07-12-2006 07:42 AM
I am having a problem on my css11503. My server guys want to be able to have one set of application servers talk to the vip for another application on the same css. If the traffic is generated from external to the css it works fine, but the problem is when the server that is on the same network tries to communicate to the vip to be load balanced to another server on the same network.
Thanks
Jeff
07-14-2006 12:27 PM
I've seen this before a number of times. If I'm reading this right you have your real servers on the same network (ex. 10.10.10.x/24).
So when serverA hits VIP associated with serverX and serverY...serverX/Y will not send the traffic back thru the CSS because the CSS just passes serverA's IP to serverX/Y and serverX/Y see's it's on the same subnet as serverA and tries to respond directly back to serverA. This obviously breaks the communication because serverA is expecting a response back from the VIP.
There are a couple options to get around this.
Put serverA and serverX/Y on different subnets on the backside of the CSS (vlan trunking to your switch)
or
configure a source group nat for serverA, thereby forcing the traffic to go back thru the CSS
07-16-2006 11:11 PM
this is the correct explanation.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide