ACE30 Load balancing based on IP and using x-forward-for header
Hi Guys,
We currently have a load balancing policy setup to direct traffic to say FARM-A based on a particular range of source (client) IP addresses, and the default FARM-B for all the other traffic.
We are now looking to introduce a web application firewall (WAF) before the ACE. The WAF will be inserting the client IP address into the x-forward-for http header. Now I was wondering how best can be achieve the load balancing based on source IP given that we'll have to parse the HTTP header for this x-forward-for field? Are there any examples that anyone can point me to?
let me know if you have any questions.
thanks
Sheldon
Hi Sheldon,
You might try creating a class map that matches on the XFF header. Then use that as the L7 load balance criteria (based on the hash value of the XFF header), using the predictor hash header.
-Alex
Similar Messages
-
Capture IP without using X-Forwarded For
Hello Friends,
We are running a web-application that has a login on the very first page.
We want to capture the real IP addresses of all the customers that visit our application.
We have Cisco layer 3 Load balancer configured in a shared mode with Natting.
We are running IBM http server over Apache.
We proposed using "X-Forwarded For" header to capture client IP but were not allowed due to known vulneabilities associated with X-Forwarded for.
We want to capture client IPs for "http" and "https" without using "X-Fwd for".
Can someone kindly suggest if there is any alternate to it?
If yes then how to implement it?Hi Vivek, adding X forwarded method.to load balance policy. So that source ip address is added to HTTP header, is the only method. Unless the application itself does not request source ip add in the header. Which can be passed through the load balancer.
Sent from Cisco Technical Support Android App -
[Project] Load Balance mutiple DSL PPPOE connections using CSR1000v in Datacenter
Hello everyone
I was about to begin a new project (just for fun) and wanted to get everyones input. I live way out in the middle of nowhere where they have to pipe in sunshine and the best connection I can get is a 6mbs DSL connection. Currently I have two DSL connections in the house the end goal is to effectively bond them together.
My plans on how to accomplish this is having a couple Cisco ISR routers (probably 2821's) connect to a CSR1000v in a Datacenter that I have a colocated server. My thoughts were to set up a couple of GRE tunnels and use EIGRP to load balance between my house and the datacenter. I'd use one of my public IP's in the datacenter as the exit point.
In my head I was thinking I'd probably need to hooked up this way:
2821 -> DSL Modem \
Home Router -> Switch < Internet -> CSR1000v
2821 -> DSL Modem /
I have probably 16 or so IP's in the datacenter free so I could probably assign a /29 to my home side of the 2821's if need be.
You all think this would be the best way to go about it? Or is there a way to do it on the home side with a single 3825? I went with two because I figured I'd run into trouble with different gateways.
Thanks!
Brandon -
How do I down load an album to itunes and use my account (has $ in it) to pay for the album?
Open itunes store.
Find what you want.
Buy it. -
Creating a Master virtual hard disk and using the same for all other VM's
Hi,
We would like to create a master virtual hard disk and use the same for all other VM's. Can we do that ?
my requirements :
1) create 10 VM's
2) first create a master virtual hard disk with win OS and use the same to create the 10 VM's.
3) After creating the VM's change the HDD size.
-- if i have created master virtual disk with 500GB , and use the same for creating a virtual machine. can we change the HDD size to 1TB ?
After creating the VM's ,i will change the system names and activate the windows accordingly.
Will there be any implications ,if we can/will do like this.
Thanks.Hi Suren424,
I think Using Differencing Disks may cover your needs .
Please refer to following setps:
"Create the Parent Virtual Machine Configuration and Virtual Hard Disk
Install the Operating System, updates, and common software
Generalize the installation
Prepare the parent virtual hard disk
Create the differencing disks
Create virtual machines that use the differencing disks
For details please refer to follwing link:
http://social.technet.microsoft.com/wiki/contents/articles/1393.hyper-v-virtual-machine-vm-parent-child-configuration-using-differencing-disks.aspx
Hope this helps
Best Regards
Elton Ji
We
are trying to better understand customer views on social support experience, so your participation in this
interview project would be greatly appreciated if you have time.
