the L3 interface for each. 1 Vlan is for management, the others are the data vlans for the servers.
    The ACE is configured in bridge mode, with all VLANs going to a specific context (non Admin).
    Some of the Host on each VLANs are not utilized for load-balancing. The default gateway for each VLAN is configured on the VSS.
    I would like to setup the ACE in the routed mode, without having to change the IP address of each servers on different VLANs.
    Basically I want to turn off the SVIs on VSS and move the L3 interface on the ACE Context, and let it perform the local routing for all the hosts.
    I was going to add a new /30 L3 interface between the VSS and ACE to be utilized for default route traffic coming from the ACE Context, and static routes from VSS to ACE for traffic destined to host that are being load-balanced and not being load-balanced. Basically force the traffic through the load-balancer in/out.
    For future deployment, I was planning on using different IP address for the VIPs, and Real servers (most likely RFC 1918).
    From most of the examples I have seen the VIP and Rservers are in different Subnets. But because I am trying to not change the IP address of the rservers and VIP, I wanted to know if the VIP and Rservers can be configured to be in the same subnet where the ACE is in routed mode.
    Unfortunately I don't have a spare ACE to test scenario.
    As always any help would greatly be appreciated.
    Regards,
    Raman

    Link-local addresses are usually the self assigned IP address that a device will set when a DHCP server cannot be found. These are the addresses with 169.254.x.x subnet.
    If the router is assigning IP addresses for your network, then they will usually have a different IP subnet, possibly 192.168.0 for D-Link. And this subnet would be for the wired and wireless connections. So it would be more a case of bridging the two network topolgies rather than routing them.
    The network host is busy message could be more to do with the driver and the IP protocol selected when creating the queue than the connection being broken between the Mac and printer. If you were to open Network Utility and select the Ping tab, enter the IP address of the HP and set the pings to 4, pressing the Ping button will soon show if there is a path through the wireless to the printer.
    If you get a response to the ping you could then open Safari and type the ip address as the URL. This would then connect to the internal web page of the printer and possibly let you enable an IP protocol like LPR so that you can use LPD on the Mac instead of Bonjour to connect to the printer.
    As for the driver, you could look at using a Gutenprint driver instead of the HP driver or the hpijs package to get past the limitations that some printer drivers have with network connections.

  • Sharing a VLAN between FWSM and ACE (Routed Mode)

    Anybody in here with experience on sharing a Vlan between an ACE and a FWSM module?
    I have a transfer network between the ACE and the FWSM in the same chassis. FWSM gets several vlans and ACE gets some Vlans.
    I wanted to configure it like this.
    firewall vlan group 10 <FWSM only vlans>
    firewall vlan group 20 <shared FWSM and ACE vlan>
    or
    svclc vlan group 20 <shared FWSM and ACE vlan>
    svclc vlan group 30 <ACE only vlans>
    The design hides the client side network and the server side network for the ACE behind the FWSM module.
    Layout:
    |-- Clients <--> MSFC <--> FWSM <--> ACE <--> Server --|
    So allocation on the 65xx would be like this.
    firewall module n vlan-group 10,20
    svclc module n vlan-group 20,30
    Any obvious issues with this design if you share the vlan(s) referred in group 20 with both modules?
    FWSM and ACE will be in routed mode.
    Thanks for reading...
    Roble

    Never mind...
    Just found the perfect answer for this in a another posting from Syed.
    http://forum.cisco.com/eforum/servlet/NetProf?page=netprof&forum=Data%20Center&topic=SNA%20Data%20Center%20Networking&CommCmd=MB%3Fcmd%3Dpass_through%26location%3Doutline%40%5E1%40%40.1dddee0b/0#selected_message
    Roble

  • ACE in a routed mode

    Guys,
    Should the ACE be the gateway for the load balanced servers in a routed mode scenario ? If yes then why ?
    Sent from Cisco Technical Support iPad App

    yes ACE interface on server vlan should be gateway. routed mode implies layer 2 adjacency of servers and ace. If ace is not the gateway and you are not doing source nat on ace then servers would respond around the ace to client via it's gateway. unless specifically configured for direct server return client would be seing response from server address rather than vip resulting in failure.

  • ACE One Arm Mode vs Routed Mode

    Gents,
    When is it required to use the One Arm Mode and one do I use the routed mode? Actually I am confused and would really like to know the pros and cons of each?
    Regards,
    Hesham                  

    Hi Hesham,
    When you do not want to change the physical topology of your network then you usually go with ONE ARM mode.
    Such as default gateway on server, IP addressing on servers. In this case client can access the server directly as well.
    Its a flat network topology where your VIP and servers are in the same network ( VLAN ).
    You use routed mode when you want to segregate the servers in seperate vlan and don't want to allow client to access it directly.
    Client and VIP in same VLAN >>> ACE >>>>>> Server VLAN ( In this case we usually point the default gateway to ACE)
    hope it helps.
    regards,
    Ajay Kumar

  • ACE routed mode

                  Two  ACEs LoadBalancers    are setup as active standby    in routed mode.
    serverfarm host s1
      predictor leastconns
      probe PROBE_HTTP
      rserver app1
        inservice
      rserver app2
        inservice
    class-map match-all s1_CLASS
      2 match virtual-address 10.12.7.11 tcp any
    policy-map type management first-match remote_mgmt_allow_policy
      class remote_access
        permit
    policy-map type loadbalance first-match s1_POLICY
      class class-default
        serverfarm s1
    policy-map multi-match POLICY
      class s1_CLASS
        loadbalance vip inservice
        loadbalance policy s1_POLICY
        loadbalance vip icmp-reply active
    we had one connection  from client to app2 server
    performed a code upgrade  on LB2 ,did a swithover to make LB2 active,.the client connection was still on app2 server
    when LB1 was upgraded  and made it primary , the connection was still on app2 .
    but after couple mins was seeing the connection on app1 ,instead of app2 .
    please help me on this
    when
    when

