Transparent pix between 2 vrf
hi guys,
This is the problem : I need to receive from a GigaEth both some multicast streams and a unicast control traffic to be filtered. So, on a 3750 there is a trunk vs data provider, and Interface Vlan X for mcast and Vlan Y for outside unicast in global space. Than a Vlan Z in a separate vrf for inside. Pix is connected on L2 port Vlan X for outside and on L2 port Vlan Z for inside. It doesn't run !!! It seems to be unable to resolve arp ...
The actual 3750, will become in a short time a 650x sup 720B, but I am not sure if we have a better results.
Any advice ?
Thanks
Maurizio
To make this happen a FWSM module has to be installed in the Catalyst 6500 series switch. The FWSM features has the following features
Layer 2 Firewall (transparent mode)
Layer 3 Firewall (route and/or NAT mode)
Mixed Layer 2 and Layer 3 firewall per FWSM
Dynamic/static NAT and PAT
Policy-based NAT
VRF-aware NAT
Destination NAT for Multicast
Static routing support in single- and multiple security context mode
Dynamic routing in single security context mode: Open Shortest Path First (OSPF), Routing Initiation Protocol (RIP) v1 and v2, PIM Sparse Mode v2 multicast routing, Internet Group Management Protocol (IGMP) v2
Transparent mode supports static routing only
Private VLAN
Asymmetric routing supporting without redundancy by using asymmetric routing groups
IPv6 networking and management access using IPv6 HTTPS, Secure Shell Protocol (SSH) v1 and v2, and Telnet
Similar Messages
-
How do I share all my pix between my devices?
How do I share my pix between
Devices,desktop PC,Verizon cell phone?iOS and iPod: Syncing photos using iTunes
http://support.apple.com/kb/HT4236
Copy Photos (& Videos) Between iOS Devices
http://tinyurl.com/cnz95bc
Cheers, Tom -
Transparent Partition Between ASO & BSO
Hi,
I am trying to define a Transparent Partition between an ASO (Source) & a BSO (Target) cube.
My ASO cube has 16 dimensions, BSO has 12 dimensions. The matching 12 dimensions are identical.
The data from the source should be taken from all levels of the 12 matching dimensions and Highest level data of the non matching dimensions.
Is this doable?
Is there any special syntax in partitions definitions?
Appreciate your thoughts.
Thanks,
Ethan.Glenn,
Thanks. It's working. I created the partition manually, kept void for all the 4 missing dimensions.
When I have to write the script, I am not sure how to specify that in the script
mapped targetAreaA ("Dim1") to (Void)
mapped targetAreaA ("Dim2") to (Void)
mapped targetAreaA ("Dim3") to (Void)
mapped targetAreaA ("Dim4") to (Void);
or
mapped targetAreaA ("Dim1", "Dim2", "Dim3", "Dim4") to (Void, Void, Void, Void)
Are these correct syntaxes?
Appreciate your thoughts.
Thanks,
Ethan. -
Hi Guys,
I had to re-post this here because I did not get any comments earlier.. hopefully I'll get something here.. :)
I'm investigating the ways that I can use 2 x ASA (5525x) to accommodate Multi-tenancy situation with overlapping addresses. Unfortunately in this particular scenario we have to stick with 5525x firewalls.
The ASAs are going to be placed in north-south traffic path between 2 routers and these routers need to be configured with multiple VRFs to segregate the traffic for each tenant with overlapping IP subnets ( We are not looking at NAT as a workaround for the time being).
As we know, this ASA model won't support VRFs so we can't use the ASA as a intermediary routing hop and therefore this is not an option.. and using security contexts per VRF seems not scale-able enough (correct me if I'm wrong). So my thinking is that, if we put the ASAs in to the transparent mode and just use the ASAs as a layer 2 interconnect (configured with different VLANs connecting VRFs served by top and bottom routers) I should be able to go up to maximum of 50 VRFs (since 5525x only supports 200 VLANs).
I'm also planning to use the 2 ASAs in a cluster mode to aggregate the bandwidth of both ASAs for better throughput.
So I need to clarify following with you guys..
