Restarting a single ACE context

We have an ACE with a number of contexts configured to allow access from our firewalls. One of the contexts seems to be having issues so is it possible to to just restart this one rather than reload the box?

Good morning,
This is unfortunately not possible.
To do a graceful reboot, you will first have to failover all the other contexts to the secondary ACE and then reboot the blade.

Similar Messages

  • Restart of an ACE context

    Is it possible to restart an individual context ? Let me explain in which case I need it :
    If, by mistake, I forgot to copy crypto files (key and cert) to the standby ACE, the standby ACE is in STANDBY_COLD state. Once the two file are copied on the standby machine, I have to reload it in order to achieve the STANDBY_HOT state. It would be nice to be able to restart only the specific context.
    It is possible ?
    Thank you
    Yves Haemmerli

    There is not a way to restart an individual context.
    You can try to to remove/add the keys certs on both ACEs and then go into
    that context and do a "no ft auto-sync running-config" and then "ft
    auto-sync running-config".
    Syed Iftekhar Ahmed

  • Sharing VLAN's on ACE context's

    I am quite a newbie with ACE configurations. I have a VLAN i want to share over three ACE context's. Every context needs to have its own vlan ip address. How can i manage to do this ? I can only define an ip address on the main ACE configuration.

    You are probably talking about the transfer-network or client-side VLAN.
    If you have already assigned the vlan to the module from the cat6k just create the three contexts and assigned those vlans to each context. That is how i do it. Serve three different context's with three different server networks with one client-side or transfer-network.
    just make sure you use different ip's for the ip,peer ip and alias for each context if you use FT or 2 modules. With this setup i always need 4 IP's including the VIP per context on the client side.
    Then you can configure the shared vlan in each context separate.
    context A
    allocate-interface vlan 10
    allocate-interface vlan 20
    context B
    allocate-interface vlan 10
    allocate-interface vlan 30
    context C
    allocate-interface vlan 10
    allocate-interface vlan 40

  • Process for placing files in an ACE context in both devices

    I want to add a crypto file to both ACE web contexts, I have a FT group configured for this context.
    I know I have to stop or shut down the FT group in order to write to the Web context on the secondary ACE.
    What I have been doing is taking the FT group out of service on the primary ACE, writing the files to both contexts and then putting the FT group back in service. My concern is when this FT group comes back on line that some of the configuration of the secondary ACE might get written to the primary.
    What is the best practice to do this?

    Hi Robert,
    Just copy the crytpo files to the device which is missing those files and once files are copied and matched, go to ACTIVE device and do this:
    config# no ft auto-sync running-conifg
    config# ft auto-sync running-config.
    Do the same for startup-config as well and everything should be fine.  There should be no configuration copied from secondary to primary since SYNC always happens from ACTIVE to standby. You don't need to do no inservice and inservice on FT group. Also, you can run the above command from specific contexts or from Admin context(will do bulk sync for all contexts).
    Let me know if you have any questions.
    NOTE: Please mark answers if they helped.

  • Restarts in single user mode since install

    I've only seen this problem on one of my computers. Since installing SL (from family disk), when restarting or starting from full shut down, the MBAir starts in Single User mode with command lines. I actually think it showed the GUI for about 2 seconds then goes into the command line text. Shows a bunch of the usual stuff about MAC framework initiations and lines about kernel dependency. I don't see any error lines repeated (but I do not understand much of the code) and it does not offer me a prompt. After about 1 minute, it launches the OS X gui and everything else is fine.
    I updated the 10.6.1 - same problem persists.
    So far I've verified, repaired some permission, PRAM, and tech tools basic. Do I need to do some deeper investigating? Any ideas?

    bluecool wrote:
    Will do. Do you mean re-choose the start up disk from the sys pref? Why might it search for another start up disk?
    resetting PRAM clears the startup disk settings.

