I have a few questions regarding the CSS and SSL certificates.
I have 2 CSS 11501 and 3 web servers, how many SSL certificates do I need?
I want to configure the CSS as active - active, is this supported using the SSL accelleration module? If it is, is it configured the same way as a standalone CSS. The documentation only mentions configurations using single module and 2 modules in the same CSS.
And a clarificacion: Does the term Backend in the CSS SSL config refer to servers on a different subnet (in our case physically separated). Our config is 2 FW -> 2 CSS -> 3 Web servers -> 2 backend FW -> 6 Backend servers (app and DB). Am I correct in assuming that Backend refer to this backend? (This might seem like a silly question but the documentation has me confused)
Regarding the certificate, you could just use one.
Get 1 certificate for your VIP and upload it on both SSL module.
However, you might have to get 2, because certificate providers usually say it's one per physical device.
If you plan on doing SSL on the servers as well, you need 3 more certificates. Or you coul use a single certificate if this is allowed by the company that will give it to you.
Backend refers to server behind the CSS.
Like a firewall defines inside and outside interfaces, the CSS define the frontend and the backend.
The frontend is the client side and the backend the server side.
When you say active/active, what do you want to achieve exactly ?
You can indeed have 2 Vip and one is active on CSS1 while the other is active on CSS2.
However, if the CSS shares the same set of servers, you need to be careful that the return traffic from the server to the client goes back to the same server. This may require client nat (group config).
Moquery is the command line cousin of Vizore, it's very helpful and efficient sometimes during the troubleshooting. This article aims to provide moquery cheat sheet to the users for some most common seen scenarios.
Here is the checklist before customers/partners contact Cisco TAC:
Firmware Version of APIC and Switch
Download Switch and APIC techsupport logs
Problem description (Symptoms with details)
Business impact (eg, what kind of services...
moquery usageAPIC moquerySwitchmoquery
This document discuss a common issue observed during the VMM integration & VM workload migration to ACI fabric.
VMware Virtual machines are hosted in Cisco UCS-B seri...