ACE loadbalancing : cannot get to the same farm with http / ssl ?

Hello there,
I configured 2 farms, and one call on a specific host adress is redirected to farm 2.
This is working, but only for HTTP traffic : for HTTPS, it's redirected to farm 1 !
I need help, if someone can help...
I post my configuration here :
probe tcp PROBE_TCP  interval 30rserver host MTP01  ip address 172.16.0.1  inservicerserver host MTP02  ip address 172.16.0.2  inservicerserver host MTP03  ip address 172.16.0.3  inserviceserverfarm host FARM01  predictor leastconns  probe PROBE_TCP  rserver MTP01    inservice  rserver MTP02    inserviceserverfarm host FARM02  predictor leastconns  probe PROBE_TCP  rserver MTP02    inservice  rserver MTP03    inserviceparameter-map type http HTTP_PARAMETER_MAP  persistence-rebalanceclass-map match-all CLASSMAP_L3L4  2 match virtual-address 178.xx.xx.xx tcp eq wwwclass-map type http loadbalance match-all CLASSMAP_L7  3 match http header Host header-value "theurloftheserver.com"class-map match-all L4-HTTPS-IP  2 match virtual-address 178.xx.xx.xx tcp eq httpsclass-map match-all L4-WEB-IP  2 match virtual-address 178.xx.xx.xx tcp eq wwwpolicy-map type loadbalance http first-match HTTPS_POLICY  class CLASSMAP_L7    serverfarm FARM02  class class-default    serverfarm FARM01    insert-http x-forward header-value "%is"policy-map type loadbalance http first-match WEB_L7_POLICY  class CLASSMAP_L7    serverfarm FARM02  class class-default    serverfarm FARM01    insert-http x-forward header-value "%is"policy-map multi-match WEB-to-vIPs  class L4-WEB-IP    loadbalance vip inservice    loadbalance policy WEB_L7_POLICY    loadbalance vip icmp-reply active    nat dynamic 1 vlan 2369    appl-parameter http advanced-options HTTP_PARAMETER_MAP  class L4-HTTPS-IP    loadbalance vip inservice    loadbalance policy HTTPS_POLICY    loadbalance vip icmp-reply active    nat dynamic 1 vlan 2369    appl-parameter http advanced-options HTTP_PARAMETER_MAP
What is really weird is that traffic to http (CLASSMAP_L7) is ok, so I don't get it : this should match on HTTPS_POLICY, where am I wrong ?
Thanks a lot !

Hi,
You are not getting match for https since with https header would be encrypted and ACE cannot read the URL and defaults to Farm01. HTTPS is encrypted HTTP.
ACE should be able to decrypt the traffic to look into the packet and take decision. SSL termination on ACE is a feature for that. I would recommend going to the SSL guide for more details.
http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA3_1_0/configuration/ssl/guide/terminat.html
Regards,
Kanwal

Similar Messages

  • Getting error "The request failed with HTTP status 401: Unauthorized " for _vti_bin/Authentication.asmx

    Hi All,
    My Web application is FBA application and I am using the lists.asmx services in my custom webpart. To run this lists.asmx service in FBA enabled site we need to use Authentication.asmx service..
    I referred this link:
    http://social.msdn.microsoft.com/Forums/en-US/sharepointdevelopment/thread/21867e28-75d5-42c8-850b-bfb5c5894eed .
    I wrote a code as mentioned in this article but now I am getting  error "The request failed with HTTP status 401: Unauthorized " for Authentication.asmx service itself. Can somebody help me why it is not working even everything looks
    correct?
    Thank you.
    Regards,
    Rahul Shinde.

    Hi Rahul,
    Give permissions to the user on the web application.
    Central Admin -->Application Management --> Application Security -->Policy for web application --> Select the
    web application --> Add User
    For more information, refer to
    http://microsoftdev.blogspot.com/2009/10/sharepoint-web-services-access-give.html
    http://www.codeproject.com/Articles/24244/Access-a-Forms-Based-SharePoint-Site-s-Web-Service
    Best Regards.
    Kelly Chen
    TechNet Community Support

  • Another iBook cannot get past the grey screen with spinning gear

    I have read the other posts on iBooks not starting up. I too have used Onyx recently but this was to cure the problem of a freeze. Now start up cannot get past the grey screen. PRAM has been zapped and safe mode will not work. Worse, the CD drive will take CDs so cannot go back to start up disk.
    Bizarrely, a visit to the Apple Store and the iBook started no problem. System was reinstalled using archive option and various health checks apparently showed no problems. But then got back home and again start up froze at grey screen with spinning gear. I have left it on this for over 15 minutes but to no avail. I have tried to connect to another ibook using T key to get target mode. I'm not sure if I am doing this right. I have started up working iBook plugged in the firewire to both machines and then started up ailing iBook holding down T key. 2nd iBook wont start at all.
    Any suggestions?

