IOS SLB and Stateless failover

Trying to compare CSM and IOS SLB features. Read where the CSM can have "stateful" failover (maintains sessions) in a box-to-box scenerio. I also read where the IOS SLB can only provide "stateless" failover (I assume during failover, state/connection information is lost) using HSRP.
Can anyone confirm what I have written?
Your help is much appreciated.

That is correct.
The CSM can maintain state on connections on a failover using the "replicate csrp" command. This command is not available on IOS SLB.
The following are links to the CSM commands and IOS SLB commands for your reference...
CSM Config guide, release notes and commands:
http://www.cisco.com/univercd/cc/td/doc/product/lan/cat6000/cfgnotes/csm_3_1/index.htm
IOS SLB commands: http://www.cisco.com/en/US/customer/products/sw/iosswrel/ps1835/products_command_summary_chapter09186a008008805e.html
IOS SLB config guide:
http://www.cisco.com/en/US/customer/products/sw/iosswrel/ps1835/products_configuration_guide_chapter09186a00800ca75d.html
hope that helps
-Steve

Similar Messages

  • IOS SLB and DNS failover

    Hi, there:
    Is that possible I could use IOS SLB and DNS failover automatically?
    i.e:
    vip 10.1.1.1
    vip 10.2.1.1
    dns records:
    vip1 10.1.1.1 10.2.1.1
    normal condition:
    vip1 will be 10.1.1.1
    when 10.1.1.1 failed it will give 10.2.1.1
    Is that something it could be done on IOS SLB, or other devices?
    real services are udp based.gtp service
    Thanks,

    Yes, IOS server load balancing and the DNS failover can be done automatically. Is this not working currently? Can you posts the configuration so that we can check where the problem is.

  • IOS SLB and FWSM

    Hi, this may be a silly question but is there any problem with configuring IOS SLB on a 6509 which also has a FWSM module in it and the Servers being load balanced are behind the FWSM?

    The only thing to consider is that by FWSM, you most likely will be running multiple VRFs on the switch and IOS-SLB has some limitations regarding VRF.
    IOS-SLB probes are sent to the global routing table (VRF default) and you will need to 'no advertise' and add static routes to null0 to the VRF for the virtual IPs.
    Other than that, IOS-SLB works fine with the FWSM and VRF...

  • IOS SLB and probe failure

    Hello,
    we use server-load-balancing with IOS 12.1(19)E1
    We have a problem if the server receives more connections following error messages “REAL 192.168.197.8 (HSSAT1-LX) has changed to PROBE_FAILED” and few seconds later “REAL 192.168.197.8 (HSSAT1-LX) has changed to OPERATIONAL” appears and so on.
    We checked the server and they works proper.
    What could be the reason for probe failed?
    My configuration:
    ip slb probe HS-PROBE tcp
    interval 5
    ip slb serverfarm HSSAT1-LX
    nat server
    predictor leastconns
    failaction purge
    probe HS-PROBE
    real 192.168.197.8 99
    reassign 2
    inservice
    real 192.168.197.9 99
    reassign 2
    inservice
    ip slb vserver HS.SAT1.DE
    virtual xxx.xxx.xxx.xxx tcp www
    serverfarm HSSAT1-LX
    advertise active
    inservice standby allvips
    How does a TCP probe works? – I could not find more exact information in the documents to configure probes.
    Is it better to use another probe (icmp)? – or without any probe?
    When does it make sense to use probes?
    Best regards
    Stefan

    HI Stefan,
    tcp probes do a complete TCP 3-way handshake and normaly terminate the session. A problem which I had some times timeout for a session to be established might be to short if the server is "heavy" loaded.
    Probing on a specific method (TCP HTTP ...) is most of the times the better solution. Imagine a WEB-Server which is properly pingable but the httpd died due to some internal error. If you would probe on a per ping basis the loadbalancer will never notice this but if you monitor tcp-port 80 by a tcp probe or better a http probe you will notice this and the server would be taken out of the serverfarm. Even better but afaik not possible in IOS SLB is to probe a certain page e.g. index.html. As you know that the httpd is up and running and pages can be displayed.
    Regarding the probing issue it might be usefull to read the follwing link describing healthmonitoring with the CSM
    http://www.cisco.com/en/US/products/hw/switches/ps708/products_installation_and_configuration_guide_chapter09186a00801c5899.html#1024967
    Hope that helped.
    Best Regards,
    Joerg

  • IOS SLB and MRTG ?

