WAAS Inline Adaper and Microsoft NLB (ISA Server Array)

Hi
I would like to place a waas device with 4-port inline adapter  between a MS ISA Firewall and the LAN switches. The ISA are unfortunately forming an array and using NLB which causes the switches to do unknown unicast flooding.
            / Switch A --------------- LAN0   WAN0  ------------ ISA1 ------------- Switch C ---------- Router A
LAN -- |            |                               WAAS                        Array                        |       HSRP     |
            \ Switch B --------------- LAN1   WAN1  ------------ ISA2 ------------- Switch D ---------- Router B
Will the WAAS get problems since it is seen all the traffic on both inline groups? Is this setup possible?
kind regards
Tobias

Gary,
Yes you just need to configuring your firewall to allow TCP options (specifically option 33 (0x21 in HEX)), then configure the WAEs for directed mode.
The firewall will see a TCP 3-way handshake at first so the two WAEs can auto discover each other and negotiate a UDP directed mode tunnel.
Once the auto discovery phase is complete traffic traffic sent over the WAN side of the connection will be encapsulated in the UDP 4050 tunnel (so your firewall must allow this traffic through as well).
Please see the configuration guide section on directed mode here which explains in more detail, and let me know if you have other questions.
http://www.cisco.com/en/US/docs/app_ntwk_services/waas/waas/v421/configuration/guide/network.html#wpxref53362
Cheers,
Mike

Similar Messages

  • SG switches and Microsoft NLB

    Hi,
    does anyone know if the SG300 switches can be used with Microsoft NLB in Multicast mode?
    I know on traditional Catalyst switches you can statically "map" IP's to mac's and then to multiple ports but this doesn't seem to work correctly on the SG switches - it gives an error about the mac not being not Unicast?
    So, any help or links to Cisco SG examples would be appreciated.
    thanks
    John

    I have not tested it yet. But I want to know this as well.
    Keep in mind that you need to use the multicast MAC Address, not your normal MAC Address. It is bound to a multicast IP Address.

  • Cleanup of ISA rules in ISA server 2004 and 2006

    Hi Team
    how could i know, which rules are actively working and which rules are not being used in ISA server 2004 and 2006 . based on this we are going to disable the rule initially and delete the rules which is currently not being used in later stage. since we have
    lot rules in ISA , we need to segregate this 
    Could you please able to help me

    Hi,
    Please check the Creating Custom Reports parts in the following blog to see whether it can help you.
    Logging and Reporting in ISA Server 2006
    http://www.isaserver.org/articles-tutorials/configuration-general/Logging-Reporting-ISA-Server-2006.html
    Note:
    Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.
    Best Regards,
    Joyce

  • Cisco Secure ACS and Windows NLB

    Hi,
    I have two ACS servers and have been trying unsuccessfully to setup Windows NLB for them. I can successful setup the NLB but ACS won't respond on the clustered IP. Other services running on the clustered IP will respond so I believe the NLB is working correctly.
    Has anyone had any success with ACS and Microsoft NLB? I can?t find any documentation to suggest that they are incompatible but I think this may be the case.
    Thanks,
    Neil

    Neil,
    ACS is not tested with NLB but if cluster hosts are attempting to communicate with the ACS using their clustered IP then ACS should reply.
    Do you see any hits on acs ? If you sniff the acs interface, what is the source IP address ? Is it clustered ip or clustered host IP ??
    Also on acs --->Network configuration add aaa client with host IP and clustered ip . Now see if acs responds to NLB.
    Regards,
    ~JG

  • Customers not able to log in with Microsoft ISA server firewall.

    I have a few external customers that are having issues logging in.  In all cases it is with the customer having Microsoft ISA firewalls.
    They can get to the site.  They put in their username and password.  The screen flashes back to the logon screen, no errors, just back to the screen.
    On the logs I seen the logon page request and the 200 OK but, the username and password never come across.
    I can not tell if the username and password are being blocked by the ISA server or when the logon screen is presented that the username and password fields are just not active.
    Has anyone else see or hear about this one?

