Cisco CSS 11501 Content Services Switch Configuration

Unanswered Question
Feb 5th, 2008
User Badges:

Hi all,

I have a Cisco CSS 11501 Content Services Switch with the bellow configurations.

!************************** SERVICE **************************

service service1

ip address


service service2

ip address


!*************************** OWNER ***************************

owner erefill_service1

content L3_Rule

protocol tcp

add service service1

add service service2

balance aca

advanced-balance sticky-srcip

port 8080

vip address


the two services are connected to a switch, and the 11501 content switch is connected to the same switch, and my laptop is connected to the same switch also.

when I try to request the "L3_Rule" from my laptop by doing "" nothing is returned.

I can ping the two services from the content switch and I can ping the content rule virtual IP from my laptop also, but I can't get any thing in return when request the service... Except when I connect the services directly to the content switch, but this is not the way I want to work...

My configurations looks fine to me... but why it's not working...

Please help and advice.



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
sg37868 Tue, 02/05/2008 - 08:23
User Badges:


please find a brief presentation of the problem and an easy solution in the attachment (PowerPoint).

It sounds like the requests are passing the CSS while the responses are directly switched from service to your laptop (bypassing the CSS).

As the CSS performs NAT on the request, the client is unable to classify those direct responses from the services.

To solve this behaviour, just make sure the traffic is always passing the CSS in both directions. The CSS will then be able to revert the NAT on the responses.

I hope this helps.

sg37868 Tue, 02/05/2008 - 09:13
User Badges:

Your understanding of my reply is correct.

eMail is under way with Topic: CSS-Issue.

M.Alnouri Tue, 02/05/2008 - 10:46
User Badges:


Many thanks for your response...

I think that it doesn't differ if the laptop is connected to the switch also... In this case the request will pass the switch to the CSS, and the CSS will send the request to the server... and the server will replay back through the CSS, then the switch to my laptop...

I really appreciate your patient with me.. but this is very important for me...

If the above is totally correct, can you please help me in troubleshooting why I can't get back the date to my laptop...

Thanks again...


M.Alnouri Wed, 02/06/2008 - 01:47
User Badges:

Mt friend you are right...

Once I connect the laptop to the CSS and request for it works fine...

If I connect it to the switch and requested the same no replay is back...

Please note that I've checked the vlans and all the ports are in the same one.

Please advice,

Thanks in advance,


sg37868 Thu, 02/07/2008 - 07:57
User Badges:


This behaviour is because the server does not send back the response to the CSS by default!

The Layer 3 functionality, the CSS uses to forward requests to the servers, is NAT (Network Address Translation - or Port Address Translation if configured).

Unfortunately by default, only the server-IP is translated, so a real server always answers to the original client-IP.

If now the CSS is used in so called "one armed" mode (clients and servers are connected through the same interface to the CSS), by default the responses will bypass the CSS and the NAT won't be reverted.

The infrastructure-design you described is "one armed".

To also perform a NAT for the client IP and thereby force all responses to always pass the CSS, you may use so called source groups.

In your example following additional config should work (unfortunately i never used it in production myself):

group Servers

vip address

add destination service1

add destination service2


Here's an additional CCO-Link describing the problem and its solution very detailed:

M.Alnouri Sat, 02/09/2008 - 23:09
User Badges:

Thank you very much... actually it's a very useful document.

I'll get back to this conversation and finish it...


This Discussion