<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Csm on Aaron&#39;s Worthless Words</title>
    <link>https://a996c8ee.aww-3cz.pages.dev/tags/csm/</link>
    <description>Recent content in Csm on Aaron&#39;s Worthless Words</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Mon, 25 Jan 2010 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://a996c8ee.aww-3cz.pages.dev/tags/csm/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Migrating CSM Serverfarms to Other Server VLANs</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2010/01/migrating-csm-serverfarms-to-other-server-vlans/</link>
      <pubDate>Mon, 25 Jan 2010 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2010/01/migrating-csm-serverfarms-to-other-server-vlans/</guid>
      <description>&lt;p&gt;A coworker brought an interesting problem to me the other day.  He wanted to move a serverfarm from one server VLAN to another without taking an outage.  Since I didn&amp;rsquo;t want to have to come into the office late at night to do work, I decided to see what we could do.&lt;/p&gt;&#xA;&lt;p&gt;It turned out to be pretty easy.  We tend to think of CSM VLANs as pairs &amp;ndash; you have the client VLAN for the web servers where the vserver sits and the server VLAN where the serverfarm sits.  The CSM doesn&amp;rsquo;t know about these relationships; all it cares about is whether the servers are in a server VLAN, and we can use that to our advantage here.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSCtd31622 - CSM, Cookies, and the year 2010</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2010/01/csctd31622-csm-cookies-and-the-year-2010/</link>
      <pubDate>Fri, 08 Jan 2010 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2010/01/csctd31622-csm-cookies-and-the-year-2010/</guid>
      <description>&lt;p&gt;It seems that we have another piece of evidence that Cisco doesn&amp;rsquo;t like the CSM.  From what I&amp;rsquo;m able to creatively interpret, the software developers didn&amp;rsquo;t think anyone would be running the CSM for very long, so they set a variable that expires CSM-inserted cookies at 01:01:50GMT on 1 January 2010&lt;a href=&#34;#1&#34;&gt;1&lt;/a&gt;.  If you&amp;rsquo;re using cookies to make connections sticky, that means you may see some unexpected results; this shouldn&amp;rsquo;t affect the web servers&amp;rsquo; cookies.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Using SSH to Run Commands on a Router or Switch</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2009/04/using-ssh-to-run-commands-on-a-router-or-switch/</link>
      <pubDate>Thu, 30 Apr 2009 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2009/04/using-ssh-to-run-commands-on-a-router-or-switch/</guid>
      <description>&lt;p&gt;SSH is more than just a shell.  You can copy files from and to a server or piece of network gear with it.  You can use it to tunnel traffic.  Possibly my favorite, though, is to use SSH to run a command on a remote box without interacting with a shell.&lt;/p&gt;&#xA;&lt;p&gt;One of my biggest pet peeves with IOS (or pretty much any Cisco OS) is the lack of complex filtering.  Let&amp;rsquo;s say I want to look at all the downed ports and interfaces on modules 3 and 6 of my 6509.  I can&amp;rsquo;t easily do that with command from the IOS, but, on my Linux box, I can use multiple &lt;em&gt;grep&lt;/em&gt; commands to get exactly what I want really easily.  Let&amp;rsquo;s work through the example, shall we?&lt;/p&gt;</description>
    </item>
    <item>
      <title>An Interesting Problem with Multiple DCs on a Stick</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2009/03/an-interesting-problem-with-multiple-dcs-on-a-stick/</link>
      <pubDate>Tue, 24 Mar 2009 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2009/03/an-interesting-problem-with-multiple-dcs-on-a-stick/</guid>
      <description>&lt;p&gt;We talked about &lt;a href=&#34;http://aconaway.com/2008/08/12/running-multiple-data-centers-on-a-stick-with-the-csm/&#34; title=&#34;AConaway.com -- Running Multiple Data Centers on a Stick&#34;&gt;running multiple data centers on a stick&lt;/a&gt; back in August, which is where you have multiple logical pairs of client and server VLANs on a single CSM for different tiers or functions.  The big point of the article was that you had to do some fancy forwarding to get a server-initiated connection from one server VLAN to appear out the appropriate client VLAN.  Well, we ran into an interesting issue with the given solution.&lt;/p&gt;</description>
