vrrp failover not working correctly alteon ad3

vrrp failover not working correctly alteon ad3

NewsGroups | Search | Tools
 comp.dcom.sys.nortel  Post an article  get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content  add this group's latest topics to your Google content  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
vrrp failover not working correctly alteon ad3 delusion39 08-15-2006
Posted by delusion39 on August 15, 2006, 9:50 am
If you were  Registered and logged in, you could reply and use other advanced thread options
This is my first Alteon configuration, so I'm a newb to all of this.

Problem:

When failover Alteon(ad3) becomes master of virtual IPs (VSR IPs and VR
IP),
web requests are not able to route back to the web client.

The Alteon shows the session with the correct ips.
The web request is sent to the virtual server IP.
The real web server receives the web requests from the Alteon.
The server is still able to access the internet.
The Server receives the SYN transmissions, but SYN-ACK transmissions do
not trasmit back through the LB to the client.
VR MAC addresses are associated with all VR IPs. ARP tables in the
firewall and server reflect correct MAC addresses.

Config:

2 Alteons (ad3)
1 web server (for testing)
Primary alteon has 192.168.0.20 assigned to a physical interface
and enabled as a VR IP.
Secondary alteon uses 192.168.0.20 as a VR IP.
Server default gateway points to 192.168.0.20

Current physical layout:


|firewall| |firewall|
|         |
|         |
\ /
\ /
\ /
|switch|
| |
| |
/ \
/ \
|alteon| |alteon|
|         |
|         |
\ /
|switch|
|
|
|
|server|


It feels like I'm missing something simple. Any info would be
appreciated.

Thanks!


NMFall 20%
Posted by Dophi on August 15, 2006, 9:43 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


You can try to create a VIR which's IP address is not the physical IP
address of any Alteon. This will help you solve this issue probably.


delusion39 wrote:
> This is my first Alteon configuration, so I'm a newb to all of this.
>
> Problem:
>
> When failover Alteon(ad3) becomes master of virtual IPs (VSR IPs and VR
> IP),
> web requests are not able to route back to the web client.
>
> The Alteon shows the session with the correct ips.
> The web request is sent to the virtual server IP.
> The real web server receives the web requests from the Alteon.
> The server is still able to access the internet.
> The Server receives the SYN transmissions, but SYN-ACK transmissions do
> not trasmit back through the LB to the client.
> VR MAC addresses are associated with all VR IPs. ARP tables in the
> firewall and server reflect correct MAC addresses.
>
> Config:
>
> 2 Alteons (ad3)
> 1 web server (for testing)
> Primary alteon has 192.168.0.20 assigned to a physical interface
> and enabled as a VR IP.
> Secondary alteon uses 192.168.0.20 as a VR IP.
> Server default gateway points to 192.168.0.20
>
> Current physical layout:
>
>
> |firewall| |firewall|
> |         |
> |         |
> \ /
> \ /
> \ /
> |switch|
> | |
> | |
> / \
> / \
> |alteon| |alteon|
> |         |
> |         |
> \ /
> |switch|
> |
> |
> |
> |server|
>
>
> It feels like I'm missing something simple. Any info would be
> appreciated.
>
> Thanks!


Posted by delusion39 on August 16, 2006, 10:59 am
If you were  Registered and logged in, you could reply and use other advanced thread options


No luck. Same issue. Thanks for the suggestion though.

Shaun

Dophi wrote:
> You can try to create a VIR which's IP address is not the physical IP
> address of any Alteon. This will help you solve this issue probably.
>
>
> delusion39 wrote:
> > This is my first Alteon configuration, so I'm a newb to all of this.
> >
> > Problem:
> >
> > When failover Alteon(ad3) becomes master of virtual IPs (VSR IPs and VR
> > IP),
> > web requests are not able to route back to the web client.
> >
> > The Alteon shows the session with the correct ips.
> > The web request is sent to the virtual server IP.
> > The real web server receives the web requests from the Alteon.
> > The server is still able to access the internet.
> > The Server receives the SYN transmissions, but SYN-ACK transmissions do
> > not trasmit back through the LB to the client.
> > VR MAC addresses are associated with all VR IPs. ARP tables in the
> > firewall and server reflect correct MAC addresses.
> >
> > Config:
> >
> > 2 Alteons (ad3)
> > 1 web server (for testing)
> > Primary alteon has 192.168.0.20 assigned to a physical interface
> > and enabled as a VR IP.
> > Secondary alteon uses 192.168.0.20 as a VR IP.
> > Server default gateway points to 192.168.0.20
> >
> > Current physical layout:
> >
> >
> > |firewall| |firewall|
> > |         |
> > |         |
> > \ /
> > \ /
> > \ /
> > |switch|
> > | |
> > | |
> > / \
> > / \
> > |alteon| |alteon|
> > |         |
> > |         |
> > \ /
> > |switch|
> > |
> > |
> > |
> > |server|
> >
> >
> > It feels like I'm missing something simple. Any info would be
> > appreciated.
> >
> > Thanks!


Posted by mlsnospam on August 17, 2006, 2:43 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Are the Virtual MACS identical on both sides of the Alteons?
If yes, then are the switches in your diagram actually one switch with
multiple VLANS? Some switches don't support multiple bridge forward
tables, and duplicate MACS on separate VLANS becomes a problem.


Similar ThreadsPosted
alteon and vrrp failover April 19, 2006, 12:57 pm
Transparent Failover support with Nortel Alteon Load balancers?? October 19, 2006, 4:53 am
Can VRRP be used when the servers are in same LAN as clients? October 28, 2006, 11:17 am
Outbound CLID not showing correctly December 15, 2006, 11:53 am
Outbound CLID not showing correctly December 15, 2006, 12:04 pm
Outbound CLID not showing correctly December 15, 2006, 12:05 pm
Outbound CLID not showing correctly December 15, 2006, 12:05 pm
Outbound CLID not showing correctly December 15, 2006, 12:11 pm
M7000 Not Working March 26, 2005, 3:19 am
Busy to VM is not working. April 1, 2005, 10:37 am

other useful resources:
The Federal Communications Commission (FCC)
Telecommunications Industry Association
Electronic and Software Security Products and Services
International Telecommunication Union

Custom CGI Perl and PHP programming by 1-Script.com

Contact Us | Privacy Policy
The site map in XML format XML site map