ACE - VIP ping issue

Unanswered Question
Feb 15th, 2008
User Badges:


for some reason I cannot ping the VIP I configured on one ACE context.

Here is a sample of the config:

class-map match-any L4_kitrik

2 match virtual-address any

class-map type http loadbalance match-any L7_kitrik_URL

2 match http url .*

class-map type management match-any REMOTE_ACCESS

2 match protocol ssh any

3 match protocol icmp any

policy-map type management first-match REMOTE_MGMT_ALLOW_POLICY



policy-map type loadbalance first-match L7_kitrik_LBPolicy

class L7_kitrik_URL

policy-map multi-match L4_kitrik_LBPolicy

class L4_kitrik

loadbalance vip inservice

loadbalance policy L7_kitrik_LBPolicy

loadbalance vip icmp-reply active

loadbalance vip advertise active

interface vlan 100

ip address

no normalization

no icmp-guard

access-group input ALL

access-group output ALL

service-policy input REMOTE_MGMT_ALLOW_POLICY

service-policy input L4_kitrik_LBPolicy

no shutdown

I am coming from VLAN 100.

I can ping from different devices but not I know connectivity is ok since I am able to telnet into port 80... ping still does not work.

Any idea?


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Gilles Dufour Mon, 02/18/2008 - 01:06
User Badges:
  • Cisco Employee,

change your class-map into :

class-map match-any L4_kitrik

2 match virtual-address tcp any


class-map match-any L4_kitrik

2 match virtual-address tcp eq 80

Right now I believe your icmp traffic is interpreted as http due to your policy and therefore it fails.


deephazz02 Mon, 02/18/2008 - 02:19
User Badges:


I just tried it but no luck.

I check this configuration against some other contexts configured for http loadbalancing and the other configurations were just the same.

I need to check the servers now to see wether they reply icmp packets or not.

Gilles Dufour Mon, 02/18/2008 - 02:47
User Badges:
  • Cisco Employee,

if you have the class-map I configured, the icmp traffic will not be forwarded to the servers.

The ace module will respond.

Share your complete config if you want me to have a look.

Also check if the ping gets to the ace module with a sniffer trace in front of the module.

You can 'monitor' the tengig interface of the module to capture a trace.

you can send me the config to [email protected] if you want to keep it private.


rmathiyalagan Wed, 02/20/2008 - 14:37
User Badges:

ICMP replies comes from the servers configured for the vip address. Check the icmp connection status to the servers and if probes configured, check them too..


This Discussion