CSS group and ACE NAT

Unanswered Question
Nov 11th, 2008
User Badges:

Hi all,

may you help me to understand those commands:

content foo

add service bar01_11111

add service bar02_11111

balance aca

protocol tcp

port 11111

vip address


group foo_group

vip address

add destination service bar01_11111

add destination service bar02_11111


flows: src1.1.1.1(A) dst10.0.0.1(B,CSS_VIP), service(C,D)

from ClientToCss: src A dst B(VIP) -- from CSStoServerBalanced src B(srcNAT) dst C,D -- from ServerToCSS src C,D dst B -- from CssToClient src B dst A

is the above example right?

If a flows begin from servers will they be SRC natted with

and if i put also this stuff what's happend?

group foo_group_int

vip address

add service bar01_11111

add service bar02_11111


could be ok this configuration if i have to hit, with servers bar01 and bar02 content foo(, same servers balancing)?

So in this way server will hit the VIP but CSS will nat src and put as address so that return traffic will pass to CSS

with ACE i have just to put nat commands on right interface?

thx a lot


  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Gilles Dufour Wed, 11/12/2008 - 00:38
User Badges:
  • Cisco Employee,

You can't configure both 'add service' and 'add destination service' with the same vip.

You could do it using ACL, but it is more complex.

add destination service will nat src ip when traffic is forwarded to the destination service.

add service will nat the src ip when traffic is coming from the service.

More info @




This Discussion