    An Archive and Install will preserve you user settings and data. You will need a minimum of 5 GB free on the hard drive to perform an A&I; you can reduce the space required by about 1 GB by selecting the option to install language support only for the language you use (assuming you don't need multiple languages).
    However, after seeing your other post (BTW, it'll be easier to keep track if relted issues are in the same thread), you do not want to try an A&I if Disk Utility is reporting anything about 'could not be repaired'. Doing so will would ensure problems down the road, if it worked at all. It's possible for one disk problem to mask another. Whenever Disk Utility (or any other repair utility) reports making repairs, it's good practice to repeat the repair until it reports no problems found or it becomes clear it cannot repair the disk.
    DiskWarrior has an excellent track record at repairing problems that Disk Utility cannot (especially Disk Utility versions prior to OS X 10.4.2).
    If the drive cannot be repaired, you may be able to keep it by doing an erase install with the write zeros (one pass) option. That will update the hard drive firmware record of bad disk sectors to avoid using. If there are only a few bad sectors, that may let you keep using the hard drive for several more years. An erase install will do just that to your data, through. If you have access to another Mac with either a large amount of free disk space of a DVD burner, you can try using the other Mac as host and the eMac as target in FireWire target disk mode. You can run the host's copy of Disk Utility on the eMac hard drive, and hopefully be able to mount the emac HD so that you can back up the data in your Home directory.

  • My iphone 5 everytime i go into mail it comes up with - Cannot get Mail - the connection to the server failed- i then have to click ok - I am still receiving mail - it is driving me mad having to click this everytime - anybody else had the same ?

    My iphone 5 everytime i go into mail it comes up with - Cannot get Mail - the connection to the server failed- i then have to click ok - I am still receiving mail - it is driving me mad having to click this everytime - anybody else had the same problem and have found a solution - only stated happening since iPhone was updated .

    Hello there, Badboymbc.
    The following Knowledge Base article provides some steps for troubleshooting mail on your iOS device:
    iOS: Troubleshooting Mail
    http://support.apple.com/kb/TS3899
    Thanks for reaching out to Apple Support Communities.
    Cheers,
    Pedro.

  • TS1398 my new ipad works perfectly. the iphone 5, however, cannot connect to the same wifi, can barely get a 3G signal, and the power level is at 53% after being barely used for 1\2 a day. Is this a hardware problem?? My old 3Gs was fine until it died.

    my new ipad works perfectly. the iphone 5, however, cannot connect to the same wifi, can barely get a 3G signal, and the power level is at 53% after being barely used for 1\2 a day. Is this a hardware problem?? My old 3Gs was fine until it died.

    Greetings,
    I've never seen this issue, and I handle many iPads, of all versions. WiFi issues are generally local to the WiFi router - they are not all of the same quality, range, immunity to interference, etc. You have distance, building construction, and the biggie - interference.
    At home, I use Apple routers, and have no issues with any of my WiFi enabled devices, computers, mobile devices, etc - even the lowly PeeCees. I have locations where I have Juniper Networks, as well as Aruba, and a few Netgears - all of them work as they should.
    The cheaper routers, Linksys, D-Link, Seimens home units, and many other no name devices have caused issues of various kinds, and even connectivity.
    I have no idea what Starbucks uses, but I always have a good connection, and I go there nearly every morning and get some work done, as well as play.
    You could try changing channels, 2.4 to 5 Gigs, changing locations of the router. I have had to do all of these at one time or another over the many years that I have been a Network Engineer.
    Good Luck - Cheers,
    M.

  • I cannot get on the internet by proxy suddently...

    All of the problem happend Suddenly!!!!!!!!
    i met some problem... All of the problem is not appear in Windows
    1. I cannot get on the internet by proxy... I try firefox, google-chrome, konqueror, all of them
    cannot, but opera can. I dont' do anything even upgrade my system.
    2. Even if I don't use the proxy, a lot of website is not allowed to explore, for example: ebay. all of the browser cannot, but opera can....
    3.when I pacman -Syu, it will appear some error:
    error: failed retrieving file 'community.db.tar.gz' from ftp.tku.edu.tw : No address record (no address record)
    but I still can download the package and install, with poorer speed.....
    I cannot use "yaourt" to visit AUR, it may display : curl error
    I still can log on amsn and use bbs.
    how can I fix this problem? Shall I have to paste any information needed?
    Thanks for answering ^ ^
    Last edited by snowwhite777 (2010-05-13 03:07:02)

