cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
283
Views
0
Helpful
2
Replies

Src/ Dst being LB'd by same ACE...reachability issue

cisco_adt
Level 1
Level 1

Hi,

Source: 2 Proxy servers

Destination: 2 Application Servers

Cannot ping each others VIP.

Can ping the real servers.

Is there some issue about the same ACE, LB'ing Src & Dest VIPs.

Response will be appreciated.

ACE mod A2(1.2)

2 Replies 2

dario.didio
Level 4
Level 4

Hi,

some more explenation would be appreciated.

What are you trying to accomplish?

What do you mean by source and destination VIPs?

Source is Proxy Server

Destination is an Application Server

2 different Vlans.

Default Gateway is the Router.

Router sends it to a FW.

(FW's are LB'd by the ACE as well)

PBR is used.

SYN follows the traffic path described above. (rserver-->VIP(Proxy)-->Router-->FW-->down towards the App VIP)

SYN-ACK (rserver-->VIP (App)-->Router-->VIP (Proxy)

SYN-ACK does not go thru the FW....but directly to the other VIP.

Thanks.