1) Can I actually do this or am I missing something.
2) Are there any limitations that I might run in to with this setup
3) Is there anyone out there who's doing the same thing or can you think of a better way to tackle this scenario (with same hardware and requirements)
4) Instead of using clustering, can I use simple Active/Stanby pare and still configure transparent mode and use it that way ?
Appreciate your input.
Thanks
ShamalThere is a limitation on how many context you can have, which depends on the license you have. This is quite possible with ASA multi routed mode and even with multi transparent mode. You can have overlapping ip in each context without the need of using nat as long as you have unique mac address for each sub interface.
Thanks -
Redundant Transparant ASA between Redundant Routed Links
Aparently the Security/Compliance team didn't review my network design before it was submitted and built, and now I have to shoe horn a firewall somewhere there was never supposed to be one.
I have my two current DC Cores (Nexus 5548UP), that currently are Layer 3 only, with no L2 configuration at all. I understand these aren't the best switches for this role, but the BoM was put in place and gear ordered, long before I came onboard, and the DC design had been completed. From these two Cores, i connect directly to a vendor's clustered Fortinet FW, via a /30 from each core to each node of their cluster, and connected via eBGP, one link with a path prepend, due to the vendor not able to figure out how to load balance on their firewall. Due to numerous vendor problems, and lack of knowlege, I cannot get them to change their design in a timely manner, to meet our timelines, and this has to be up yesterday to be PCI compliant (so our security people say) prior to go live in 1 week. The vendor took 3 weeks just to figure out how to aggregate routes to me!.
So I want to drop a transparent pair of firewalls inline on the two links, but due to the Active/Standby limitation of ASA's, I am not sure this will be that easy given the /30 L3 interfaces being used. Secondly the lack of L2 between the two upstream cores may be a concern, at least from past expiriences. I know if I was using some other vendor's clustered FW, this wouldn't be a problem, but I definately don't want to join the Dark side again, or do I have time to procure any other equipment other than the 5520's I currently have laying around. Someone please tell me I have overlooked something simple, and the design listed below will be simple to implement!!!!
Any ideas appreciated!why you don't use this design:
connect the vendor clustered direct to nexus with a vrf instance, then route traffic to asa and then route to nexus whith other vrf istance.
Regards
V. -
Using Clustered ASAs in Transparent mode to support VRF based Network ?
Hi Guys,
I'm investigating the ways that I can use 2 x ASA (5525x) to accommodate Multi-tenancy situation with overlapping addresses. Unfortunately in this particular scenario we have to stick with 5525x firewalls.
The ASAs are going to be placed in north-south traffic path between 2 routers and these routers need to be configured with multiple VRFs to segregate the traffic for each tenant with overlapping IP subnets ( We are not looking at NAT as a workaround for the time being).
As we know, this ASA model won't support VRFs so we can't use the ASA as a intermediary routing hop and therefore this is not an option.. and using security contexts per VRF seems not scale-able enough (correct me if I'm wrong). So my thinking is that, if we put the ASAs in to the transparent mode and just use the ASAs as a layer 2 interconnect (configured with different VLANs connecting VRFs served by top and bottom routers) I should be able to go up to maximum of 50 VRFs (since 5525x only supports 200 VLANs).
I'm also planning to use the 2 ASAs in a cluster mode to aggregate the bandwidth of both ASAs for better throughput.
So I need to clarify following with you guys..
1) Can I actually do this or am I missing something.
2) Are there any limitations that I might run in to with this setup
3) Is there anyone out there who's doing the same thing or can you think of a better way to tackle this scenario (with same hardware and requirements)
4) Instead of using clustering, can I use simple Active/Stanby pare and still configure transparent mode and use it that way ?
Appreciate your input.
Thanks
ShamalIs any expert out there who can answer my query ?. Much appreciated.
-
Problem after moving pix between rolls
Let me say up front that I know I should be using albums to organize pix. And that's what I'll do from now onn. But I could use some suggestions for dealing with this.