    ping www.google.com
    PING www.l.google.com (72.14.203.103) 56(84) bytes of data.
    64 bytes from tx-in-f103.1e100.net (72.14.203.103): icmp_seq=1 ttl=53 time=8.81 ms
    Ping www.google.com.tw
    PING www.google.com (72.14.203.147) 56(84) bytes of data.
    64 bytes from tx-in-f147.1e100.net (72.14.203.147): icmp_seq=1 ttl=53 time=5.64 ms
    ping www.yahoo.com
    PING fp.wg1.b.yahoo.com (72.30.2.43) 56(84) bytes of data.
    64 bytes from ir1.fp.vip.sk1.yahoo.com (72.30.2.43): icmp_seq=1 ttl=54 time=137 ms
    ping www.yahoo.com.tw
    PING rc.tpe.yahoo.com (119.160.246.23) 56(84) bytes of data.
    64 bytes from w2.rd.vip.tw1.yahoo.com (119.160.246.23): icmp_seq=1 ttl=50 time=5.64 ms
    when I ping the website that i cannot visit normally
    for example : ping www.gamer.com.tw
    PING www.gamer.com.tw (60.199.217.25) 56(84) bytes of data.
    64 bytes from www.gamer.com.tw (60.199.217.25): icmp_seq=1 ttl=242 time=6.97 ms
    I forgot to said that i cannot use "yaourt" to obtain the information of AUR
    it may display: curl error
    The admin may not change his/her config, because everything is good under windows in the same condition

  • TS1702 Cannot get iPhone 4 to talk with Mac Lion using Numpad. Have updated, restarted etc. Have Screen Sharing on. It sees my computer but when I press keys on the NumPad there is no response. I have tried it on the Calculator and on Sibelius. Any clues?

    Cannot get iPhone 4 to talk with Mac Lion using Numpad. Have updated, restarted etc. Have Screen Sharing on. It sees my computer but when I press keys on the NumPad there is no response. I have tried it on the Calculator and on Sibelius. Any clues??

    Here's how to do it.
    1. App Store, iTunes Store should have the same AppleID on Computer and iPhones. (Free to share apps, music and books... )
    2. Person A uses the same purchasing account for everything (ie. email, contacts and ...).
    3. Person B have the same purchase account see no. 1 (for App Store and iTunes Store) but create a second AppleID for iCal, e-mail, contacts  and etc.

  • I have a new Macbook pro, I cannot get past the country selection screen.  'Continue' is greyed out and keys just make error sounds. How do I move it on?

    I have a new Macbook pro, I cannot get past the country selection screen.  'Continue' is greyed out and keys just make error sounds. How do I move it on?

    sideeque wrote:
    I have the same problem. What did you do last time?
    What  should I do now? Its around 40 miles away the apple store? Would they pay my taxi fare to go and return?
    How can we trust this apple product?
    You are still under warranty.  Call Apple Care.

  • I cannot get past the password screen

    I cannot get past the password screen, I've tried resetting it but it tells. Me I'm not an allowed user

    If the old Macbook(?) has Snow Leopard 10.6 installed, and you have that retail install disc or the system disc of the current (base level) system on it, you could use the installer disc as a boot volume and use the utilities on the booted install disc to reset the password. It should be a menu option in the booted Install disc, way short of any effort to re-install anything. And if your computer can do this, the same DVD has Disk Utility, to check/repair the Mac HDD.
    What OS X version do you have, & what MacBook, etc is that?
    Good luck & happy computing!

  • Cannot Get Mail - The connection to the server failed. iPhone 3GS & Hotmail

    I've got an iPhone 3GS and I'm using Hotmail.
    I'm geting the same error message over and over - "Cannot Get Mail - The connection to the server failed.". Out of the blue it started on my phone, but then the email worked again for a day after, and then quit working again. I've tried deleting and adding it as a new account. I tried to go back to what might have in-part caused the problem, and the only thing I had done over the weekend was to turn iCloud on and start backing up to it, but the e-mail did work after that for a couple days. I've tried a couple different Hotmail accounts to see if it was a corrupt e-mail in one account, but both accounts give me the same "Cannot Get Mail" response. Creating the "TEMP" folder on Hotmail and moving e-mails there did not work.
    Could anyone spell out in layman's (non-IT) terms what I might be able to try?

    Who is the provider? Do you have two-step verification turned on? Did they change something on their end?

  • I purchased Photoshop Elements from Costco the other day and cannot get past the registration of serial

    I purchased Photoshop Elements from Costco the other day and cannot get past the registration of serial number since it says that the number is incorrect.  So, what can I do now?