    Hi,
    What you saw it is totally expected behavior.
    What happens is that the ACE will keep the connections active and they will be served until the either the connection is closed by the client( by closing the browser) or times out due to inactivity, then if you switchover to another ACE then all "NEW" connections will be handled by the new master ACE since there´s no reason to send the traffic to the previous master ACE because it is not longer the Primary.
    Again, this is expected.
    Hope this helps
    Jorge

  • ACE Routed mode - cannot see serverside network

    Hi all,
    I'm having a problem with the first context I've set up in pure routed mode without NAT. Taking advice from this forum I've defined the interface for the serverside VLAN only in the ACE context. Trouble is this doesn't seem to have propagted into the routing table.
    The ACE can see the servers - they are in the ARP cache and can be PINGed from the context.
    A show IP route on the 6500 doesn't find the serverside subnet in the routing table.
    Am I missing something obvious. I've attached the config if that helps.
    Thank you
    Cathy

    I am not sure what your question is
    Are you not seeing the VIPs in 6500 routing table? If its about vip the RHI (Route health injection (loadbalance vip advertise) should take care of it.
    Or you want to see the Server vlan in the routing table of 6500?.
    If thats the case then that is not going to happen. You will have to add static routes and redistribute them in the network (on upstream router).
    Syed Iftekhar Ahmed

  • Does ACE-30 support multicast in routed mode?

    We currently have ACE20's, which only support multicast in bridge mode.
    Was wondering if it's the same on ACE30's, or if Cisco finally implemented support for mcast in routed mode.
    thx
    Kevin

    Could you please confirm if this applies to both ACE20 & ACE30, or just ACE20?
    If both, when does Cisco plan on supporting mcast in routed mode?
    thx
    Kevin

  • Example Config ACE routed mode with NAT

    Hi all,
    i have a two-arm loadbalancer (routed mode).
    client ->vlan100->[VIP]Loadbalancer[NAT] ->vlan200-> serverfarm
    But i have my problems to configure the NAT. Can anybody show me a example configuration of a two-arm loadbalancer with NAT?
    Especially the access-list, class-map, policy-map and on which interface the NAT-Policy must be added.
    BR
    Dominik

    Hi Dominik,
    Something like this:
    access-list ANYONE line 10 extended permit ip any any
    rserver host SERVER_01
      ip address 10.198.16.2
      inservice
    rserver host SERVER_02
      ip address 10.198.16.3
      inservice
    rserver host SERVER_03
      ip address 10.198.16.4
      inservice
    serverfarm host REAL_SERVERS
      rserver SERVER_01
        inservice
      rserver SERVER_02
        inservice
      rserver SERVER_03
        inservice
    class-map match-all VIP-30
      2 match virtual-address 192.168.1.30 tcp eq www
    class-map type management match-any REMOTE_ACCESS
      description remote-access-traffic-match
      2 match protocol telnet any
      3 match protocol ssh any
      4 match protocol icmp any
    policy-map type management first-match REMOTE_MGT
      class REMOTE_ACCESS
        permit
    policy-map type loadbalance first-match SLB_LOGIC
      class class-default
        serverfarm REAL_SERVERS
    policy-map multi-match CLIENT_VIPS
      class VIP-30
        loadbalance vip inservice
        loadbalance policy SLB_LOGIC
        loadbalance vip icmp-reply active
        nat dynamic 1 vlan 452
    interface vlan 451
        ip address 192.168.1.2 255.255.255.0
      access-group input ANYONE
      service-policy input CLIENT_VIPS
      no shutdown
    interface vlan 452
      description Servers vlan
      ip address 10.198.16.1 255.255.255.0
      access-group input ANYONE
      nat-pool 1 10.198.16.5 10.198.16.5 netmask 255.255.255.0 pat
      no shutdown
    ip route 0.0.0.0 0.0.0.0 192.168.1.1
    Cesar R
    ANS Team

Maybe you are looking for

  • How to contain all windows in Application Frame cs5 MAC

    Hello, This is my last resort to hopefully find a solotion to my problem. Ive recently switched from PC to MAC, and since the switch I have had some trouble with photoshop (apparently its not the same?) Now please bear with mem I have trouble explain

  • Runtime Error - No Component Exist with the name "FLAG"

    This is an issue I am having from chapter 5 exercise 2 from the ABAP Basics book. Moderator message - Welcome to SCN. Please note that there is a 2,500 character limit to posts in the forums. Please post only the relavant portions of your code.. Also

  • Why we need ITS & Web As server in portal landscape

    HI Gurus, Why we need ITS server and web As server in portal landscape Thanks in Advance, Sakthi

  • Updating xml with jdom

    I create a blank xml file when my user selects new: and I create a list of the elements <?xml version="1.0" encoding="UTF-8"?> <Root>    <START/>    <END/> </Root>User creates a new element, i insert the new element between start and end. It's there

  • The airplay icon has disappeared from my menu bar, help?

    Not sure how it happened but the airplay icon has disappeared from my menu bar, !! can anyone help. I logged out and restarted but still not appearing.