    I've tried to run MRTG against IOS SLB to get stats on the VIPs, but can't get it to work.
    Anyone else had any luck with this ?
    Anyone monitoring individual VIPs or serverfarms some other way?
    Simon

    You could try using SNMP to poll the SLB instead. I also found that MRTG doesn't work too well with SLB.
    You could use MIBs to monitor VIP processor load and memory usage.
    This is the link to the MIB that will enable you to poll SLB through SNMP:
    ftp://ftp.cisco.com/pub/mibs/v2/CISCO-SLB-MIB.my

  • IOS SLB and IBM Workload Manager

    Does anyone know if IOS SLB can function similar to Multinode Load Balancing (MNLB) in that the IOS router acts as a Services Manager which contacts the OS390 Worload Manager (WLM) who then reports back the best OS390 server for a particular connection.
    Under MNLB, the Local Director performs the task as the Services Manager, but can a IOS SLB router perform this task?
    Thank you for your help.

    Steve, thank you for the reply. I have a large-scale OS390 WLM request as I'm told that this is the method for providing server load-balancing in a sysplex environment. I wonder why it is not supported in version 4.X. Do you happen to know the long term goal for OS390 load balancing support?
    I appreciate your help, Thank you

  • CSM - IOS SLB failover ?

    I can't see this from the documentation, but as far as I can see the configuration commands on the switch are the same for IOS SLB and for the CSM. Does this mean that if you have an CSM which fails, the subset of functions supported by IOS SLB will be ?
    I realise performance would be less and only 500 VIPs would be supported etc.
    Thanks
    Simon

    Simon,
    I do not think this is the case. If you look closely at the configuration you will see the command ip slb mode csm. This causes all SLB functions to be offloaded to the CSM. The default is ip slb mode rp which is IOS based. If the CSM fails then SLB will stop working. You will need to enter the command ip slb mode rp for it to work again.
    If you are running version 2.1 or above it is recommended you run ip slb mode rp and use the configuration command
    module ContentSwitchingModule X where X is the module number
    and the slb commands under this.
    Cheers
    Phil
    Cheers
    Phil

  • IOS SLB versus CSM

    Hi,
    trying to figure out a possible solution for a 6500 and got a bit confused. According to my knowledge, IOS SLB is working either in L2 (MAC) or L3/4 (NAT), to ensure load balancing. CSM comes in the game, but offers much more, extending to L4/7. Are the two solutions substitude or complementary? Is it true that only with an CSM can you get HTTP probes to check your load balanced server farm? What other differences do you know about these two solutions?
    In the paper http://www.cisco.com/en/US/partner/products/hw/modules/ps2706/products_configuration_example09186a0080094066.shtml
    it is stated that "To run Cisco IOS SLB software, you must configure the mode using the show ip slb mode [csm | rp] command before any configuration. In the show ip slb mode command, the rp argument is default. You can only configure csm argument if you have the Content Switching Module (CSM)."
    While in
    http://www.cisco.com/en/US/partner/products/hw/modules/ps2706/products_configuration_example09186a008009452d.shtml
    cisco states that "You cannot run Cisco IOS® SLB software on the same switch as the CSM."
    Any ideas on that?
    Thanks in advance

    there are 2 ways to configure the csm.
    You can use the same ios slb command and just tell the switch that there is a csm with the command 'ip slb mode'.
    Or you can use the 'module contentswitching ' command.
    If you use the first method, you can't use both a CSM and ios slb on the same switch.
    If you use the second method, it is ok to have both ios slb and csm.
    IOS SLB offers L4-7 loadbalancing solution.
    Just be aware that as soon as you do L7 or do some nating, you poor performance with ios slb compare to a CSM.
    One advantage of ios slb is the capacity to do radius loadbalancing [inspecting radius packet to identify framed ip, ...]
    This is why in CMX solution we combine both ios slb and csm.
    IOS SLB is used to loadbalance radius and the CSM is used to loadbalance the rest of the traffic.
    Personally, I would say if you just need some vpn or firewall loadbalancing, ios slb is enough.
    If you need HTTP or any other traffic wthe CSM is a better choice.
    Regards,
    Gilles.

  • IOS SLB w/GLBP?

    Currently I'm using IOS SLB with stateless backup on a pair of switches running HSRP. We are installing another project with similar requirements except we are trying to move to GLBP for a variety of reasons.
    As best as I can determine the stateless backup features only seem to work with HSRP at least that's my guess from the documentation. Anyone have any experience with this?
    I really don't want to have to fall back to HSRP on this particular pair of switches.

