How can I preserve Client Port on CSS

Hi guys,
I’m wondering if there is a way to configure CSS11503 running 8.10 so that the servers in the content rules can see the client port number??
The servers can see the client IP, but not the port!! It seems when forwarding packets to the servers in the content rule, the CSS uses a new high-number port when communicating with servers.
Thanks

I might be wrong, but afaik it depends on the type of balancing method used.
As long as the CSS only needs to nat the destination it won't change the client source port.
As soon as it get's a Layer4 rule it will intercept and setup a new connection and thus cause higher port numbers.

Similar Messages

  • How can I preserve Client IP address?

    I am configuring the ACE for bridged mode. However, the real server is seeing VIP IP but not Client IPs. Our business requires that the real server must see client IPs. Do you have any idea how to set that up?
    I tried to turn ON/OFF normalization but it is still not working.
    Thanks,
    Vincent
    ==============================
    Here is my configuration:
    rserver host 192.168.71.71
      ip address 192.168.71.71
      inservice
    serverfarm host WEB_FARM
      failaction purge
      probe ICMP
      rserver 192.168.71.71
        inservice
    access-list PERMIT-BPDU ethertype permit bpdu
    access-list ALL line 8 extended permit ip any any
    sticky ip-netmask 255.255.255.255 address source WEB_FARM_Sticky
      timeout 180
      replicate sticky
      serverfarm WEB_FARM
    class-map match-all WEB_FARM_VIP
      2 match virtual-address 192.168.71.154 tcp eq 80
    class-map type management match-any remote_access
      2 match protocol xml-https any
      4 match protocol icmp any
      5 match protocol telnet any
      6 match protocol ssh any
      7 match protocol http any
      8 match protocol https any
      9 match protocol snmp any
    policy-map type loadbalance first-match WEB_FARM_Policy
      class class-default
        sticky-serverfarm WEB_FARM_Sticky
    policy-map multi-match WEB_VIPS
      class WEB_FARM_VIP
        loadbalance vip inservice
        loadbalance policy WEB_FARM_Policy
        loadbalance vip icmp-reply active
        nat dynamic 6 vlan 31
        nat dynamic 5 vlan 21
    interface vlan 21
      description Client VLAN
      bridge-group 171
      no normalization
      mac-sticky enable
      access-group input PERMIT-BPDU
      access-group input ALL
      service-policy input WEB_VIPS
      nat-pool 5 192.168.71.154 192.168.71.154 netmask 255.255.255.255 pat
    interface vlan 31
      description Server VLAN
      bridge-group 171
      no normalization
      mac-sticky enable
      access-group input PERMIT-BPDU
      access-group input ALL
      service-policy input WEB_VIPS
      nat-pool 6 192.168.71.154 192.168.71.154 netmask 255.255.255.255 pat
      no shutdown
    interface bvi 171
      ip address 192.168.71.3 255.255.255.0
      no shutdown