  • restart when work with context menu

    After upgrade from Mac OS X 10.6.8 to Mac OS X 10.8.2 work with crashes.
    When I try use context menu (for example Git Info on File or Folder) restart every time.
    Process:         Finder [439]
    Path:            /System/Library/CoreServices/
    Version:         10.8.1 (10.8.1)
    Build Info:      Finder_FE-808001006000000~2
    Code Type:       X86-64 (Native)
    Parent Process:  launchd [304]
    User ID:         502
    Date/Time:       2013-01-07 03:51:54.679 +0400
    OS Version:      Mac OS X 10.8.2 (12C60)
    Report Version:  10
    Crashed Thread:  0  Dispatch queue:
    Exception Type:  EXC_CRASH (Code Signature Invalid)
    Exception Codes: 0x0000000000000000, 0x0000000000000000
    Application Specific Information:
    Performing @selector(cmdShowStaticInfo:) from sender TContextMenuItem 0x7f9911b4b540
    Thread 0 Crashed:: Dispatch queue:
    0                    0x000000010c553121 0x10c4b9000 + 631073
    1                    0x000000010c5b60a6 0x10c4b9000 + 1036454
    2                    0x000000010c5b5fe2 0x10c4b9000 + 1036258
    3                    0x000000010c5afbc8 0x10c4b9000 + 1010632
    4                    0x000000010c5ae500 0x10c4b9000 + 1004800
    5                    0x000000010c5adc16 0x10c4b9000 + 1002518
    6                    0x000000010c5adae2 0x10c4b9000 + 1002210
    7                    0x000000010c50d9f4 0x10c4b9000 + 346612
    8                    0x00007fff90b80a59 -[NSApplication sendAction:to:from:] + 342
    9                    0x00007fff90cb644c -[NSMenuItem _corePerformAction] + 406
    10                    0x00007fff90cb613a -[NSCarbonMenuImpl performActionWithHighlightingForItemAtIndex:] + 133
    11                    0x00007fff909a346f -[NSMenu _internalPerformActionForItemAtIndex:] + 36
    12                    0x00007fff909a32f7 -[NSCarbonMenuImpl _carbonCommandProcessEvent:handlerCallRef:] + 135
    13                    0x00007fff90caf245 NSSLMMenuEventHandler + 342
    14                 0x00007fff9a646f0a DispatchEventToHandlers(EventTargetRec*, OpaqueEventRef*, HandlerCallRec*) + 1206
    15                 0x00007fff9a6463d9 SendEventToEventTargetInternal(OpaqueEventRef*, OpaqueEventTargetRef*, HandlerCallRec*) + 410
    16                 0x00007fff9a65c1bd SendEventToEventTarget + 40
    17                 0x00007fff9a692e89 SendHICommandEvent(unsigned int, HICommand const*, unsigned int, unsigned int, unsigned char, void const*, OpaqueEventTargetRef*, OpaqueEventTargetRef*, OpaqueEventRef**) + 443
    18                 0x00007fff9a637c11 SendMenuCommandWithContextAndModifiers + 59
    19                 0x00007fff9a637bc3 SendMenuItemSelectedEvent + 254
    20                 0x00007fff9a637a4f FinishMenuSelection(SelectionData*, MenuResult*, MenuResult*) + 94
    21                 0x00007fff9a7ae009 PopUpMenuSelectCore(MenuData*, Point, double, Point, unsigned short, unsigned int, Rect const*, unsigned short, unsigned int, Rect const*, Rect const*, __CFString const*, OpaqueMenuRef**, unsigned short*) + 1673
    22                 0x00007fff9a7ad924 _HandlePopUpMenuSelection7 + 629
    23                    0x00007fff90d3261b _NSSLMPopUpCarbonMenu3 + 3916
    24                    0x00007fff90d316a8 -[NSCarbonMenuImpl _popUpContextMenu:withEvent:forView:withFont:] + 189
    25                    0x00007fff90e8c063 -[NSMenu _popUpContextMenu:withEvent:forView:withFont:] + 200
    26                    0x000000010c6ca616 0x10c4b9000 + 2168342
    27                    0x000000010c6c8498 0x10c4b9000 + 2159768
    28                    0x000000010c72c054 0x10c4b9000 + 2568276
    29                    0x000000010c726dc5 0x10c4b9000 + 2547141
    30                    0x00007fff90b75c81 -[NSWindow sendEvent:] + 8504
    31                    0x00007fff90b71744 -[NSApplication sendEvent:] + 5761
    32                    0x000000010c64db71 0x10c4b9000 + 1657713
    33                    0x00007fff90a872fa -[NSApplication run] + 636
    34                    0x00007fff90a2bcb6 NSApplicationMain + 869
    35                    0x000000010c4beb46 0x10c4b9000 + 23366
    36  libdyld.dylib                       0x00007fff988ea7e1 start + 1

    I solve problem - CMD + R -> Reinstall Mac OS X (but reason of crashes not found)

  • Simple question - ACE Context Running Config

    How do I erase the running config of a context ? wr erase only gets rid of the the start up. I can go through it with no commands but was hoping there is a better way.

    If you could reload per context erasing the startup config would work. Unfortunately you can only reload the whole ace blade.
    Fastest way to get rid of a config within a context is to delete the context in the admin context and then re-create it.
    changeto Admin
    conf t
    no context
    If you had checkpoints already created those are gone as well once you issue the "no context " command.
    To make it easier in the future i would suggest you create an empty checkpoint at the very beginning or at the point of your configuration where you want to start to experiment with the settings.
    conf t
    checkpoint create
    checkpoint create
    To get the settings back u issue.
    conf t
    checkpoint rollback
    The checkpoints are per context btw.
    Hope that helps.