    </item>
    <item>
      <title>CSM Probe Status of ???</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2009/02/csm-probe-status-of/</link>
      <pubDate>Fri, 20 Feb 2009 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2009/02/csm-probe-status-of/</guid>
      <description>&lt;p&gt;I must be bored since I&amp;rsquo;m posting again.&lt;/p&gt;&#xA;&lt;p&gt;A colleague asked me to change the failed value of a TCP probe today.  It was no big deal, but, when I looked to see the status of the change, I noticed interesting stati of the RIPs.&lt;/p&gt;&#xA;&lt;blockquote&gt;&#xA;&lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; class=&#34;chroma&#34;&gt;&lt;code data-lang=&#34;fallback&#34;&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;switch#sh mod csm 7 probe name TCP80-PROBE detail&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;probe           type    port  interval retries failed  open   receive&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;---------------------------------------------------------------------&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;TCP80-PROBE  tcp     80    20       3       120     10&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;Description: Quick fail recovery&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;recover = 3&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;real                  vserver         serverfarm      policy          status&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;------------------------------------------------------------------------------&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;192.168.1.45:80       VS01            FARM01        (default)       ???&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;192.168.1.44:80       VS01            FARM01        (default)       ???&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;192.168.1.43:80       VS01            FARM01        (default)       ???&#xA;&lt;/span&gt;&lt;/span&gt;&lt;span class=&#34;line&#34;&gt;&lt;span class=&#34;cl&#34;&gt;192.168.1.42:80       VS01            FARM01        (default)       ???&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/blockquote&gt;&#xA;&lt;p&gt;It seems that when a change is made to a probe, the CSM discards the state of the probe and starts over.  If you catch it before the first probe is finished, you&amp;rsquo;ll get a status of &amp;ldquo;???&amp;quot;.  I&amp;rsquo;m just picturing the CSM saying &amp;ldquo;Uhh&amp;hellip;I&amp;hellip;don&amp;rsquo;t&amp;hellip;know&amp;rdquo;.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Fail Actions on CSM Serverfarms</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2009/02/fail-actions-on-csm-serverfarms/</link>
      <pubDate>Fri, 20 Feb 2009 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2009/02/fail-actions-on-csm-serverfarms/</guid>
      <description>&lt;p&gt;I&amp;rsquo;ve talked about &lt;a href=&#34;http://aconaway.com/2008/11/06/using-probes-on-the-csm/&#34; title=&#34;AConaway.com -- Using Probes on the CSM&#34;&gt;probes&lt;/a&gt; and stuff on the CSM, but I never mentioned what happens to the connections to a server that fails.  That is, if I&amp;rsquo;m connected to server A in a cluster and that server suddenly commits &lt;a href=&#34;http://en.wikipedia.org/wiki/Seppuku&#34; title=&#34;Wikipedia.com -- Seppuku&#34;&gt;ritual seppuku&lt;/a&gt;, what happens to my connection through the CSM?&lt;/p&gt;&#xA;&lt;p&gt;Remember how the CSM works?  You connect to the VIP, some state tables are updated, your packet&amp;rsquo;s destination IP is changed to a RIP, and the packet is forwarded.  The point I want to emphasize this time is the state table.  If you were to send another packet to the same VIP on the same port, the CSM would look in its state table and see that you&amp;rsquo;re already connected to a server and just forward you on over after a NAT.  What if that server has suddenly died?&lt;/p&gt;</description>
    </item>
    <item>
      <title>Configuring Dedicated Trunks for the CSM</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2008/11/configuring-dedicated-trunks-for-the-csm/</link>
      <pubDate>Mon, 24 Nov 2008 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2008/11/configuring-dedicated-trunks-for-the-csm/</guid>