    We are seeing a slightly different problem but certainly related. We are using a SAP cFolder server for PLM collaboration. Companies using a Microsoft ISA server are not seeing problems logging in but are seeing problems with the mass download feature. They are seeing the connection hang. Looking at the ISA log file on the server they are receiving an authentication problem and a broken connection. If you try a single file download everything works OK. Also vendors without ISA are working fine.
    What is it about ISA that would be causing issues like these?

  • SharePoint 2010 and ISA server proxy - Any step by step documentation to do this?

    Hi there,
    I know that ISA is deprecated - still for next few months we still need to use it. 
    I will appreciate if you could please share any document on how to have a SharePoint 2010 Intranet Web Application available on Internet using ISA server proxy.
    Thank you so much.

    Hi,
    here you are
    http://blogs.technet.com/b/paulpaa/archive/2009/09/23/steps-to-publish-sharepoint-sites-created-in-host-header-mode-hh-mode-with-isa-server-2006.aspx
    http://serverfault.com/questions/174061/how-to-configure-aams-in-sp-2010-to-work-with-isa-2006-and-kerberos-authenticati
    http://www.benjaminathawes.com/2010/08/22/publishing-sharepoint-2010-with-isa-server-2006-sp1/
    http://www.isaserver.org/articles-tutorials/publishing/How-to-Publish-Microsoft-Sharepoint-Service-ISA-Server-2006.html
    http://technet.microsoft.com/library/bb794854.aspx#SecureWebPublishing
    Kind Regards,
    John Naguib
    Technical Consultant/Architect
    MCITP, MCPD, MCTS, MCT, TOGAF 9 Foundation
    Please remember to mark your question as answered if this solves your problem

  • Perimeter authentication with ISA server and AD

    Hi,
    We have a Microsoft ISA server that does all authentication at the perimeter. I'm trying to set up a WLS 10 that can inspect and pass on the authenticated Subject to the (SQLServer) database when performing searches.
    I have configured the environment according to the steps in [url  http://e-docs.bea.com/wls/docs100/secmanage/sso.html], and I have set up my security realm with an Active Directory Authentication provider and a Negotiate Identity Assertion provider. But soemthing is obviously not working, since I see no signs of the authenitcated subject in the server log, and Security.getCurrentSubject() returns an empty Subject. What am I doing wrong?
    Thanks
    Edited by tdirrenb at 04/18/2008 6:33 AM
    Edited by tdirrenb at 04/18/2008 6:34 AM

    Hi Vinod,
    Looks like this is a AAA issue. Moving this to AAA domain for faster response.
    thanks,
    Vinay

  • ASA 8.0 and Microsoft ISA (local user backup)

    What is the command so that when the username + password cannot be found in the microsoft isa server, the pix will look at the local database?
    This command works in the router, but I cannot seem to find the equivlant for the pix.
    aaa authentication login default local group tacacs+
    Basically does the pix asa 8.0 support Multiple authorization commands?
    Thank you very much for your help.

    On a router, "aaa authentication login default local group tacacs+ " will ALWAYS use the local user DB, never tacacs.
    "aaa authentication login default group tacacs+ local" will first try tacacs and only if the tacacs server is not responding, use the local DB. Note that if the tacacs DOES respond but rejects the authentication attempt (user does not exist or wrong password), that the router will NOT use the local DB.
    That said, on pix/asa you can do the same, e.g.:
    aaa-server TPLUS protocol tacacs+
    aaa-server TPLUS (management) host 10.0.0.1
    aaa authentication telnet console TPLUS LOCAL
    hth
    H

  • Use of CE/WCCP with Microsoft ISA server acting as an authentication proxy.

    We have a design where all web users are authenticated against Active Directory by Microsofts ISA server proxy service prior to accessing web resources.
    Is it possible to implement a CE behind the ISA server, and still have the proxy authenticate users credentials?
    My concern is that WCCP will redirect traffic to the content engine first, if the content is not available, wil the content engine then forward to the proxy for authentication prior to the request going out to the web?
    Cheers,

    Since there has been no response to your post, it appears to be either too complex or too rare an issue for other forum members to assist you. If you don't get a suitable response to your post, you may wish to review our resources at the online Technical Assistance Center (http://www.cisco.com/tac) or speak with a TAC engineer. You can open a TAC case online at http://www.cisco.com/tac/caseopen
    If anyone else in the forum has some advice, please reply to this thread.
    Thank you for posting.