  • ANM 2.0: one of three ACE contexts couldn't "sync to CLI"

    We are using ANM 2.0 Update A to manage an ACE module running A2(1.2). About a week ago, one of our 3 contexts started showing "Out of sync" in the "CLI sync status" column. I tried to sync the context numerous times; no errors were reported but this particular context was always "out of sync".
    Then this morning I tried a "sync to CLI" operation once more and this time it finally worked! The status is now "in sync".
    I was wondering why this happened, and if anything can be done to prevent it in the future.

    Synchronizing configuration files for the standby ACE requires:
    1. Auditing the standby ACE to confirm that its configuration does not agree with the ANM-maintained configuration data for the ACE. See Synchronizing Virtual Context Configurations, page 3-64.
    2. Uploading the configuration from the standby ACE to the ANM server. See Synchronizing Virtual Context Configurations in the below URL:
    3. For an Admin context, uploading configurations on any newly imported user contexts. If new user contexts are not updated, they cannot be managed using ANM.

  • ACE context management per user

    Dear All,
    Can per user get management access in per context on ACE module?
    For instance, user A can manage just context A, user B can manage just context B on attachment file.

    If you use an ACS for TACACS you can (for ACE you have to) set custom attributes for your group. The attributes look like this:
    shell:= ...
    If you want to restrict the user from changing into another context, you should change the Shell Command Authorization Set settings.

  • Throughput of an ACE context

    We're running an ACE SM with the 8GB throughput license. We also have 4 contexts on that ACE. Would the max througput per context be 8GB/4 = 2 GB or the 8GB would be drawn by different contexts depending on their requirements?
    Thanks  Greg...

    Thanks - that would make sense. Below is the sh resources usage taken on one of the contexts. We have 8Gbps license and 7 active contexts (including the Admin context). So, I would have expected to see the max bandwidth as 8G as opposed to 1G if that was indeed the max theoretical bandwidth...Any idea on this?   Thnx again...
    Resource                 Current       Peak            Min             Max    
    bandwidth                149720    210620645    1997500   1100527532          0
        throughput             144644   210602113    1997500    976777532          0
        mgmt-traffic rate        5076      18532          0             123750000          0

  • ACE Context - Error: Resources in use

    Hi All,
    I am trying to associate a resource to a newly created context to enable configuration of sticky sessions within the context. When I assigne the context to the Resource Member it comes back as errored Resources in Use. Any idea's how I can get this configured as my deadlines are tight (thanks to our web developers bringing forward a go-live date to Monday).
    The Key configurations are here:
    resource-class BRONZE
      limit-resource all minimum 0.01 maximum unlimited
      limit-resource sticky minimum 0.01 maximum unlimited
    resource-class GOLD
      limit-resource all minimum 5.00 maximum unlimited
      limit-resource sticky minimum 5.00 maximum unlimited
    resource-class RESERVE
      limit-resource all minimum 18.10 maximum equal-to-min
      limit-resource sticky minimum 18.11 maximum equal-to-min
    context ACCTX_SPT_FRN
      description SPT Context
      allocate-interface vlan 1204
      allocate-interface vlan 1310
      allocate-interface vlan 1410
    context ACCTX_SSM_FRN
      description SSM Context
      allocate-interface vlan 1213
      allocate-interface vlan 1313
      allocate-interface vlan 1413
      member GOLD
    context reserve
      member RESERVE
    Obviously not all contexts shown - there are 14 in Total - 1 reserve, 2 Bronze, 9 Gold and 2 unassigned (of which 1 needs to be Gold).
    I saw in previous posts the resource usage was key to identifying where issue could be. As I am learning this beast, I couldn't fully make sense of the previous posts so apologies for this:
            Resource         Current       Peak        Min        Max     Denied
    Context: Summary
      conc-connections         115391     217571    3601600   65976000          0
      mgmt-connections             69        326       2250      41250          0
      proxy-connections         27736      49687     472060    8647590          0
      xlates                        0          0     472060    8647590          0
      bandwidth              15037110 1503203965  450200000 3952032704       3915
      connection rate              76      11281     450200    8247000          0
      ssl-connections rate         10       1495       6754     123720          0
      mgmt-traffic rate           618     277886   56275000 1030875000          0
      mac-miss rate                 0        868        900      16500     100033
      inspect-conn rate             0          0       2700      49470          0
      acl-memory               102912     109392    3930522   43220012          0
      regexp                      104        104      52429     576507          0
      syslog buffer           4194304    4196352     209715    2306028          0
      syslog rate                   4        923        150       1649          0
    Help is very much appreciated. There are no reported issues with current loads so the Denieds I take as a misnomer.