    I've been experiencing the same problem for over a month now...using Windows 7

  • I use to be able to sign in to itunes store just fine but now I cannot get to the itunes store homepage?

    I use to be able to sign in to itunes store just fine but now I cannot get to the itunes store homepage?

    Hello,
    '''Try Firefox Safe Mode''' to see if the problem goes away. Safe Mode is a troubleshooting mode, which disables most add-ons.
    ''(If you're not using it, switch to the Default theme.)''
    * You can open Firefox 4.0+ in Safe Mode by holding the '''Shift''' key when you open the Firefox desktop or Start menu shortcut.
    * Or open the Help menu and click on the '''Restart with Add-ons Disabled...''' menu item while Firefox is running.
    ''Once you get the pop-up, just select "'Start in Safe Mode"''
    '''''If the issue is not present in Firefox Safe Mode''''', your problem is probably caused by an extension, and you need to figure out which one. Please follow the [[Troubleshooting extensions and themes]] article for that.
    ''To exit the Firefox Safe Mode, just close Firefox and wait a few seconds before opening Firefox for normal use again.''
    ''When you figure out what's causing your issues, please let us know. It might help other users who have the same problem.''
    Thank you.

  • TS3899 Hi my nan keeps Getting an error message of cannot get mail the connection to the server failed.... Can any one tell me what this means please

    Hi my nan keeps Getting an error message of cannot get mail the connection to the server failed.... Can any one tell me what this means please

    I too am getting this message. I have been using my iPad for two years with no problems but a couple of days ago I starting having this problem intermittently. I have restarted the iPad when that did not work I deleted the account and reloaded it. Nothing seems to work. I was having the same problem on my iPhone but that seems to be OK today. Any other ideas?

  • On my I pad mini I keep getting "cannot get mail" the connection to the server failed. but everything is Ok I can get mail. Why do I get this message??

    On my I pad Mini I keep getting the message "Cannot get Mail" The connection to the server has failed.
    But this is not the case everything works OK so why do I get the message

    An iOS fluke or mail app glitch maybe. Not sure anyone will know why you get it. Do you're ever close the mail app? Try closing it and reset the iPad and see if the message goes away.
    Assuming that you are running iOS 7, in order to close apps, you drag the app up from the multitasking display. Double tap the home button and you will see apps lined up going left to right across the screen. Swipe to get to the Mail app that you want to close and then swipe "up" on the app preview thumbnail to close it.
    Reset the iPad by holding down on the sleep and home buttons at the same time for about 10-15 seconds until the Apple Logo appears - ignore the red slider if it appears on the screen - let go of the buttons. Let the iPad start up.

  • Cannot get past the terms and conditions of the icloud thing

    i updated my iphone and now i cannot get past the icloud terms and conditions to do any thing else? help please!!!

    Since I do not know what you actually did maybe:
    http://syncor.blogspot.com/2013/09/ios7-and-missing-agree-button.html
    Otherwise:
    Try:
    - Reset the iOS device. Nothing will be lost
    Reset iOS device: Hold down the On/Off button and the Home button at the same time for at
    least ten seconds, until the Apple logo appears.
    - Go to Settings>iCloud and delete the account from the iPod and then sign back in.
    - Restore from backup. See:                                                
    iOS: How to back up                                                                                     
    - Restore to factory settings/new iOS device.             

Maybe you are looking for

  • Avoiding rendering in FCP when working with Quicktime sources

    I do a lot of stuff which requires clips dropped in from a variety of odd sources like SnapzPro screen grabs, ripped DVD (via Handbrake), and other compressed formats in differing resolutions. My usual method is to use Quicktime export to bring every

  • Access Point Help

    I have 3 1131AG access points that i am setting up in my office building. I would like to setup each ap in such a way that if a user is connected wirelessly that can "roam" throughout the building, and if they get dropped off, once they are in range

  • Unable to sync iPhone4 with new iTunes 11 UI

    Has anyone else experienced this?  Just upgraded to iTunes 11 with the new UI and found myself unable to sync my iPhone4.  The "iPhone" button would be next to the "Store" button but if I tried to click it (left or right click) the button simply disa

  • Usinf Web Beans without Business Components

    We are using JDeveloper 3.0 with Oracle8i. However, we deploy an various platforms (OAS, IBM WebSphere, Apache, Iportal) and do not want to use Oracle's Business Objects. Is there any problem with using Data Web Beans without the Business Objects? Or

  • What configuration will allow me to run at optimal proformance?

    I just recently purchased an airport extreme and I have found that there are many different settings in the airport utility. Options such as; 802.11n b/g compatible, 802.11n 2.4 GHz 802.11n 5 GHz, and different multicast rates. I really don't know mu