Dragged and dropped some pix from one roll - call it Roll A - to another, Roll B. Since there were no pix left in A, I deleted it. In the Library view, the pix/thumbnails are in B. But when I double click to them to edit (or just to view them at full size), I get a grey box with a dotted outline around an exclamation mark. A Finder search for the file name shows files in the Original and Data directories of the Library but in subdirectories that bear the original name of Roll A.
I'd rather not mess with the Finder to move these files from Directory A to Directory B. Is there some other way I can correct this?Jim:
Since it sounds like you used the Finder to do your reorganization, it's iffy if a rebuild will succeed. But try it anyway and select ALL FOUR options. Maybe the orphaned option will bring in those you've moved.
If that doesn't work you're looking at starting over with a new library and importing the Originals folder from the old one. Here's how to proceed:
Creating a new library while preserving the rolls from the original.
Move the existing library folder to the desktop.
Launch iPhoto and, when asked, select the option to create a new library.
Drag the Originals folder from the iPhoto Library on the desktop into the open iPhoto window.
This will create a new library with the same rolls as the original library. However dates on the rolls may be different but can be edited as you would the roll title.
Once this is completed you can delete the iPhoto library folder from the desktop. If desired, you can keep the older library folder to try other fixes on it.
In the future I recommend you make a backup copy of the Library6.iPhoto file after each import and after doing a lot of editing and organizing in the library. Then if you experience a similar crash all you need to do is replace the damaged database file with the backup copy and you'll be back to the same place in the library as when you make the backup. See the tip at the end of my signature. Also you can move photos between rolls but it must be done within iPhoto, not the Finder.
Do you Twango?
TIP: For insurance against the iPhoto database corruption that many users have experienced I recommend making a backup copy of the Library6.iPhoto database file and keep it current. If problems crop up where iPhoto suddenly can't see any photos or thinks there are no photos in the library, replacing the working Library6.iPhoto file with the backup will often get the library back. By keeping it current I mean backup after each import and/or any serious editing or work on books, slideshows, calendars, cards, etc. That insures that if a problem pops up and you do need to replace the database file, you'll retain all those efforts. It doesn't take long to make the backup and it's good insurance.
I've written an Automator workflow application (requires Tiger), iPhoto dB File Backup, that will copy the selected Library6.iPhoto file from your iPhoto Library folder to the Pictures folder, replacing any previous version of it. You can download it at Toad's Cellar. Be sure to read the Read Me pdf file. -
Communication between multiple vrf context on fwsm
i have 2 vrf context on fwsm of 6509 switch. i want to reach from vrf context1 inside to vrf context inside. how can i do it?
vrf_context1_inside----6509_fwsm----vrf_context2_inside
vrf_context1_inside must reach to vrf_context2_insideThanks for the response.
FileLock. We still have to target JDK 1.3 so we can't use FileLocks (at this point)
JNI: That's an interesting idea. I suspect many people are using our software on Windows. Therefore, we could probably fix it in Windows the same as in the C++ code. If they're not on Windows, we could use the Sockets approach.
I also had another idea: how about hashing the username string into some integer (or long) value. Then use the hashed value to lock some other resource: like the port number passed to ServerSocket. I know ServerSocket only accepts 0 - 0xFFFF so this obviously won't work. But is there some other system-wide thing we could lock given an integral value? -
WLSM, FWSM in transparent mode, VRF's , EAPFAST and LEAP
Has anyone got any experience of all of the above.
Some background - The FWSM is in transparent mode, using virtual contexts between the VRF and the main routing table to ensure relevant mobility traffic passes through the relevant security context.
I can authenticate with LEAP via RADIUS, then obtain an IP through DHCP, ping my gateway from wireless client but not outside my VRF. If I remove the VRF from the tunnel interface associated with my mobility group all connectivity OK.
With EAPFAST I can authenticate via RADIUS, but do not get an address through DHCP. If I use a static ( and use mobility trust on tunnel interface )I can not ping my gateway. If I remove the VRF off the tunnel interface associated with this type of users mobility group, I receive an address through DHCP, and can ping merrily everywhere.