    IOS SLB stateless backup does not support Gateway Load Balancing Protocol (GLBP). Only HSRP.
    http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fipr_c/ipcprt1/1cfsflb.htm#1001462

  • IOS SLB Products

    I have recently been researching the IOS SLB features but have had a hard time finding the list of products that support IOS SLB and which feature sets it is available in. Does anyone have the CCO link where this is all located? Thanks!!
    -jason

    This feature can be run on the 7100 & 7200 series routers and on the Catlyst 6000 series switches equipped with a Superviser 1 or 2 routing blade.
    It will also run on 4840g switches which are currently end-of-sale.
    You'll have to use the feature navigator to make sure which software image you need for which platform.
    Cheers,
    Perry.

  • IOS SLB inservice standby

    Hi,
    I would like to know what is the main purpose of use the "standby" at the "inservice standby <group>" defined under the virtual server?. It's just a information ("as description") to associate the HSRP standby into this virtual server or it's have another function?.
    Thanks,
    Marcelo

    Marcelo,
    IOS SLB "inservice standby" is used where you require stateless redundancy for vservers across 2 SLB routers or switches. Using this command makes the vserver state follow the HSRP state of the relevant interface, to prevent the situation where one router is processing routing traffic but the other router is active and listening for traffic directed to the vserver address. It is much more than a description for the HSRP group, it is the mechanism to allow redundancy to function.
    This page has details0
    http://www.cisco.com/univercd/cc/td/doc/product/software/ios122/122cgcr/fipr_c/ipcprt1/1cfsflb.htm#1001434
    Regards, Peter

  • IOS SLB - Samba

    Hi,
    Is it possible, and can anyone provide an example, to configure IOS SLB for Samba services ?
    Thanks

    Thanks for the response Ivan,
    My level of account access wont allow me to view the link you have provided
    Here's what I am looking at trying to achieve....
    We have a file system that is accessed by many clients, the access is via a proprietary protocol. In order to support generic client access we mount the file system, using our own driver and share it as a Samba share. The systems hosting this Samba share are used for client access.
    So, we could potentially have multiple machines hosting the same file system via Samba.
    I would like to be able to present this architecture as an N+1 resilience model, which would require load balancing and failover on the machines hosting the Samba mount. IOS SLB seems like the right approach on paper, especially if you substitute Samba for FTP as an example.
    One concern I do have is whether the throughput is constrained by utilizing SLB. Do you have any comment on this ?
    I will look to see if I can dig up any L4 LB papers elsewhere in the mean time.
    Thanks for your input thus far.

  • IOS SLB Loab Balance Questions

    Forgive me if this is the wrong forum but it was the closest one I found relating to my issue.
    I've trying to load balance four of our radius servers using IOS SLB. The config works well and the radius servers are accepting requests fine. I follow this article which wasn't too bad to follow:
    http://www.cisco.com/application/pdf/en/us/guest/netsol/ns377/c649/cdccont_0900aecd800eb95f.pdf
    My two questions are:
    1. Sticky Option
    I understand it's used to make sure the client's accounting information
    goes to the correct real server, but I'm not sure how it really works
    and what's the best time to set it to.
    Eg:
    ip slb vserver RAD-UDP-1646
    virtual 210.x.x.224 udp 1646
    serverfarm RADFARM
    sticky 86400 group 10
    inservice
    a/ The documentation says "This configuraion causes the sticky database to store its entries for 86,400 seconds of inactivity". What do they mean by "inactivity" - no radius packets coming through? inactivity from the user's end?
    b/ It also says "the client's IP address is added to the IOS SLB database..." - is this the client's framed IP that the ISP assigns to the customer???
    c/ And what would be the optimum time to set the sticky timer to be?
    2. SLB connection statistics
    core1-router#sh ip slb reals
    real farm name weight state conns
    203.x.x.74 RADFARM 8 OPERATIONAL 0
    203.x.x.78 RADFARM 8 OPERATIONAL 0
    203.x.x.79 RADFARM 8 OPERATIONAL 0
    203.x.x.80 RADFARM 8 OPERATIONAL 2
    When you disconnect, the slb stats still show you as being connected to
    the real server (and both udp ports) which isn't very accurate. There is a default "delay" time which handles TCP disconnections and after being disconnected for 10 sec, the SLB stats are updated to reflect this (I've verified this works)- but nothing about how it handles UDP disconnections??? This
    would skew the stats and give us a very bad misrepresentation of the
    number of current and valid connections. Is there anyway to correct this???
    Thanks.
    Andy

    Inactivity for IOS SLB means that after specified time of inactivity, the client will be free to be load balanced to another server. As long as they remain active without an idle time , they will remain connected to the same real server. For the client's IP address which is added to the IOS SLB database I think it is the frammed IP address which the ISP assigns. The optimum time for the sticky timer will be its default value or say 60 seconds.

