SSL-M integration into a 6500 environment with a CSM in one-arm mode with PBR
Ok..so I seem to have the TAC befuddled so I'm going to come here as well.
I have a 6509 with a CSM blade and a SSL-M blade installed. The CSM is configured and working properly in a one-arm mode and we are tring to get the SSL-M integrated into the flow. I can get the SSL-M to present the certificate, but response flow from the server REAL back to the client is getting hung it appears. Even outside of talking through the CSM, the SSL-M does not seem to be functioning correctly. I think if I can get the SSL-M to just return traffic from a server REAL through to the client, the CSM integration would then be fall down. Can someone help me with this as I am obviously missing something. SSL-M is running 3.1(4). The server real responds on port 81 and I can telnet to the port from the SSL-M. If someone wants more of the config, I will attach it. Right now I just want traffic to flow correctly through the SSL-M, I'll integrate the CSM into the mix later.
ssl-proxy context Default ! service SSLTEST virtual ipaddr 10.80.110.214 protocol tcp port 4443 server ipaddr 10.80.100.214 protocol tcp port 81 certificate rsa general-purpose trustpoint windows-iis6 inservice
interface SSL-Proxy0 no ip address no ip route-cache hold-queue 2048 in ! interface SSL-Proxy0.1 encapsulation dot1Q 4 ip address 10.4.1.10 255.255.0.0 no ip route-cache ! interface SSL-Proxy0.80 encapsulation dot1Q 80 ip address 10.80.0.254 255.255.0.0 no ip route-cache ! ip classless ip route 0.0.0.0 0.0.0.0 10.4.0.1
Question We run asr9001 with XR 6.1.3, and we have a very long delay to
login w/ SSH 1 or 2 to the device compare to IOS device. After
investigation, the there is 1s delay between the client KEXDH_INIT and
the server (XR) KEXDH_REPLY. After debug ssh serv...
Introduction The purpose of this document is to demonstrate the Open
Shortest Path First (OSPF) behavior when the V-bit (Virtual-link bit) is
present in a non-backbone area. The V-bit is signaled in Type-1 LSA only
if the router is the endpoint of one or ...
Hi, I am seeing quite a few issues with patch install and wanted to
share my experience and workaround to this. Login to admin via CLI, then
access root with the “shell” command Issue “df –h” and you’ll probably
see the following directory full or nearly ...