    Do you have a default route on the ACE and the rservers? Are they all pointing to the same IP? I have the same configuration.  An ACE 4710 in transparent mode, but I have no NATing and my rservers are able to see the original client IPs (security requirement).
    Here is part of my config for one serverfarm
    rserver host RS_MIDTIER_220
      description
      ip address 172.31.0.131
      inservice
    rserver host RS_MIDTIER_221
      description
      ip address 172.31.0.132
      inservice
    rserver host RS_MIDTIER_222
      description
      ip address 172.31.0.133
      inservice
    rserver redirect RS_SSL_Redirects
      webhost-redirection https://%h/%p 301
      inservice
    action-list type modify http SSL_URL_REWRITE
      ssl url rewrite location ".*"
    serverfarm redirect SF_SSL_Redirects
      predictor leastconns
      rserver RS_SSL_Redirects
      inservice
    serverfarm host SF_Midtier_Prod
      description Midtier Production
      predictor leastconns
      probe APACHE
      probe ICMP
      rserver RS_MIDTIER_220 80
        inservice
      rserver RS_MIDTIER_221 80
        inservice
      rserver RS_MIDTIER_222 80
        inservice
    ssl-proxy service SSL_PSERVICE_MIDTIER_PROD
      key
      cert
      chaingroup EntrustChainGroup
    sticky http-cookie JSESSIONID Sticky_Jsession_Cookie_Midtier_Prod
      timeout 90
      serverfarm SF_Midtier_Prod
    class-map type management match-any REMOTE_MGT_ACCESS
      description remote access traffic match
      2 match protocol ssh source-address
      4 match protocol https source-address
      5 match protocol snmp source-address
    class-map match-any VS_Midtier_Prod_L3SLB
      description Midtier Prod IPs
      2 match virtual-address 172.31.0.46 tcp eq https
      3 match virtual-address 172.31.0.47 tcp eq https
    class-map match-any VS_SSL_Redirects
      description Redirects any http VIPS to https
      5 match virtual-address 172.31.0.46 tcp eq www
      6 match virtual-address 172.31.0.47 tcp eq www
    policy-map type management first-match REMOTE_MGMT_ALLOW_POLICY
      class REMOTE_MGT_ACCESS
        permit
    policy-map type loadbalance http first-match Midtier_Prod_L4SLB
      class class-default
        sticky-serverfarm Sticky_Jsession_Cookie_Midtier_Prod
        action SSL_URL_REWRITE
    policy-map type loadbalance first-match SSL_Redirect_L4SLB
      class class-default
        serverfarm SF_SSL_Redirects
    policy-map multi-match Farm_VIPS
      class VS_SSL_Redirects
        loadbalance vip inservice
        loadbalance policy SSL_Redirect_L4SLB
      class VS_Midtier_Prod_L3SLB
        loadbalance vip inservice
        loadbalance policy Midtier_Prod_L4SLB
        loadbalance vip icmp-reply active
        ssl-proxy server SSL_PSERVICE_MIDTIER_PROD
    interface vlan 100
      description DMZ ACE frontside
      bridge-group 1
      access-group input BPDUALLOW
      access-group input ALL
      service-policy input REMOTE_MGMT_ALLOW_POLICY
      service-policy input Farm_VIPS
      no shutdown
    interface vlan 110
      description DMZ ACE backside
      bridge-group 1
      access-group input BPDUALLOW
      access-group input ALL
      no shutdown
    interface bvi 1
      ip address 172.31.0.150 255.255.255.0
      no shutdown
    rserver redirect RS_SSL_Redirects
      webhost-redirection https://%h/%p
    301
      inservice
    domain
    ip route 0.0.0.0 0.0.0.0 172.31.0.1

  • How can i know the port of my database?

    hello,
    how can i know the port of my database is working in?
    ty

    user11933068 wrote:
    I don't know how to do this, sorry
    :-(TNSNAMES.ORA is used by the client to resolve an alias to an actual server/listenr port/db service name.
    TNSNAMES.ORA is found, by defualt, on the client machine at $ORACLE_HOME/network/admin
    Here's how it works:
    Suppose I have this in my tnsnames.ora:
    fubar =
      (DESCRIPTION =
        (ADDRESS_LIST =
          (ADDRESS = (PROTOCOL = TCP)(HOST = myhost)(PORT = 1521))
        (CONNECT_DATA =
          (SERVICE_NAME = btzlkfp)
      )So, my connect string would look something like this:
    $> sqlplus scott/tiger@fubarTNS will take the name 'fubar' and look it up in the tnsnames file. In my example, it will then route the connection request to 'myhost' (using other net services to resolve that to an actual IP address), and place the request on port 1521 at that server. The listener will pick that up and see that scott wants to log on to database 'btzlkpf'.
    There's more, but at this stage I want you to understand the connection between what you enter for your connect string and the database itself.

  • CS3 - How can I preserve Links and Hyperlinks in my INDB?