  • IOS-XRv and HSRP: Supported?

    Hey gang -
    I'm building a virtual lab within a KVM hypervisor, and it includes 2 XRv images tied together across a VM switch image (Arista vEOS, but that's unimportant).  The L2 connectivity is clearly there between the two routers:
    RP/0/0/CPU0:r2#show cdp neighbors gigabitEthernet 0/0/0/6
    Fri Apr 17 10:49:07.505 UTC
    Capability Codes: R - Router, T - Trans Bridge, B - Source Route Bridge
                      S - Switch, H - Host, I - IGMP, r - Repeater
    Device ID       Local Intrfce    Holdtme Capability Platform  Port ID
    r1                    Gi0/0/0/6        149     R          IOS XRv S Gi0/0/0/6
    And HSRP is able to sync up appropriately between the two of them:
    RP/0/0/CPU0:r2#show hsrp br
    Fri Apr 17 10:46:32.806 UTC
    IPv4 Groups:
                            P indicates configured to preempt.
                            |
    Interface      Grp  Pri P State   Active addr     Standby addr   Group addr
    Gi0/0/0/6         1 100 P Standby 172.17.0.242    local          172.17.0.241
    IPv6 Groups:
    However, r2 (the secondary) can't ping the HSRP IP at all.  It can ping the buddy router's IP address, but not the HSRP one:
    RP/0/0/CPU0:r2#ping 172.17.0.242
    Fri Apr 17 10:51:30.635 UTC
    Type escape sequence to abort.
    Sending 5, 100-byte ICMP Echos to 172.17.0.242, timeout is 2 seconds:
    Success rate is 100 percent (5/5), round-trip min/avg/max = 9/17/19 ms
    RP/0/0/CPU0:r2#ping 172.17.0.241
    Fri Apr 17 10:51:32.595 UTC
    Type escape sequence to abort.
    Sending 5, 100-byte ICMP Echos to 172.17.0.241, timeout is 2 seconds:
    Success rate is 0 percent (0/5)
    The primary router can ping the HSRP IP though:
    RP/0/0/CPU0:r1#ping 172.17.0.241
    Fri Apr 17 11:32:32.679 UTC
    Type escape sequence to abort.
    Sending 5, 100-byte ICMP Echos to 172.17.0.241, timeout is 2 seconds:
    Success rate is 100 percent (5/5), round-trip min/avg/max = 1/1/1 ms
    Further, the switch VM that the two XRv routers are connected to can ping both of their IPs on Gig0/0/0/6, but can't ping the HSRP IP:
    #ping 172.17.0.242
    PING 172.17.0.242 (172.17.0.242) 72(100) bytes of data.
    80 bytes from 172.17.0.242: icmp_req=1 ttl=255 time=17.0 ms
    80 bytes from 172.17.0.242: icmp_req=2 ttl=255 time=19.0 ms
    80 bytes from 172.17.0.242: icmp_req=3 ttl=255 time=21.8 ms
    80 bytes from 172.17.0.242: icmp_req=4 ttl=255 time=22.6 ms
    80 bytes from 172.17.0.242: icmp_req=5 ttl=255 time=23.3 ms
    --- 172.17.0.242 ping statistics ---
    5 packets transmitted, 5 received, 0% packet loss, time 71ms
    rtt min/avg/max/mdev = 17.024/20.790/23.366/2.406 ms, pipe 2, ipg/ewma 17.794/19.066 ms
    #ping 172.17.0.243
    PING 172.17.0.243 (172.17.0.243) 72(100) bytes of data.
    80 bytes from 172.17.0.243: icmp_req=1 ttl=255 time=17.2 ms
    80 bytes from 172.17.0.243: icmp_req=2 ttl=255 time=19.4 ms
    80 bytes from 172.17.0.243: icmp_req=3 ttl=255 time=21.4 ms
    80 bytes from 172.17.0.243: icmp_req=4 ttl=255 time=22.1 ms
    80 bytes from 172.17.0.243: icmp_req=5 ttl=255 time=23.1 ms
    --- 172.17.0.243 ping statistics ---
    5 packets transmitted, 5 received, 0% packet loss, time 71ms
    rtt min/avg/max/mdev = 17.266/20.684/23.157/2.100 ms, pipe 2, ipg/ewma 17.758/19.114 ms
    fn1.vpn#ping 172.17.0.241
    PING 172.17.0.241 (172.17.0.241) 72(100) bytes of data.
    --- 172.17.0.241 ping statistics ---
    5 packets transmitted, 0 received, 100% packet loss, time 4008ms
    (Pay no mind to the horrendous latency; it's due to the way Arista wrote the VM).
    So after all of that: should I expect HSRP to be fully supported with XRv?  Or, like the L2 interfaces that are fully configurable, is it something that isn't supported?  Did I, perhaps, forget to enable some bit within the XRv's config?
    Thanks!