  • Java 1.5.0_04 and ISA server

    i dont have any programming knowledge , but can you tell me if ISA server supports the use of the drag and drop facility in the version stated abovePlease no techy stuff it will go in one ear and out the other.

    "Agreed. This doesn't sound like it has anything to do with Java. Try to find a Microsoft (ISA) forum and ask there. Good luck."
    do you know of a link that i could see relating to ISA forums, so i can ask my question there.
    I too will suggest to them to try other servers. I asked a friend what reverting back to an old version of java would do. And they said it wouldnt solve the problem, but you would just need to copy and paste instead of having a drag n drop facility.
    My ex boyfriend use to about java all the time so i kind of know what you guys are on about.
    I guess my choices are:
    test it on another server;
    see to what extent ISA support java applets.
    try another port??? how do i do that?
    the obvious one ask in an ISA forum

  • Microsoft NLB and Cisco 4500 VSS

    Hi,
    I have a pair of Cisco 4507 switches in VSS mode. An server (10.4.1.166)  using Microsoft NLB MAC address (03bf.0a04.01a6) is connected to VSS Node 1 on port Gi1/6/43. The following is configured on the switch.
    arp 10.4.1.166 03bf.0a04.01a6 ARPA
    mac address-table static 03bf.0a04.01a6 vlan 31 interface Gi1/6/43
    The second command appears differently in running-config but looks good in mac-address-table:
    # show running-config | inc mac address
    mac address-table static 03bf.0a04.01a6 vlan 31 interface Gi6/43
    # show mac address static | inc 01a6
      31      03bf.0a04.01a6   static Gi1/6/43
    Now, from a PC I can ping the VIP address 10.4.1.166 when connected to VSS Node 1 or any other switch connecting to VSS Node1. If the PC attachment is to VSS Node 2 directly or indirectly, then the ping times out. Doing the same for all the rest of servers not using Microsoft NLB  but connected to Node 1 only, is successful from anywhere.
    Why is the traffic not traversing the the VSL link i.e. PC -> VSS Node 2 -> VSL -> VSS Node1 -> Server.
    Thanks,
    Rick.