Has anybody got any thoughts if I am missing something here?The software requirements for Cisco Secure ACS are dependent on the type of Extensible Authentication Protocol (EAP) desired. For full support of all the EAP types including EAP-Flexible Authentication via Secure Tunneling (FAST), use release 3.2.3 or higher.
http://www.cisco.com/en/US/netsol/ns340/ns394/ns431/ns434/networking_solutions_implementation_guide09186a008038906c.html -
Hi to all, i'm trying to configure nat between vrf.I have a network with multiple vrf and a common vrf where there are some service shared among them.
I've ip overlapping issue, so i'm trying to use nat aware vrf.
The shared service is on a vrf also.
I use route-target import and export to import route between vrf.I've seen nat is working between VRF and global routing, but not between different VRF that already are able to comunicate.
This is my configuration :
ip vrf proxy
rd 500:500
route-target export 500:500
route-target export 501:501
route-target import 500:500
route-target import 401:401
ip vrf upa
rd 300:300
route-target export 300:300
route-target export 401:401
route-target import 300:300
route-target import 501:501
ip vrf upa-tv
rd 1000:1000
route-target export 1000:1000
route-target export 401:401
route-target import 1000:1000
route-target import 501:501
mpls label protocol ldp
interface GigabitEthernet0/0
no ip address
duplex auto
speed auto
interface GigabitEthernet0/0.1
description interfacccia outside per ip pubblico ipsec
encapsulation dot1Q 500
ip address 195.195.195.195 255.255.255.0
interface GigabitEthernet0/0.10
encapsulation dot1Q 300
ip vrf forwarding upa
ip address 172.31.47.254 255.255.255.0
ip nat enable
interface GigabitEthernet0/0.20
encapsulation dot1Q 310
ip vrf forwarding proxy
ip address 172.31.50.1 255.255.255.0
interface GigabitEthernet0/0.10
encapsulation dot1Q 320
ip vrf forwarding upa-tv
ip address 10.4.1.254 255.255.255.0
interface GigabitEthernet0/1
description connessa a 6500
ip address 80.x.x.1 255.255.255.0
duplex auto
speed auto
mpls ip
router bgp 65000
no synchronization
bgp log-neighbor-changes
neighbor 80.80.80.2 remote-as 65000
no auto-summary
address-family vpnv4
neighbor 80.80.80.2 activate
neighbor 80.80.80.2 send-community both
exit-address-family
address-family ipv4 vrf upa-tv
no synchronization
exit-address-family
address-family ipv4 vrf upa
redistribute connected
no synchronization
exit-address-family
address-family ipv4 vrf proxy
redistribute connected
no synchronization
exit-address-family
ip route vrf proxy 169.254.99.12 255.255.255.255 GigabitEthernet0/0.10 172.31.47.254
ip route vrf upa 10.4.1.0 255.255.255.0 172.31.47.1
ip nat inside source static 10.4.1.12 169.254.99.12 vrf upa
as you can see i export route from vrf upa and upa-tv as RT 401:401 ,and import it in proxy vrf, and in the same way i export route from proxy vrf as RT 501:501 and import it into upa and upa-tv.
network 10.4.1.0/24 exist in both vrf upa and upa-tv.So i 'd like to nat one of them with another ip address (i tried to use a static translation to be able to reach the same ip address in both vrf). I make some test, and it seems to work when i make a nat from vrf to global, but not work when nat is between vrf (is this supported ?).I tried with NVI and with classic nat command:
interface GigabitEthernet0/0.10
encapsulation dot1Q 300
ip vrf forwarding upa
ip address 172.31.47.254 255.255.255.0
ip nat inside
interface GigabitEthernet0/0.20
encapsulation dot1Q 310
ip vrf forwarding proxy
ip address 172.31.50.1 255.255.255.0
ip nat outside
ip nat inside source static 10.4.1.12 169.254.99.12 vrf proxy
tried also with
ip nat inside source static 10.4.1.12 169.254.99.12 vrf upa
but it didn't work...
any suggestion ?
any help will be appreciated
MaxHi Mohammed, now all works well.