    I am still pretty new to ID, so please speak slowly :)
    My problem - I create an INDB that consists of several indd chapters. The chapters include numerous Links (to PNG & PSD images) and Hyperlinks both to Text anchors to other chapters within the INDB, as well as to URLs. I have all items saved on my local HD. Once complete, I do "Package for Print", check the Preflight report to make sure all is OK (it is) and then save the new INDB folder in a new location on my local HD. This all seems to work just fine, BUT if I move this packaged INDB folder (such as to a backup drive, or give to another worker that copies it to their HD), upon opening the INDB file, some links and Hyperlinks are broken.
    It seems that these broken Links and Hyperlinks are still pointing to the original locations on my HD. But obviously not all are, since most links/hyperlinks DO work fine. The Hyperlinks to Text anchors within other indd chapters seem to typically break. Is there a way to force these to reference the packaged assets within the INDB folder? Seems ID would be smart enough to look there itself!
    Also, I was creating some Hyperlinks as "cross referenced" - that is, I created a URL Hyperlink Destination in Chapter 1 indd and then created Hyperlinks pointing to it from other chapter indd in the book. I have learned that these ALWAYS break in the above scenario, so I started creating the URL destination within the same chapter indd and pointing to it there rather than across chapters. But this is just more work to keep re-creating the same URL destination in every indd!
    I'll keep running into these problems since I need to share my finished INDB with other CS3 users. I also would like to be able to do a Save As of the INDB when creating a revised, newer version, but I see this also results in the new INDB links/hyperlinks still pointing to the original INDB's assets! Any way to make the Save As update the Links/Hyperlinks in the new INDB?
    Thanks greatly for any insight. I can find no help in the Help on these issues!

    The title of the post is this
    How can I preserve row and column addresses on multiple cells at once in Numbers?
    I restated the Question as follows
    Can "Preserve Row" an / or "Preserve Column" be set on multiple cells at the same time.
    In both cases it is not asked if multiple cells can be set to....
    That is a given.
    Step back a second...  It is like selecting multiple cells and setting the text color of the currently selected cells to red. This can be done. More than one cell at a time modified because they are currently selected.
    Whats is being asked is:  if more than one cell is selected at the same time can the settings "Preserve Row" an / or "Preserve Column" be applied. No table I put up will help with that question.
    YES or NO
    If YES how?

  • How can I preserve row and column addresses on multiple cells at once in Numbers?

    How can I preserve row and column addresses on multiple cells at once in Numbers 3.2.2? I do a lot of rearranging and sorting and want to reference cells in other sheets. After entering the formulas (example: '=Sheet1::Table 1::H126') I will sort the table and the formulas will not move with the sort.  I think I can fix this by going cell by cell checking the 'preserve row' and 'preserve column' boxes when editing the formula.  I want to avoid having to go one by one.  I know that checking the boxes creates a formula like this: '=Sheet1::Table 1::$H$126'  I have also tried entering this manually and filling down but it doesn't include the preservations (the $$) in the autofill.  If there is another way to remedy my sorting problem that would also be welcomed!
    THANKS!!

    The title of the post is this
    How can I preserve row and column addresses on multiple cells at once in Numbers?
    I restated the Question as follows
    Can "Preserve Row" an / or "Preserve Column" be set on multiple cells at the same time.
    In both cases it is not asked if multiple cells can be set to....
    That is a given.
    Step back a second...  It is like selecting multiple cells and setting the text color of the currently selected cells to red. This can be done. More than one cell at a time modified because they are currently selected.
    Whats is being asked is:  if more than one cell is selected at the same time can the settings "Preserve Row" an / or "Preserve Column" be applied. No table I put up will help with that question.
    YES or NO
    If YES how?

  • How can I get Client IP Address in oracle?senthil

    How can I get Client IP Address in oracle?senthil

    Hi,
    Following query can help you to get the Client IP Address.
    select sys_context('userenv','ip_address') from dual;
    Thanks,

  • How can I get client IP address in portlet (servlet) ?

    How can I get client IP address in portlet (servlet) ?
    request.getRemoteAddr() return server IP.
    May be I must use Portal API, which extend Servlet classes, but I can't find this.
    Can any help me?