    From my first idea I would think you use more then 100% of your sticky resource. maybe you should provide the whole context config.

  • ACE - context administration

    I've created two contexts, allocated administrative vlan to each context, in each context created management class map and policy map (allow all icmp,ssh) and binded it to this vlan. I can ping each context but i can not telnet to port 22 (ssh not listening).
    I've done the same in Admin context and i can login using ssh. Why another contexts do not have sshd listening ?

    I've found that in new wersion i do not have "ssh" command under context-config:
    host1/Admin(config-context)# ssh key rsa1 1024
    but anyway i tried to login and had to wait about 5 minutes - then context let me in.
    it seems that context drugging first ssh login (first TCP SYN on port 22) generates appriopriate keys ? (and it can not be done by any command anymore)?

  • Restart a single application

    I would like to find a way to restart just one of the
    applications that I have running on my server with out having to
    restart coldfusion. Restarting coldfusion would restart all of the
    application running.

    insuractive wrote:
    > Can't you also call the onApplicationStart() function
    from a regular coldfusion
    > page? I remember reading in the docs about being able to
    call the
    > onSessionStart() function, but it didn't mention
    anything about the
    > onApplicationStart() function.
    Yes you can, the only caveat is to be careful how the
    function is
    written. When it is called automatically during the start of
    application all application variables are appropriately
    locked. If
    called at any other time the automatic locking does not
    occur. So be
    aware of potential race conditions and code appropriately.

  • ACE 4710 eHealth monitoring of context

    Our eHeath people tell me they cannot stat anything in any of the contexts (excluding Admin) on the ACE, i can snmpwalk the various contexts using the '@context' suffix.
    e.g. snmpwalk -c community@context2 .
    eHealth can only route to the Admin context.
    Does anybody know if eHealth can access the ACE contexts in this fashion?

    Here is the expected operation for each of those cases:
    A real server.
    If the server is not associated with any serverfarm, the status will not be probed (the rserver will be marked as INACTIVE)
    A real server and then associate the real server with a  server farm. You can associate a single probe or multiple probes with  real servers within a server farm.
    The probe will only be applied to that specific server
    A server farm. All servers in the server farm receive probes of the associated probe types.
    The probe will be applied to all the servers in the serverfarm.
    Another thing to take into account is that (by default) if more than one probe is associated to a server (either directly or through a serverfarm), all the probes need to succeed to consider the server operational. You can also add the command "fail on all" to a serverfarm or rserver to change this behavior and only consider the server as down when all the probe fail
    I hope this answers your question

  • ACE bridge and routed interface in the same context

    /* Style Definitions */
    mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
    font-family:"Times New Roman";
    I am wondering if it is possible to configure one ACE context to support both routed and bridge interface?
    I would like to have a bridge-mode context but in the same time I would like to have a separated OOB interface for management.
    If it is possible how they could interact to each other?
    Thank you in advance for any answer

    /* Style Definitions */
    mso-padding-alt:0cm 5.4pt 0cm 5.4pt;
    font-family:"Times New Roman";
    We've just tried to configure bridged and routed interfaces at the same time in the lab and we've had a problem.
    When we added the def gw for the bridged config we noticed that we had an issue with the traffic src by the rservers in the routed config.
    When we deleted the new def gw, the problem disappeared.
    I am attaching the lab config.
    When we added to it the following line
    ip route
    reals B1-B10 could not communicate to the outside world.
    Do you know why it does not worked and what could we do to fix it ?
    Thank you in advance.

Maybe you are looking for

  • Possible to add sub-pages ?

    Hello, I began to create a site in iWeb. For presentation and organisation issues, I would like to add subpages to it -i.e. to have pages links that shows only on a certain page and not the navigation menu) Example: On the site there is a page of pic

  • Mi iphone 6 plus no quiere descargar aplicaciones

    Todo estaba perfecto un dia decidi sincronizarlo a la computadora y ahi empezaron los problemas. Primero no quería descargar aplicaciones, se queda moviendose el circulo como si estubiera tratando de cargar pero nunca me pide la huella o el password

  • 7.2 delay compensation

    Have 7.2 delay compensation in TDM?

  • FIxing "nag" authentication request with Adobe

    Hi all, I have a user who keeps receiving an admin password authentication request whenever she tries to open Acrobat, Reader, or CS4. I've run permissions repair from Disk Utility, and I've used my admin logon to clear the screen once. It seems to g

  • Help! Flash on Firefox Not Working!

    All was fine with flash player on firefox, then all of a sudden I started to get messages that flash player was not installed - that I needed to add the plug in and when I would click on the prompt, it would say I had to do it manually. I did it manu