      <description>&lt;p&gt;Did you catch the article on &lt;a href=&#34;http://aconaway.com/2008/10/10/configuring-fault-tolerance-on-the-csm/&#34; title=&#34;AConaway.com -- Configuring Fault Tolerance on the CSM&#34;&gt;setting up fault tolerance on the CSM&lt;/a&gt;?  In that article, I mentioned that Cisco recommends a dedicated trunk for the FT VLAN if you have two HA CSMs in two chassis.  Discuss amongst yourselves while I drone on.&lt;/p&gt;&#xA;&lt;p&gt;Why should you set up a dedicated trunk for this stuff?  The most obvious reason is to be sure that normal traffic doesn&amp;rsquo;t step on the syncing traffic.  Since we&amp;rsquo;re syncing state information as well as configuration, the frames need to arrive in a timely manner.  Any errors could potentially disrupt the FT process, which is bad.  You surely don&amp;rsquo;t want the primary to fail only to find out that the standby doesn&amp;rsquo;t have the complete or current config.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Using Probes on the CSM</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2008/11/using-probes-on-the-csm/</link>
      <pubDate>Thu, 06 Nov 2008 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2008/11/using-probes-on-the-csm/</guid>
      <description>&lt;p&gt;There are three different ways that a CSM checks for the health of the servers &amp;ndash; active probes, inband health checking, and inband HTTP monitoring.  Let&amp;rsquo;s talk about active probes.&lt;/p&gt;&#xA;&lt;p&gt;Active probes (or just probes) typically send traffic to one of the RIPs of a serverfarm, do some stuff, and give a pass or fail grade.  If the probe fails a certain number of times in a row, that server is considered sick and taken out of the pool for use.  The CSM keeps checking the unhealthy until it passes a number of times in a row, at which point it is placed back in the pool for use.  Almost everything is configurable, of course, so let&amp;rsquo;s look at some of those settings.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Configuring Fault Tolerance on the CSM</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2008/10/configuring-fault-tolerance-on-the-csm/</link>
      <pubDate>Fri, 10 Oct 2008 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2008/10/configuring-fault-tolerance-on-the-csm/</guid>
      <description>&lt;p&gt;Like (nearly) everything in the Cisco world, you can set up your CSM to fail over to another module when the primary dies a horrible death.  You can have two in the same chassis or even have them in separate chassis &amp;ndash; the process is the same no matter how you have it set up.  Either way, you have a primary and a secondary module in fault tolerance (FT) mode.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Running Multiple Data Centers on a Stick with the CSM</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2008/08/running-multiple-data-centers-on-a-stick-with-the-csm/</link>
      <pubDate>Tue, 12 Aug 2008 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2008/08/running-multiple-data-centers-on-a-stick-with-the-csm/</guid>
      <description>&lt;p&gt;That&amp;rsquo;s an awesome title, eh?  I&amp;rsquo;ve mentioned a &lt;a href=&#34;http://aconaway.com/2007/08/20/router-on-a-stick/&#34; title=&#34;AConaway.com -- Router on a Stick&#34;&gt;router-on-a-stick&lt;/a&gt; before but not a data-center-on-a-stick (DCOAS).  This is one of those Cisco terms I ran across a while ago and is a group of servers sort of sticking out on their own behind a load balancer and/or firewall.  Connections to and from the server group go through a single spoke &amp;ndash; kinda like stubby routing.  Here&amp;rsquo;s a pretty picture.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Backup Servers on the CSM</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2008/06/backup-servers-on-the-csm/</link>
      <pubDate>Thu, 26 Jun 2008 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2008/06/backup-servers-on-the-csm/</guid>
      <description>&lt;p&gt;On the CSM, you can configure a &lt;em&gt;vserver&lt;/em&gt; to use a main and backup &lt;em&gt;serverfarm&lt;/em&gt; which is used if a serverfarm is toast.  If all the RIPs in the main farm are out-of-service, the CSM will start to treat the backup farm just as if it&amp;rsquo;s configured to be the main one.  Once one or more of the main farm RIPs have recovered, the CSM reverts back and uses those again.  &amp;ldquo;Give me an example when I&amp;rsquo;d use it!,&amp;rdquo; you say?  Since the CSM is made for HTTP connections, we&amp;rsquo;ll assume that you are using it for such. &lt;/p&gt;</description>
