02-20-2012 11:02 AM
I have a web server farm and an email server farm, both load balanced behind the same ACE. However, the web servers cannot connect to the email servers (and vice versa).
I've also tested from other servers behind the ACE, and they cannot connect to either server farm.
Is there something that prevents the ACE from servicing hosts that actually lie behind the ACE?
I can ping the VIP, but cannot access the web site or connect to port 25 on the mail server.
Thanks.
Jason
Solved! Go to Solution.
02-20-2012 11:18 AM
Jason,
There are two reasons why this would not be working when the client is in the server vlan.
1 you need to have the service-policy applied to the server facing vlan.
2 you need SNAT. If the device initiating the connection to the vip is in the server vlan nat is needed to force the server to reply back to the ACE rather than the client directly. this would be considered a one armed mode topology in this case.
Regards
Jim
02-20-2012 11:18 AM
Jason,
There are two reasons why this would not be working when the client is in the server vlan.
1 you need to have the service-policy applied to the server facing vlan.
2 you need SNAT. If the device initiating the connection to the vip is in the server vlan nat is needed to force the server to reply back to the ACE rather than the client directly. this would be considered a one armed mode topology in this case.
Regards
Jim
02-20-2012 12:25 PM
That was what I needed. Once I added the SNAT, it worked.
Thank you.
Jason
03-24-2012 06:27 AM
Hello,
i understand the sourcenat but is it mandatory to add the service policy with SN on server side and not only on client side ?
thanx
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide