cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
365
Views
0
Helpful
1
Replies

CSS 11503 One armed config

skumar1969
Level 1
Level 1

All,

I got a question on the one armed config.

Cisco says use "destination service" under the source group to change the default NAT behaviour of the CSS, because the servers' default gateways are set to the router IP address and the source IP address of the load balanced request is not on the local subnet. I understand this way you avoid the packets reaching the router directly when they head back to the client, bypassing the CSS.

Now the question I got here is that, what if I set the Servers' default gateway to the CSS rather than the Router. This way you are actually forcing the packets destined for remote networks to go through the CSS DG.. Should I need the source group anyway here. I think I don?t. Someone please clarify. Much appreciated?

thanks

1 Reply 1

Gilles Dufour
Cisco Employee
Cisco Employee

if you set the default gateway to be the CSS, then there is no need for the source group.

However, if you have traffic going directly to the servers, they will go client-->router-->server-->CSS [breaks - because asymetric flow].

If you never access the server directly, you're ok. OR you can set a route on the router forcing the traffic through the CSS.

Gilles.