    </item>
    <item>
      <title>Intro to Policies on the CSM</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2008/06/intro-to-policies-on-the-csm/</link>
      <pubDate>Mon, 23 Jun 2008 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2008/06/intro-to-policies-on-the-csm/</guid>
      <description>&lt;p&gt;The &lt;a href=&#34;http://aconaway.com/category/cisco/csm/&#34; title=&#34;AConaway.com -- Category:CSM&#34;&gt;CSM&lt;/a&gt; is pretty bad little box.  It not only watches layer 4 items like TCP connections, but also talks HTTP, which you can use to do some custom, or policy-based, load balancing.&lt;/p&gt;&#xA;&lt;p&gt;Policies are the objects that make custom balancing work.  Like everything else (it seems) on the CSM, a policy is an object made up of other objects &amp;ndash; &lt;em&gt;maps&lt;/em&gt; and &lt;em&gt;serverfarms&lt;/em&gt;.  A &lt;em&gt;map&lt;/em&gt; matches patterns based on a number of things including the URL and HTTP header values, while the &lt;em&gt;serverfarm&lt;/em&gt; directive tells where to send traffic that matches the &lt;em&gt;map&lt;/em&gt;.  If, for example, you want to send all requests with &amp;ldquo;/admin&amp;rdquo; in the URL to a management server instead of the regular web servers, you can do it with a policy.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Getting Something Out of the CSM</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2008/06/getting-something-out-of-the-csm/</link>
      <pubDate>Tue, 10 Jun 2008 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2008/06/getting-something-out-of-the-csm/</guid>
      <description>&lt;p&gt;My buddy told me that my site is the only place on the web with documentation on the Cisco &lt;a href=&#34;http://aconaway.com/2007/10/02/getting-started-with-the-cisco-csm/&#34; title=&#34;AConaway.com -- Getting Started with the CSM&#34;&gt;Content Switching Module (CSM)&lt;/a&gt;. I also noticed a few months ago that every TAC case I&amp;rsquo;ve opened on the CSM has been handled by the same guy. I seriously think that the only people in the world that really know about these things are me and him. Cool. I better get some more content up.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Monitoring the CSM with SNMP</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2007/10/49/</link>
      <pubDate>Wed, 24 Oct 2007 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2007/10/49/</guid>
      <description>&lt;p&gt;I had an &lt;a href=&#34;http://aconaway.com/2007/10/02/getting-started-with-the-cisco-csm/&#34; title=&#34;AConaway -- Getting Started with the Cisco CSM&#34;&gt;article&lt;/a&gt; a few weeks ago about the Cisco CSM, which is a load-balancer module for the 6500 series switches. This thing is a pretty good device, but monitoring the connections to each VIP and RIP is not very straightforward. If you have an SNMP monitoring system like &lt;a href=&#34;http://cacti.net/&#34; title=&#34;Cacti -- Home Page&#34;&gt;Cacti&lt;/a&gt; or &lt;a href=&#34;http://oss.oetiker.ch/mrtg/&#34; title=&#34;MRTG -- Home Page&#34;&gt;MRTG&lt;/a&gt;, you need to know the OID to monitor, but it doesn&amp;rsquo;t work like anything else in the world.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Getting Started with the Cisco CSM</title>
      <link>https://a996c8ee.aww-3cz.pages.dev/posts/2007/10/getting-started-with-the-cisco-csm/</link>
      <pubDate>Wed, 03 Oct 2007 00:00:00 +0000</pubDate>
      <guid>https://a996c8ee.aww-3cz.pages.dev/posts/2007/10/getting-started-with-the-cisco-csm/</guid>
      <description>&lt;p&gt;Cisco&amp;rsquo;s Content Switching Module (CSM) is an application accelerator. Or is it an application networking service module? I hate those fancy buzzwords &amp;ndash; it&amp;rsquo;s a load balancer. It&amp;rsquo;s a module for the 6500 series switches that lets you load balance services in any VLAN and can also be set up for high-availability. I could go on for a while about the features, but let&amp;rsquo;s keep it simple for now. A short tutorial, if you will.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