    Thanks Reza, Please find the output of the commands below. The VSS switch looks to be good and working for all other services.
    #show switch virtualExecuting the command on VSS member switch role = VSS Active, id = 1Switch mode                  : Virtual SwitchVirtual switch domain number : 1Local switch number          : 1Local switch operational role: Virtual Switch ActivePeer switch number           : 2Peer switch operational role : Virtual Switch StandbyExecuting the command on VSS member switch role = VSS Standby, id = 2Switch mode                  : Virtual SwitchVirtual switch domain number : 1Local switch number          : 2Local switch operational role: Virtual Switch StandbyPeer switch number           : 1Peer switch operational role : Virtual Switch Active# show switch virtual redundancyExecuting the command on VSS member switch role = VSS Active, id = 1                  My Switch Id = 1                Peer Switch Id = 2        Last switchover reason = none    Configured Redundancy Mode = Stateful Switchover     Operating Redundancy Mode = Stateful SwitchoverSwitch 1 Slot 3 Processor Information :-----------------------------------------------        Current Software state = ACTIVE                 Image Version = Cisco IOS Software, Catalyst 4500 L3 Switch Software (cat4500e-UNIVERSALK9-M), Version 15.1(2)SG, RELEASE SOFTWARE (fc3)Technical Support: http://www.cisco.com/techsupportCopyright (c) 1986-2012 by Cisco Systems, Inc.Compiled Wed 05-Dec-12 04:38 by prod_rel_team                          BOOT = bootflash:cat4500e-universalk9.SPA.03.04.00.SG.151-2.SG.bin,1;        Configuration register = 0x102                  Fabric State = ACTIVE           Control Plane State = ACTIVESwitch 2 Slot 3 Processor Information :-----------------------------------------------        Current Software state = STANDBY HOT (switchover target)                 Image Version = Cisco IOS Software, Catalyst 4500 L3 Switch Software (cat4500e-UNIVERSALK9-M), Version 15.1(2)SG, RELEASE SOFTWARE (fc3)Technical Support: http://www.cisco.com/techsupportCopyright (c) 1986-2012 by Cisco Systems, Inc.Compiled Wed 05-Dec-12 04:38 by pro                          BOOT = bootflash:cat4500e-universalk9.SPA.03.04.00.SG.151-2.SG.bin,1;        Configuration register = 0x102                  Fabric State = ACTIVE           Control Plane State = STANDBYExecuting the command on VSS member switch role = VSS Standby, id = 2show virtual switch redundancy is not supported on the standbySKR_4507_01#show switch virtual link port-channelExecuting the command on VSS member switch role = VSS Active, id = 1Flags:  D - down        P - bundled in port-channel        I - stand-alone s - suspended        H - Hot-standby (LACP only)        R - Layer3      S - Layer2        U - in use      N - not in use, no aggregation        f - failed to allocate aggregator        M - not in use, no aggregation due to minimum links not met        m - not in use, port not aggregated due to minimum links not met        u - unsuitable for bundling        d - default port        w - waiting to be aggregatedGroup  Port-channel  Protocol    Ports------+-------------+-----------+-------------------15     Po15(SU)         -        Te1/3/1(P)  Te1/4/1(P)16     Po16(SU)         -        Te2/3/1(P)  Te2/4/1(P)Executing the command on VSS member switch role = VSS Standby, id = 2Flags:  D - down        P - bundled in port-channel        I - stand-alone s - suspended        H - Hot-standby (LACP only)        R - Layer3      S - Layer2        U - in use      N - not in use, no aggregation        f - failed to allocate aggregator        M - not in use, no aggregation due to minimum links not met        m - not in use, port not aggregated due to minimum links not met        u - unsuitable for bundling        d - default port        w - waiting to be aggregatedGroup  Port-channel  Protocol    Ports------+-------------+-----------+-------------------15     Po15(SU)         -        Te1/3/1(P)  Te1/4/1(P)16     Po16(SU)         -        Te2/3/1(P)  Te2/4/1(P)#show run int gi1/6/43interface GigabitEthernet1/6/43 switchport access vlan 31 switchport mode access spanning-tree portfast spanning-tree guard root
    Regards,
    Rick.

  • Problem of Teststand3.1 database and microsoft SQL Server 2000 personal edition

    I have a problem when using teststand database function with Microsoft sql server 2000. the error(seen in attached screenshot3.jpg) is:
    "An error occurred calling 'LogResults' in 'ITSDBLog' of 'DBLog 1.0 Type Library'
    An error occurred executing a statement.
    Schema: Generic Recordset (NI).
    Statement: UUT_RESULT.
    [Microsoft][ODBC SQL Server Driver][SQL Server]unable to insert NULL value to column "ID", table "test.dbo.UUT_RESULT";This column is not alowed to be blank. INSERT Failed. Multiple-step OLE DB operation generated errors. Check each OLE DB status value, if available. No work was done.
    [Microsoft][ODBC SQL Server Driver][SQL Server]terminated.
    Source: TSDBLog"
     Here I listed my proceess.
    1, Configure in SQL Sever, please see attached screenshot0.jpg
       a, Open SQL
       b, build a new database with the name of test
       c, import the data from "C:\Program Files\National Instruments\TestStand 3.1\Components\NI\Models\TestStandModels\Database\TestStand Results.mdb"
    2, Configure Microsoft SQL sever: please see attached screenshot1.jpg
       a, Open windows Control Panel and select "Data Sources (ODBC). Under system DSN tab, add a SQL server data source
    3, Configure teststand database option, see attached screenshot2.jpg
       a, configure logging option, enable
       b, configure datalink
       c, select schemas of "Generic recordset (NI)
       d, No change on the tabs of "statements" and "Columns/Parameters"
    4, run an seqence file with the proess model of SequentialModel.Seq.
    Attachments:
    Screenshot.zip ‏425 KB

    Thanks Scott,
      The database function is OK now after I changed imported tables in SQL Sever.
      Actually, I once tried anothor method that you refered by using the scripts
    located at: <TestStand>\Components\NI\Models\TestStandModels\Database\SQL Server Create Generic Recordset Result Tables.sql. Attached is the error screenshots, please help me on this.
    Thanks
    Jacky
    Attachments:
    Error.jpg ‏59 KB

