Re: CSS 11000 Clients' Src IP replaced with VIP's IP
the client nat is done when you have a group configured. - you forgot to provide this part of the config, but I'm certain you have a group in your config.
If the person who configured the CSS thought a group was needed, there might be a reason.
Most ofthen it is required when you have a one-armed scenario. It is being used to guarantee that the response from the server will go back to the CSS first and not directly to the client - which would break connectivity.
You should verify if indeed you're in one-armed.
In one-armed, you can get rid of the group if you can find another way to guarantee the response from the server to go to the CSS.
This can be done by changing the server default gateway or by configuring policy routing on the current default gateway.
Moquery is the command line cousin of Vizore, it's very helpful and efficient sometimes during the troubleshooting. This article aims to provide moquery cheat sheet to the users for some most common seen scenarios.
Here is the checklist before customers/partners contact Cisco TAC:
Firmware Version of APIC and Switch
Download Switch and APIC techsupport logs
Problem description (Symptoms with details)
Business impact (eg, what kind of services...
moquery usageAPIC moquerySwitchmoquery
This document discuss a common issue observed during the VMM integration & VM workload migration to ACI fabric.
VMware Virtual machines are hosted in Cisco UCS-B seri...