Nortel Networks vrrp failover not working correctly alteon ad3

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
vrrp failover not working correctly alteon ad3 delusion39 08-15-06
Posted by delusion39 on August 15, 2006, 9:50 am
Please log in for more thread options
This is my first Alteon configuration, so I'm a newb to all of this.

Problem:

When failover Alteon(ad3) becomes master of virtual IPs (VSR IPs and VR
IP),
web requests are not able to route back to the web client.

The Alteon shows the session with the correct ips.
The web request is sent to the virtual server IP.
The real web server receives the web requests from the Alteon.
The server is still able to access the internet.
The Server receives the SYN transmissions, but SYN-ACK transmissions do
not trasmit back through the LB to the client.
VR MAC addresses are associated with all VR IPs. ARP tables in the
firewall and server reflect correct MAC addresses.

Config:

2 Alteons (ad3)
1 web server (for testing)
Primary alteon has 192.168.0.20 assigned to a physical interface
and enabled as a VR IP.
Secondary alteon uses 192.168.0.20 as a VR IP.
Server default gateway points to 192.168.0.20

Current physical layout:


|firewall| |firewall|
|         |
|         |
\ /
\ /
\ /
|switch|
| |
| |
/ \
/ \
|alteon| |alteon|
|         |
|         |
\ /
|switch|
|
|
|
|server|


It feels like I'm missing something simple. Any info would be
appreciated.

Thanks!


Posted by Dophi on August 15, 2006, 9:43 pm
Please log in for more thread options
You can try to create a VIR which's IP address is not the physical IP
address of any Alteon. This will help you solve this issue probably.


delusion39 wrote:
> This is my first Alteon configuration, so I'm a newb to all of this.
>
> Problem:
>
> When failover Alteon(ad3) becomes master of virtual IPs (VSR IPs and VR
> IP),
> web requests are not able to route back to the web client.
>
> The Alteon shows the session with the correct ips.
> The web request is sent to the virtual server IP.
> The real web server receives the web requests from the Alteon.
> The server is still able to access the internet.
> The Server receives the SYN transmissions, but SYN-ACK transmissions do
> not trasmit back through the LB to the client.
> VR MAC addresses are associated with all VR IPs. ARP tables in the
> firewall and server reflect correct MAC addresses.
>
> Config:
>
> 2 Alteons (ad3)
> 1 web server (for testing)
> Primary alteon has 192.168.0.20 assigned to a physical interface
> and enabled as a VR IP.
> Secondary alteon uses 192.168.0.20 as a VR IP.
> Server default gateway points to 192.168.0.20
>
> Current physical layout:
>
>
> |firewall| |firewall|
> |         |
> |         |
> \ /
> \ /
> \ /
> |switch|
> | |
> | |
> / \
> / \
> |alteon| |alteon|
> |         |
> |         |
> \ /
> |switch|
> |
> |
> |
> |server|
>
>
> It feels like I'm missing something simple. Any info would be
> appreciated.
>
> Thanks!


Posted by delusion39 on August 16, 2006, 10:59 am
Please log in for more thread options
No luck. Same issue. Thanks for the suggestion though.

Shaun

Dophi wrote:
> You can try to create a VIR which's IP address is not the physical IP
> address of any Alteon. This will help you solve this issue probably.
>
>
> delusion39 wrote:
> > This is my first Alteon configuration, so I'm a newb to all of this.
> >
> > Problem:
> >
> > When failover Alteon(ad3) becomes master of virtual IPs (VSR IPs and VR
> > IP),
> > web requests are not able to route back to the web client.
> >
> > The Alteon shows the session with the correct ips.
> > The web request is sent to the virtual server IP.
> > The real web server receives the web requests from the Alteon.
> > The server is still able to access the internet.
> > The Server receives the SYN transmissions, but SYN-ACK transmissions do
> > not trasmit back through the LB to the client.
> > VR MAC addresses are associated with all VR IPs. ARP tables in the
> > firewall and server reflect correct MAC addresses.
> >
> > Config:
> >
> > 2 Alteons (ad3)
> > 1 web server (for testing)
> > Primary alteon has 192.168.0.20 assigned to a physical interface
> > and enabled as a VR IP.
> > Secondary alteon uses 192.168.0.20 as a VR IP.
> > Server default gateway points to 192.168.0.20
> >
> > Current physical layout:
> >
> >
> > |firewall| |firewall|
> > |         |
> > |         |
> > \ /
> > \ /
> > \ /
> > |switch|
> > | |
> > | |
> > / \
> > / \
> > |alteon| |alteon|
> > |         |
> > |         |
> > \ /
> > |switch|
> > |
> > |
> > |
> > |server|
> >
> >
> > It feels like I'm missing something simple. Any info would be
> > appreciated.
> >
> > Thanks!


Posted by mlsnospam on August 17, 2006, 2:43 am
Please log in for more thread options
Are the Virtual MACS identical on both sides of the Alteons?
If yes, then are the switches in your diagram actually one switch with
multiple VLANS? Some switches don't support multiple bridge forward
tables, and duplicate MACS on separate VLANS becomes a problem.


Similar ThreadsPosted
vrrp failover not working correctly alteon ad3 August 15, 2006, 9:50 am
alteon and vrrp failover April 19, 2006, 12:57 pm
Transparent Failover support with Nortel Alteon Load balancers?? October 19, 2006, 4:53 am
Outbound CLID not showing correctly December 15, 2006, 12:05 pm
Outbound CLID not showing correctly December 15, 2006, 12:05 pm
Outbound CLID not showing correctly December 15, 2006, 12:04 pm
Outbound CLID not showing correctly December 15, 2006, 11:53 am
Outbound CLID not showing correctly December 15, 2006, 12:11 pm
Can VRRP be used when the servers are in same LAN as clients? October 28, 2006, 11:17 am
Nortel Contivity / VPN Router and VRRP Deactivate feature November 25, 2008, 10:05 am
M7000 Not Working March 26, 2005, 6:19 am
Busy to VM is not working. April 1, 2005, 1:37 pm
Norstar/Callpilot not working as hoped! May 4, 2007, 12:20 pm
Night Service not picking up StarTalk Not Working May 24, 2006, 5:33 pm
On the Meridian PBX X1126xxx was just the working title for Release 3., right? January 19, 2006, 7:00 pm