  • Download Manager with Microsoft ISA Server

    Hello forum, I need help with the connection of program SAP DOWNLOAD MANAGER with ISA Server 2004 
    I've installed JAVA 1_4_2_13 and Download Manager, I configured the setting with the proxy connection (server ISA, user and pass) 
    but an error appears: 
    The basket content could not be read. The following exception occurred: 
    Unable to read data from the Service Marketplace: Check your settings and try again 
    In my ISA server I declared the form my IP to Internet permit all traffic out. 
    Somebody help me ??? what do I have to configure in my ISA Server to permit the connection? 
    Thanks.
    Costa Gustavo

    Hi Ram, I solved the problem with download manager. 
    First my PC don't use as default gateway the ISA Server, I've another default gateway for my LAN. 
    Is it the problem because my PC never contact directly to SAP, I could solved this problem if my PC can contact directly the IP of SAP. 
    You will can set in your PC the gateway of ISA server and public DNS to contact SAP directly 
    For example: 
    I've default gateway 192.168.0.1 for my LAN 
    My ISA server to internet is 192.168.0.9 
    Public DNS : (My ISP) 200.0.1.1 
    In your ISA server you can set a policy from your PC to External for all user with all traffic permit. 
    You try set in your PC the following: 
    Default gateway: 192.168.0.9 
    DNS: 200.0.1.1 
    I hope this can resolve your problem 
    Regards. 
    Costa Gustavo
    SAP BASIS.

  • Differance between microsoft sql 7 server and oracle 8

    can anybody give me the exact technical differances between microsoft 7 server and
    oracle8 server ?

    hi,
    below i listed few differences known to me.
    Oracle is a multiplatform rdbms whereas sqlserver is restricted to NT server workstations.
    Oracle does not include the concept of master db. All db runs independently, with their own data files,mem management, and control.
    Sql server has much larger set of fundamental data types than oracle.
    Oracle uses row-level locking whereas sqlserver uses page level locking.
    Oracle is more mature product. It should be used for high throughput and availability and reliable backup and recovery.
    hope it will give u some idea.
    regards,
    arun.

  • How to connect Java and Microsoft SQL Server 2000

    hi,
    could anyone please teach me how to connect Java and SQL Sever 2000?? if possible could you guys provide me with an example??? i could hardly find any relevant resources about it...
    Thanks ~!

    thanks for the information...
    by the way hv any working module on it?? i'm new to
    both Java and Microsoft SQL Server... Thanks againFirst things first... you should read this:
    http://java.sun.com/docs/books/tutorial/jdbc/
    This is microsofts official JDBC Driver: http://www.microsoft.com/sql/downloads/jdbcregister.asp
    Install it and the documentation has some usage examples

Maybe you are looking for

  • Can I back up two computers with the same name to Time Machine?

    I recently bought a new MacBook Pro to replace my old one. Both have the same Computer Name (as shown in the Sharing tab of System Preferences). The older one backed up to my Time Capsule as Stuart Field's MacBook Pro.sparsebundle.What will happen if

  • How to restrict users from printing documents and exporting to local file

    Hi SAP gurus, I have two questions. 1. How can I restrict users from printing a document? i.e. billdoc? I would like to know if I could block it though authorization. If yes, what auth obj to use? 2. How to restrict certain users from exporting to lo

  • Error IllegalArgumentException in java.sql.Date used PreparedStatement

    I'm found bug (probably). I have a table with column DATA type. Now I connect do database use JDBC in Java, and create PreparedStatement: PreparedStatement stmt = conn.prepareStatement("insert into \"Appuser\" (\"IDUser\", \"createAccountDate\") valu

  • How do i get the apple dock to show whilst im on chrome?

    I've just purchased a macbook pro (my first mac) and im just getting to know the basics and was wondering how i can see the dock whilst im on chrome? it seems to dissappear when i maximise the screen? thanks.

  • ITouch Syncs, but won't Sync.

    I recently got an iTouch, and it worked great. I've had it for... 2 weeks. It's been fine until Saturday, which was 2 days ago. My boyfriend and I tried to sync my iPod to his computer, however it said we needed more space. So, we manually managed th