    Hi,
    Following query can help you to get the Client IP Address.
    select sys_context('userenv','ip_address') from dual;
    Thanks,

  • MSExchangeTransport 1020 'NT AUTHORITY\ANONYMOUS LOGON - How can I identify Client?

    My Exchange 2010 box is logging this error with some regularity:
    MSExchangeTransport
    1020
    The account 'NT AUTHORITY\ANONYMOUS LOGON' provided valid credentials, but is not authorized to use the server; failing authentication.
    How can identify what client is attempting this connection?

    Hi,
    If there is no event id 1035, I recommend you use protocol logs with log parser to check the sender IP. Also, you can use network monitor to verify this client's IP address.
    Here is a helpful article for your reference.
    Report Top Sender IP’s on Exchange Server 2010 using Log Parser
    http://exchangeserverpro.com/exchange-2010-report-top-sender-ips-log-parser/
    Note: Microsoft is providing this information as a convenience to you. The site is not controlled by Microsoft. Microsoft cannot make any representations regarding the quality, safety, or suitability of any software or information found there. Please make
    sure that you completely understand the risk before retrieving any suggestions from the above link.
    Hope it helps.
    Best regards,
    If you have feedback for TechNet Subscriber Support, contact
    [email protected]
    Amy Wang
    TechNet Community Support

  • How can I open all ports on a Window 2003 Server

    How can I open all ports on my windows 2003 server for a specific range of IP addresses?

    Hi,
    Just want to confirm the current situations.
    Please feel free to let us know if you need further assistance.
    Regards.
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • How can I change the port of a running database ?

    Hi Friends,
    on my laptop there is running a 9i DB with port 1521 and a 10gR2 DB with port 1521 also.
    The tnsping on these db's is successfully and
    with any tools I get the error : ORA-12505 .
    How can I change a port number e.g. of the 10g DB ?
    Thanks,
    Friedhold

    These tools you are talking about, did you configure the tnsnames for them?
    If you plan to change the default listening port, you need to modify the listener.ora file under $ORACLE_HOME/network/admin
    After 9i, Oracle has service registration
    A feature by which the PMON process automatically registers information with a listener. Because this information is registered with the listener, the listener.ora file does not need to be configured with this static information.
    You can try to run one listener, see if both instances can register themselves in even they are different versions.

  • How can u creat LSMW port in Idoc Processing

    how can u creat LSMW port in Idoc Processing
    actullay i'm using Lsmw with bapi

    Hello Ronei
                 *After giving the project ,sub project ,object & short description
                      *go to menu bar click on settings  in that select idoc inbound processing ,
                      *in that screen click on maintain port push button
                      *port creation screen will be displayed in that left menu expand the file
                      *after that select file_port
                      *click on copy button
                      *provide your port name
                      *provide the short description
                      *after that deselect the uni code check box
          --->*this is the main step
                     *in the directory you will provide the path of your flat file other wise your
                      project will be terminated after 13 th step .
    thanks .
    prasad gandepalli     

  • How can I change HTTP port in J2EE

    Hi.
    I installed Sneak Preview 640 and I want to change HTTP port for J2EE. (default port is 50000)
    So, I started config tools and move to dispatcher -> service -> http -> port.
    There is port information.
    - Custom value : empty
    - Default value : (Port:80,SocketQueue:200,AcceptingThreadsCount:10,BindAddress:,Type:http)(Port:443,SocketQueue:200,AcceptingThreadsCount:10,BindAddress:,Type:ssl)
    My first question is that default port is "80" in above confirguration. Why we use "50000" ?
    Second question is that I changed custom value but It doesn't work. How can I change HTTP port ?
    Regards, Arnold.

    you can use the "visual administrator" to set your http-port, too:
    Dispatcher / Services / HTTP Provider / Ports
    kr, achim

  • How can i find SDM port , Message server port, Message server name?