Thanks for helping make community forums a great place. -
HT3529 Is there a way to create, store and use preset messages for use with "Messages"?
Is there a way to create, store and use preset messages for use with "Messages". I often have a recurrinig message to send, after a repeating event, and need to enter the same short message each time. It would be nice to have this short message stored and selectable so that I do not need to enter each time.
found an answer that seems to work:
https://discussions.apple.com/message/17997300#17997300 -
i bought an ipod in 2006 and used it only for a few days, and i lost it when it fell two times from my hand and it wasn`t working, help me regarding this.
REGARDS
RISHABH AULIYAApple - Support - iPod - Repair pricing - http://www.apple.com/support/ipod/service/prices/
ipod repair options - https://discussions.apple.com/thread/3900047 and https://discussions.apple.com/message/18867033
Service Answer Center - iPod - http://support.apple.com/kb/index?page=servicefaq&geo=US&product=ipod <-- enter correct country once on page. -
Hi,
Can we assign 2 IPs for a SCCM 2012 primary site server and use 1 Ip for communicating with its 2 DPs and 2nd one for communicating with its upper hierarchy CAS . ?
Scenario: We are building 1 SCCM 2012 primary site and 2 DPs in one domain . In future this will attach to a CAS server which is in different domain. Can we assign 2 IPs in Primary site server , one IP will use to communicate with its 2 DPs and second
IP for communicating with the CAS server which is in a different domain.?
Details:
1)Server : Windows 2012 R2 Std , VM environment .2) SCCM : SCCM 2012 R2 .3)SQL: SQL 2012 Std
Thanks
Rajesh VasudevanFirst, it's not possible. You cannot attach a primary site to an existing CAS.
Primary sites in 2012 are *not* the same as primary sites in 2007 and a CAS is 2012 is completely different from a central primary site in 2007.
CASes cannot manage clients. Also, primary sites are *not* used for delegation in 2012. As Torsten points out, multiple primary sites are used for scale-out (in terms of client count) only. Placing primary sites for different organizational units provides
no functional differences but does add complexity, latency, and additional failure points.
Thus, as the others have pointed out, your premise for doing this is completely incorrect. What are your actual business goals?
As for the IP Addressing, that depends upon your networking infrastructure. There is no way to configure ConfigMgr to use different interfaces for different types of traffic. You could potentially manipulate the routing tables in Windows but that's asking
for trouble IMO.
Jason | http://blog.configmgrftw.com | @jasonsandys -
On my home PC, I operate with Windows XP and use Outlet Express for my email. Can my Outlook Express address list be imported to my IPhone4
Not directly; OE is not supported by iTunes. You need full Outlook. Address Book in later versions of Windows is supported.
-
Is it ok to buy students version and use it mainly for University .. and sometimes i use it to design (logo, Poster, etc ..) for my friends and other peoples ?
i care really about this small detailsHi There,
Yes, yon can use if you personal as well as commercial use.
For more info check : Education FAQ
Thanks,
Atul Saini -
How to Download and Use HP iPrint for Android, iPhone, and iPod Touch
Greetings iPrint users!
The following documents contain instructions for downloading the iPrint Application and use the app to print photos.
Included on each page are step-by-step instructions with screen shots, as well as a video walkthrough.
iPhone and iPod Touch Users
How to Download and Use HP iPrint for iPhone and iPod Touch
Android Users
How to Download and Use HP iPrint for Android
Happy Printing
I am an HP Employee
Click the KUDOS Star to say "Thanks"
Please mark the post that solves your problem as "Accepted Solution"Hi nstav,
I'm sorry that you are having problems finding the app to print from your iPad to your Photosmart Premium C309a.
The app you are looking for is HP's ePrint Mobile app. You can find it in the Apple App Store or iTunes. I have included a link to a document about getting started with the app. I have also included an FAQ document for the app.
Getting Started with HP ePrint Mobile Apps
http://h10025.www1.hp.com/ewfrf/wc/document?cc=us&lc=en&dlc=en&docname=c01616126
HP ePrint Mobile App FAQs
http://h10025.www1.hp.com/ewfrf/wc/document?cc=us&lc=en&dlc=en&docname=c01923321
Regards,
Happytohelp01
Please click on the Thumbs Up on the right to say “Thanks” for helping!
Please click “Accept as Solution ” on the post that solves your issue to help others find the solution.
I work on behalf of HP -
Installig and using Crystal Report for reporting on BW
Dear Experts
We are working on BW 7.00 and do't have BO(Business Objects) . Now we wnt to install and Use crystal Report for reporting purpose. Pl. let me know whether Crystal reports can be used to extact data from BW Query or We need to have BO in order to Use Crystal Report.
Thanks in advance
Dinesh SharmaHello Dinesh,
first of all Crystal Reports is not a extraction tool - it is a reporting tool - which is a huge difference.
In regards to products you do need Crystal Reports, SAP Integration Kit, and SAP BusinessObjects Edge or SAP BusinessObjects Enterprise.
Ingo -
I am not able to set my Personal Hotspot setting, if I try to set it massage displayed "To enable Personal Hotspot for this account, contact carrier " I am in Oman and using Nawras service for data plan. Plz help me. Before I was using this service but now facing problem.
Md Asad wrote:
Yes but they told mobile co mean Device 'iPhone co'
Sorry but that makes no sense in English. Only your mobile phone company (i.e. "carrier") can enable the Personal Hotspot feature. -
Hello,
I have a back-end ACE which needs to create a sticky based on a header value. The X-Forwarded-For header is perfect as it indicates the original client ip. There is a front end ACE which is setting the header correctly.
My goal is to have the sticky associate every subsequent request originating from the same client ip (X-Forwarded-For value) to go to the same backend server. This application opens multiple sessions and they all need to go to the same backend server.
Does anyone have an example of what that backend ACE config would look like?Hi Joseph,
If I understood you correctly, you now configured the ACE to insert a header with the client IP in it. Am I right? If so, this is not going to work
For stickiness to work properly, you would need to ensure that the client (or the proxy before the ACE) is inserting a string on the request that remains constant throughout all the connections from a single client. The moment this string changes, the ACE will no longer be able to find a valid sticky entry and just send the request to another server.
If the header stickiness is not working properly due to the changing headers, you could always try using cookie stickiness instead. The ACE can insert a cookie for stickiness purposes, and there is no reason for the client to modify it.
Daniel -
IP Filtering based on X-Forwarded-For Header
Hello,
I am a newbie to the Weblogic proxy plugin to begin with.
We have a requirement to block certain IPs that are coming via a proxy. The enduser IP is embedded in the standard X-Forwarded-For header and we need to use this as our mechanism rather than the IP of the proxy. Has anyone done this before.
Can I get some pointers to literature concerning this subject?
Thank You,I forgot to mention the NSAPI plugin is involved probably because iPlanet is the Web Server sitting before the WebLogic cluster.
Maybe you are looking for
-
Hi all, We've been having some problems with all of our Photoshop files recently. It seems to be a problem that's been duplicated throughout during the design progression. When using finder to navigate through our design folders, it often locks up fo
-
How to set up BlazeDS project in FB3?
Hi , I want to start a new project with Flex,BlazDS and web service. web servces are located in other server by SOAP. I have install BlazeDS in local pc and I do not have a idea how to start set up in Flex Builder and do the project. Please help me .
-
Ignoring cRIO Host Control via Network Variables
I have a PC Host application that defines the operating state of my cRIO using Network Variables. In some cases the cRIO must ignore the Host control and define its own operating state. As an example, think of a simple boolean ON/OFF front panel co
-
Old Apps appear in Open With list
After backing up my data to another hard drive, erasing the target hard drive and doing a clean install of Leopard, I see that when I option-click a file, then select Open With, the list of applications include the apps on my backup hard drive in add
-
Errors upon saving question files
Hi- I am hoping that someone can help me here. This is the second time that this issue has hit me and my IT department is not able to resolve the issue. This is the second time that this has happened when I got to save the question file that I am cu