I understand my error, basically when i tried to ping, i pinged a router on my
own vrf, because i imported the network, so the packet didn't came across
interfaces and nat was not in place.Now i tried static host and network
natting and dymanic natting and all works well.
here there is a complete working configuration
ip vrf proxy
rd 500:500
route-target export 500:500
route-target export 501:501
route-target import 500:500
route-target import 401:401
ip vrf upa
rd 300:300
route-target export 300:300
route-target export 401:401
route-target import 300:300
route-target import 501:501
ip vrf upa-tv
rd 1000:1000
route-target export 1000:1000
route-target export 401:401
route-target import 1000:1000
route-target import 501:501
mpls label protocol ldp
interface GigabitEthernet0/0
no ip address
duplex auto
speed auto
interface GigabitEthernet0/0.1
description interfacccia outside per ip pubblico ipsec
encapsulation dot1Q 500
ip address 195.195.195.195 255.255.255.0
interface GigabitEthernet0/0.10
encapsulation dot1Q 300
ip vrf forwarding upa
ip address 172.31.47.254 255.255.255.0
ip nat inside
interface GigabitEthernet0/0.20
encapsulation dot1Q 310
ip vrf forwarding proxy
ip nat outside
ip address 172.31.50.1 255.255.255.0
interface GigabitEthernet0/0.10
encapsulation dot1Q 320
ip vrf forwarding upa-tv
ip address 10.4.1.254 255.255.255.0
interface GigabitEthernet0/1
description connessa a 6500
ip address 80.x.x.1 255.255.255.0
duplex auto
speed auto
mpls ip
router bgp 65000
no synchronization
bgp log-neighbor-changes
neighbor 80.80.80.2 remote-as 65000
no auto-summary
address-family vpnv4
neighbor 80.80.80.2 activate
neighbor 80.80.80.2 send-community both
exit-address-family
address-family ipv4 vrf upa-tv
no synchronization
exit-address-family
address-family ipv4 vrf upa
redistribute connected
no synchronization
exit-address-family
address-family ipv4 vrf proxy
redistribute connected
no synchronization
exit-address-family
ip route vrf proxy 169.254.99.12 255.255.255.255 GigabitEthernet0/0.10 172.31.47.254
ip route vrf upa 10.4.1.0 255.255.255.0 172.31.47.1
ip nat inside source static 10.4.1.12 169.254.99.12 vrf upa
Many thanks for the help, now all works well and i understand the way to
configure it. -
Howto control/filter traffic between VRF-(lite) using route leaking?
Hi,
does anybody know how I can control/filter the traffic between two vrf when I use route leaking or also normal route target export/import connections, maybe with an acl, in the following scenarios?
Scenario 1:
I use a normal MPLS network with several PE routers (maybe ASR series) which connect to the CE routers via OSPF. Two VPNs are configured on the PE routers and I want one of PE routers to allow/route traffic between these VPNs but especially traffic on tcp port 80 and no other ports. I'm only aware of bindung acls to logical or physical interfaces but I don't know how to do this here.
Scenario 2:
Same as scenario 1 but not the PE router will connect the VPN but a separate router-on-a -tick (e.g. 4900M) which is connected to one of the PE routers should do this job with vrf-lite and route leaking (address-family ipv4 vrf ...). Also here I want only to allow tcp port 80 between the vpns
Kind Regards,
ThorstenThanks.
That's what I was assuming. In my experience this solution does not scale with increasing number of vpn and inter vpn traffic via route target.
Is it correct that there is only one common acl per vpn where all rules for the communication to all other vpns are configured? Doesn't this acl become too complex and too error-prone to administrate in a real network environment? Further on in my understanding this acl has to be configured per vpn on all pe routers which have interfaces to ce routers for that vpn.
Does cisco offer software for managing this? -
CISCO ASR901 BRIDGE BETWEEN 2 INTERFACES
Hi All!