    In order to get redundancy to run between two SLB switches, you need to configure HSRP between the two VLAN interfaces and then associate the standby name with the Cisco IOS SLB Virtual Server (Vserver). When using IOS SLB in an HSRP environment ensure that the active HSRP router (also active for IOS SLB) is receiving the return traffic for the IOS SLB connections.

  • IOS SLB RADIUS loadbalancing

    Hi Guys,
    can anyone confirm or point out errors in this config that I wish to pop on our 6509. We don't have a test environment, so I need to get as much feedback as I can on this.
    Thanks in advance,
    James
    no natpool WSB_RADIUS 10.176.57.115 10.176.57.115 netmask 255.255.255.128
    no serverfarm WSB_RADIUS
    no serverfarm WSB_RADIUS_NAT
    no policy WSB_RADIUS_NAT
    no vserver WSB_RADIUS
    no probe WSB_RADIUS_AUTH udp
    ip slb serverfarm WSB_RADIUS
    nat server
    real 10.176.57.38
    faildetect numconns 8 numclients 1
    inservice
    real 10.176.57.39
    faildetect numconns 8 numclients 1
    inservice
    real 10.176.57.40
    faildetect numconns 8 numclients 1
    inservice
    real 10.176.57.41
    faildetect numconns 8 numclients 1
    inservice
    ip slb vserver WSB_RADIUS
    virtual 10.176.57.115 udp 1813 service radius
    serverfarm WSB_RADIUS
    idle radius request 2
    inservice standby WSB
    interface Vlan130
    standby 130 name WSB

    IOS SLB provides RADIUS load-balancing capabilities for RADIUS servers. In addition, IOS SLB can load-balance devices that proxy the RADIUS Authorization and Accounting flows in both traditional and mobile wireless networks, if desired. IOS SLB does this by correlating data flows to the same proxy that processed the RADIUS for that subscriber flow.
    http://www.cisco.com/en/US/products/sw/iosswrel/ps1833/products_feature_guide09186a00802081ce.html#wp2889077

Maybe you are looking for

  • Dual boot with lion and mavericks?

    Hi Guys, I want to updgrade to mavericks as well as keeping lion to run my old soundcard { no new drivers will be made } so, I'm thinking of using my external hard drive to try and install mavericks onto and Dual boot my MBP. is this possible? Cheers

  • Assigning more than one G/L accounts to WRX

    Hi! I want to assign more than one G/L accounts to WRX, I knew that it can be done through general modification. I have defined like below: Valuation           General                   G/L accounts Modification        Modification IN     I01     240

  • I cracked my ipad screen

    Does anyone know the cost to replace the cracked screen of an iPad?  Is this even possible to do without having to purchase an entirely new iPad? Spirit70

  • Rounded Buttons and Flat Menus [SOLVED]

    This is probably something easily dealt with which I haven't managed to find on the forums, but I am using LXDE and was wondering how one gets a desktop with square  pointed buttons as in http://www.symsysit.com/images/linuxrev - -busy1.jpg to one wi

  • Is it legal to replace the OEM Windows system?

    Hi guru, Let's say, my company bought a computer, which is pre-installed a Windows, for example, Windows 8.1, can I replace the Windows 8.1 with a Windows 7 (I downloaded a Windows 7 ISO from internet). Q1. Can I use the OEM key to activate the Windo