My 2 server farm distribution switches are running in "hybrid" mode, with CAT OS on the switch and IOS on the MSFC.
My server team is asking to block traffic to a specific server that is load balanced using Cisco's CSM load-balancer which is also installed in the chassis.
The question that I have is this.
Does anyone know in what order the MSFC will inspect and apply the ACL and when will the CSM make the load balancing decision?
The reason I need to know this is that the CSM is setup in bridged mode, where traffic to the server comes into the MSFC with a destination IP of a VIP which resides on the CSM. Subsequently, the CSM forwards the traffic to the one of the real servers in the load-balanced server farm after it makes its load-balancing decision. Which ocurrs first??
Does anyone have any info on what ocurrs first and so forth??
Is there a link to Cisco's website that explains this process??
"Actually the MSFC cannot filter traffic to the real server because from its point of view traffic is directed to the Virtual server IP and has no knowledge of what real the traffic will be sent to."
I agree totally with what you wrote here. But you then go on to give an example where you could filter it by using an ACL outbound on the client vlan. But the destination would be the VIP not the real address. It only becomes the real address after it has gone through the CSM.
I agree the easiest way is to take the server out of service under the serverfarm if that's possible but Tony may want to just block only certain traffic to that server.
Question We run asr9001 with XR 6.1.3, and we have a very long delay to
login w/ SSH 1 or 2 to the device compare to IOS device. After
investigation, the there is 1s delay between the client KEXDH_INIT and
the server (XR) KEXDH_REPLY. After debug ssh serv...
Introduction The purpose of this document is to demonstrate the Open
Shortest Path First (OSPF) behavior when the V-bit (Virtual-link bit) is
present in a non-backbone area. The V-bit is signaled in Type-1 LSA only
if the router is the endpoint of one or ...
Hi, I am seeing quite a few issues with patch install and wanted to
share my experience and workaround to this. Login to admin via CLI, then
access root with the “shell” command Issue “df –h” and you’ll probably
see the following directory full or nearly ...