    Hi All,
       I am tring to deploy a ear file from NWDS.
    I am trying to congigure through
      Windows>Preferences>SAP J2EE engine -- Remote.
    I have these questions.
    1. How can i find Message server Host?
    2. How can i find Message server Port?
    3. How can i find SDM port?
    4. What is the difference betweent the Message server port and SDM port? Both are same or can be different?
    5. What are the ways to deploy a ear file on remote J2EE engine ?
    6.Can I run SDM from a remote mechine and connect to the server?
    7. When i am trying to deploy a ear file i am getting
      "Cannot determine sdm host (is empty)" what is the possible reason.
    (Here i used information from /usr/sap/GXI/DVEBMGS00/j2ee/cluster/instance.properties for server host and port number)
    Thank you
    Ganges Leaves

    Hi Ganges~
    Please check this link~
    Deployment Problem
    Could not start SDM Server
    SDM setting the target system for j2ee engine
    "No route to host" - SDM
    SDM Error
    Can not deploy. sdm host is empty
    Hope this helps,
    regards,
    moorthy

  • How can I  change the port number generated in the returned url?

    We have a hardware load balancer listening on port 80 and forwarding requests to weblogic 6.1 sp2 servers on port 8090. The web servers generate urls containing the port number (and ip address of the load balancer). The browser tries to acces the load balancer at port 8090 and fails. So, how can I tell weblogic not to put a port number in the url?
    TIA, Reinier

    Generated WSDL will use the URL of the incoming
    HTTP GET request (request to retrieve wsdl) to create:
    service->port->location->address
    attribute inside the WSDL.
    This attribute is used by the client to send the SOAP
    request.
    So the HTTP GET request to retrieve the WSDL
    should use the address of the load balancer (ie 80).
    Then the generated WSDL will also have a url with
    port 80.
    http://manojc.com
    "reinier" <[email protected]> wrote in message
    news:3ea95116$[email protected]..
    We have a hardware load balancer listening on port 80 and forwardingrequests to weblogic 6.1 sp2 servers on port 8090. The web servers generate
    urls containing the port number (and ip address of the load balancer). The
    browser tries to acces the load balancer at port 8090 and fails. So, how can
    I tell weblogic not to put a port number in the url?
    TIA, Reinier

  • How can I use two ports in the same time?

    My application need one pc use two ports the same time.But when I open one port and my systerm is running the other port can't be opened.
    I use the frame API in VC++6.0.
    My OS is win2000 server;
    The functions I used are ncOpenObject();

    Hi DickW
    Thank you for your help!
    I have tried the example.But the example shows how to connect one CAN network with two ports.
    I want each port connect to the net can both read and write;
    I want to apply the function like this:
    1.config the port1 and port2
    2,open port1 and port2
    But after I open port1 or port2 the other port can't be opened;
    After I open the second port it always returns negative.
    In the codes I use CAN0 and CAN1 as the CAN objects.
    Attachments:
    twoport.zip ‏1184 KB

Maybe you are looking for

  • How long does it take to download a movie with a 2 Mb/sec connection speed?

    I will shortly be returning back to the UK after a number of years in India where we have a slow internet connection. I will need to sign up for a new ISP and want to choose carefully what kind of contract I buy. Downloads on my current speed ( never

  • Color picker crashes in DW 5.5 Mac OS 10.7?

    Using eyedropper in color picker in CSS Styles panel or CSS rule dialog box in order to sample color in design view outside of immediate color swatch causes crashes in Dreamweaver 5.5 with Mac OS 10.7 Lion.

  • ZOOM functionality in GANTT UI in WD ABAP not working

    Dear Experts We are using GANTT UI element in webdynpro ABAP application with time scale. While we increase or decrease GANTT zoom then time scale is not zooming accordingly. We are using below transformation lines to generate XML for TIMESCALE,     

  • Is Packager for iPhone gone?

    From http://www.adobe.com/devnet/air/articles/ios_features_in_air26.html: "The PFI (Packager for iPhone) utility is gone, and its functionality has been integrated into ADT. ADT can now be used to package AIR files, native desktop installers, Android

  • Can anyone help me in this error

    and this is the error i got :