I'm looking for some way to make a transparent bridge between two interfaces of a Cisco router ASR901 , is there any possibility? I ask this because I have a scenario where I would use the ASR901 to the following question :
POP01 ( ) ASR901 g0 / 6 -------- > ISG_7206
POP02 ( MPLS CLOUD ) g0 / 7 -------- > ISG_7206
POP03 ( )
The ASR901 will focus EoMPLS with other points in the network and pass on to ISG routers , ie , VLANs would have to be two ports with XConnect to a remote router , the configuration would be something like this :
interface GigabitEthernet0/6
Core description : MPLS CONC PPPOE02
no ip address
negotiation auto
hold- queue 1024 in
hold- queue 1024 in October
service instance 4095 ethernet
encapsulation dot1q 4094
rewrite ingress tag pop 1 symmetric
interface GigabitEthernet0/7
Core description : 7206_PPPOE_01
no ip address
negotiation auto
service instance 4095 ethernet
encapsulation dot1q 4094
rewrite ingress tag pop 1 symmetric
end
L2VPN XConnect context TEST
ethernet interworking
member 201.55.127.202 1212 encapsulation mpls group TEST
member GigabitEthernet0 / 7 service -instance TEST 4095 group priority 1
member GigabitEthernet0 / 6 service -instance 4095
redundancy group delay 1 3 TEST
But without an interface that was redundant of other , what I need is the 2 interfaces in " bridge " making a XConnect to a remote router , and these 2 interfaces connected ISGs in 2 to make a balance .Hi,
This discussion is for IOS-XR related questions. You should post your question under Service Provider > MPLS.
thanks,
rivalino -
CISCO ASR901 BRIDGE BETWEEN 2 INTERFACES WITH XCONNECT
Hi All!
I'm looking for some way to make a transparent bridge between two interfaces of a Cisco router ASR901 , is there any possibility? I ask this because I have a scenario where I would use the ASR901 to the following question :
POP01 ( ) ASR901 g0 / 6 -------- > ISG_7206
POP02 ( MPLS CLOUD ) g0 / 7 -------- > ISG_7206
POP03 ( )
The ASR901 will focus EoMPLS with other points in the network and pass on to ISG routers , ie , VLANs would have to be two ports with XConnect to a remote router , the configuration would be something like this :
interface GigabitEthernet0/6
Core description : MPLS CONC PPPOE02
no ip address
negotiation auto
hold- queue 1024 in
hold- queue 1024 in October
service instance 4095 ethernet
encapsulation dot1q 4094
rewrite ingress tag pop 1 symmetric
interface GigabitEthernet0/7
Core description : 7206_PPPOE_01
no ip address
negotiation auto
service instance 4095 ethernet
encapsulation dot1q 4094
rewrite ingress tag pop 1 symmetric
end
L2VPN XConnect context TEST
ethernet interworking
member 201.55.127.202 1212 encapsulation mpls group TEST
member GigabitEthernet0 / 7 service -instance TEST 4095 group priority 1
member GigabitEthernet0 / 6 service -instance 4095
redundancy group delay 1 3 TEST
But without an interface that was redundant of other , what I need is the 2 interfaces in " bridge " making a XConnect to a remote router , and these 2 interfaces connected ISGs in 2 to make a balance .Hello,
I do not believe that the ASR901 will do this without help from an upstream device. If I understand correctly, you want to build a bridge-domain with 3 EFPs: 2 physical ports, and one pseudowire. As of the last IOS revision that I have configured on this platform, the 901 doesn't support the pseudowire on a bridge-domain, only a service instance.
It seems to me that you would need an upstream box involved to support this.
Either:
Build 2 pseudowires to an upstream box that supports this configuration (like an ME 3600x, ME3800x, or 9k).
or
Associate both service instances to a common bridge domain that is extended to an upstream box that is initiating the pseudowire. More platforms would support this, since it does not require supporting the pseudowire on a bridge domain.
...Unless you are looking to build an LACP channel-group on the interfaces connected to the ISGs to load-balance. The 901 supports LACP, and it also supports building an EFP (service instance) on the channel-group interface. This technically makes the 2 physical interfaces one EFP. The part of this that I have not tried is building a pseudowire on an EFP on a channel-group.
Hope this helps.
