-
Balance HTTPS traffic(without decryption)
Hi all! The task is to balance HTTPS traffic to 2 servers (TLS1 + TLS2), without decryption. How to configure the virtual server correctly in this case? The TLS|SSL processing itself will continue on TLS1+TLS2, i.e. you only need to do balancing 1.slb virtual-server VIP_HTTPS 192.168.195.2 port 443 https source-nat pool…
-
"Address already used for an interface" when changing IP address VIP
Hello, I need to change the address of the virtual server, it gives such an error. Reboot does not help.
-
Service IP unknown
Hello, I would like you to guide me a little. I have configured a site with GSLB and regarding the Service IP, when the configuration is finished the IP shows it in unknown state in the GUI, but it does respond to the ping. What can be happening? Is it missing to add something in the GSLB configuration? Thank you
-
Configure 3 sites with HTTPS and Wildcard Certificate
Hello, I need your help. We are setting up 3 GSLB websites which are set up with a wildcard certificate. So far only 2 websites work and one does not work since it throws an unsafe site. Added Client SSL and Server SSL, but a pool that has a real server with HTTP port 8080 appears as a non-secure site. If I remove the SSL…
-
Thunder A1040s - load balancer
Does Thunder A1040s supports reverse proxy? thanks.
-
Inter partition Routing
Hello I am trying to do a Inter partition Routing, i did two lv3 partitions, one partition has 1 port with the network 10.0.0.0/24 and the other partition has other port with the network 11.0.0.0/24 but when i do a ping it says network unreachable ! partition P_IPSEC-1 id 5 application-type adc ! partition P_VXLAN-1 id 6…
-
total connections
I want to see the total number of connections per VS server in a period of time in A10, how to view ?(for example, what is the total number of connections per IP in the past month)
-
Block harmful traffic or attack via Websocket traffic
Hi Experts, We have a web server is running some services via Websocket traffic. Now we want to block harmful traffic, attacks like SQL Injection, XSS... like the WAF template works with HTTP traffic, but now is WebSocket traffic. Could you give me a detail aflex script or WAF template to do that. (One more point, we…
-
Control CPU reaches 100 percent
Dear All, I m using A10 Thunder 1040. I observed that Control CPU is reaching 100 %. Please define What is control cpu? what is data cpu? How do I limit Control CPU for reaching 100 %. Would there be any impact on ADC functionality in case of 100% control CPU? Waiting for reply.
-
Virtual Server with 443 (HTTPS)
Dear, I am new to A10 and I need to create a virtual server with a service group and its real servers in 443. When I finish the configuration and test the site in the browser, it gives me the following: bad request Your browser sent a request that this server could not understand. Reason: You're speaking plain HTTP to an…
-
virtual-server with two service-group
Hi team I've a virtual server with a specify IP, but I need associate differentes service-group because the service will be use always the same IP. How I can associate for the same port (in my case 80) differents service-group for SLB? Thank you
-
CVE-2022-0778
A10 PSIRT says: To mitigate this issue for ACOS management plane, avoid importing / exporting files using the HTTPS transfer method. Does it include GUI operation, which ACOS works as HTTPS server and does not verify certification and accept EC parameters either.
-
Management port
Hi team Im new with ACOS software. How I can setup the management port and assign an address IP? Thanks,
-
Problem with ip nat pool configuration not deletable
Hi Everyone We have a problem with our TH1030S cluster(two TH1030S, VRRP-A and VCS). Advanced Core OS (ACOS) version 4.1.4-GR1, build 78 . I can't erase the following ip nat pool configuration. ip nat pool 172.17.12.0 172.17.12.11 172.17.12.30 netmask /24 ``` #no ip nat pool 172.17.12.0 NAT pool is in use. Try again after…
-
APPLICATION ACCESS MANAGEMENT Deployment
Hello everyone! I was asked by my company to provided a solution to deploy 2nd factor authentication for our web applications, without having to recode the application. I know there's some platforms as auth0 that can be used for this, but I'm just trying to find if it's possible to do it with the equipment that we already…
-
How to fix this issue for CVE-2011-1473
How to fix this issue for CVE-2011-1473
-
What is solution of A10 for API?
Hi everyone, Our customer have a web service system communicate with mobile app via API (RESTful API protocol). Now they want to a solution of A10 to support and protect this API. I have informed that is aXAPI, right? Please give me some advice about this issues Thanks
-
Microsoft Windows print spooler and any other Windows service health check Load Balance
Hi, anyone here know how to load balance printer spooler services in A10 ?
-
Command "trunk-group (id group) lacp" is not enable in partition
Hi experts, I have a trouble when i config in CLI the command "trunk-group" (ex: trunk-group 1 lacp) on Thunder 1030S device. It still actives in part shared, but not actives in part LV3. My configuraion is below: Netpo_Thunder_1030S#conf t Netpo_Thunder_1030S(config)#active-pa Netpo_Thunder_1030S(config)#active-partition…
-
SSL Secure Renegotiation
Hi, How configure SSL Secure renegotiation ? Regards
-
IIS + PHP + Chrome Issue
Hi! I try to load balance two PHP Servers, they are identical Php files. If use HTTPS L7 VIP every so often it experienced a logout. If use TCP L4 VIP every so often I get "server.com sent an invalid response" I try many Service Group Modes and persistence This only happens using Google Chrome Has anyone experienced…
-
http
Hey Guys, I need some help because I have some problem on ADC configuration, I have an external issl appliance perform the encryption and decryption(transparent), and im using a10 to forward the traffic to DLP through ICAP. When we configure tcp in SLB we can see the traffic passthrough a10, but when we configure HTTP we…
-
Unable to delete service-group
Please refer to the details below can delete unused service-group on standby device normally. l After a few days, I can delete several service groups, but there are still a few that can not be deleted. The same error message is displayed when deleting through gui. I think it may be related to current session. Oct 28 2021…
-
TACACS with Cisco ISE
I have been trying to set up TACACS authentication via Cisco ISE on an A10 ADC, but haven't been able to find much for configuration documentation, options and examples. Does anyone have any of these? Or know where I could find them? Any assistance would be greatly appreciated. Thanks
-
Servers and virtual servers
I want to ask if I can have the servers and slb virtual server from the same subnet ?
-
Functionally up
what does " Functionally up " mean for servers
-
Staging code on local device for upgrade
Good morning! We have several ADC devices that are scheduled for a code upgrade, some in far remote locations that are only accessible through trans-Atlantic WAN links. Is there a way to copy the code image file to the local device and install it from the device itself rather than specifying a remote location from which…
-
Transparent Device
Hey Guys, I need some help because I have some problem on ADC configuration, I have an external issl appliance perform the encryption and decryption(transparent), and im using a10 to forward the traffic to DLP through ICAP. When we configure tcp in SLB we can see the traffic passthrough a10, but when we configure HTTP we…
-
Console CLI is unavailable
We have several A10 Thunder 4440s that are unavailable via the console CLI. Upon connect, no login prompt appears and it appears to be in a sort of hung state. SSH connections work normally as expected. Is there a means of resetting the console CLI session so that login via console is available without rebooting the device?
-
IP NAT POOL Port Usage
It seems that the NAT POOL Port capacity of each ADC module is different? Who has the relevant calculation method? I want to design a sufficient POOL for my environment and have provided it for use.