Jason -
Hello. Muse 2014.2 : when I copy and paste svg from Illustrator to Muse, i have no transparency. Only by importing saved svg file I have transparency.
In official Adobe (promo) Tutorial in the same operation - svg is transparent, link: Import SVG | Adobe Muse CC tutorials
Please help me!. It would be very usefull copy&paste svg with transparency.
Andrew MaolaHi.
Thank you for explaining the theory about rendering in Muse but something doesn't work.
I'm running on Win7 - CC2014.2. on 2 different computers. Efe Of course the transparency displays correctly when I preview my page in the browsers (All browsers - also IE11).
Also in preview mode svg is very good but in design mode
In order to render the SVG at design time, Muse hands the SVG to Safari on the Mac and Internet Explorer on Windows and asks it for a bitmap. This bitmap is only used at design time and when viewing the site in a browser that does not support SVG. Unfortunately, the bitmap returned by Internet Explorer strips out partial transparency. Fully transparent pixels should be preserved at design time and all transparency should be preserved when you actually view your site in the browser.
We have not seen or heard of differences in the handling of transparent pixels between copy/pasting and save/import. Hence, I'm wondering if the copy/paste issue is only with partially transparent pixels and if the case that succeeds in a save/import workflow is for fully transparent pixels. To be clear, this transparency issue should only be during design time on Windows. There shouldn't be any issues on the Mac or in the browser.
Muse 2014.2 : when I copy and paste svg from Illustrator to Muse, i have no transparency. -
Using AGG/CALC DIM function in the BSO target cube of Transparent Partition
Hi,
Is it possible to use AGG("dimension") on a dimnesion in the BSO cube that is a target cube for a BSO-BSO Transparent Partition/
I have created the partition area with 3 dimensions, one being 'Source'. 90% of the source members are being refrenced from source to target via that transparent partition. But I still have the 10% Source members in the target cube that need to roll up to the 'Source"(along with the 90%) for correct aggregation.
When I try to use AGG("Source") in a FIX statement that's within the partition area, I get the following error:
Error: 1042013 Network error [10054]: Cannot Receive Data
Error: 1042012 Network error [10054]: Cannot Send Data
Can I not aggregate the dimension in the Target cube?
ThanksHi,
We have the same problem.
I try to create transparent pertition between BSO (as a source) and ASO (target) and have the same warning message.
Just to eliminate possible effect of outline complexity I created very simple DBs with the following outlines:
__For ASO:__
mes1
mes2
Measures
prd1
prd2
Products
Actual
Adjustment
Scenarios
__For BSO:__
mes1
mes2
Measures
prd1
prd2
Products
Adjustment
Scenarios
In addition to the message I have the following behavior - ASO has data in "Actual" scenario, BSO has data in "Adjustment" scenario. Before partition definition I can see the data in the right places, but when the partition created, Actual data disapeared from report of ASO. It is still in the database, and when the partition removed - appears again.
Any ideas?
Thank you in advance,
Alexey
Maybe you are looking for
-
Stock of a material as on given date
Hi all, Is there any function module or any BAPI to calculate the opening and closing stock of a material as on the given date, based on which a customizing report is to be developed.. There was a Transaction MB5B to know the as on date stock, bu
-
Podcast episode does not appear in iPod app on iPhone
My podcast feed "A Thoughtful Faith" has two episodes. Both of them download without trouble on the desktop version of iTunes, but on the iPhone after episode 1 downloads it still shows that it is available and not "Downloaded," and will not show up
-
Decimal Notation + C14N_NUMERIC_FORMAT
Hello Friends, The user can set the Decimal Notation as he want, and I need to set it in this format... 1 234 567,89 I found this FM, but dont know how to use it, can any one pls put some example for so ? Regards,
-
have Imac with 10.6.8. osx....can receive emails but cannot send & have .mac email . was working fine last week
-
Installation problem - no project type 'enterprise'
Hello I have just installed Java Studio Enterprise 8 but I dont have an 'enterprise' option on the new project menu. The options samples, standard, uml & web are available. I am using Windows XP SP2 and JDK 1.5.0.10 One of my colleagues intalled the