-
reverse proxy skype for business AX1030
Hi, I'm hoping someone can direct me to a guide or blog that can help me setup a reverse proxy instance for our on-prem Skype for Business setup. I found an older guide for the AX series, but it's for lync running on windows server 2008. I recently upgraded to Skype4Bus 2015 & it's running on windows server 2012 STD…
-
Centralized web server log on AX
Posted by ddesmidt A customer just asked me today an interesting question: Instead of looking at the web logs individually on each server, why not using the AX to create the web logs and send these to an external centralized syslog server. Note: They used the w3c format, but actually as you know aFleX is pretty flexible…
-
SSL offloading with SharePoint 2016 farm
We have been testing a new farm and the A-10 Thunder Series load balancer and while it seems to be working for the most part we do have problems with some pages not drawing: they don't complete the load. I have noticed browser session in debug shows SEC7111: HTTPS security is compromised by http://... We have no Alternate…
-
MIB Access for monitoring software
Hello, I'm a member of the Prometheus[0] monitoring project. We provide support for monitoring a wide variety of systems. In order to support monitoring of devices that support SNMP, we have to create a config file to translate SNMP OIDs into Prometheus metrics. We have a tool that automatically generates these configs…
-
GSLB between two different HW/SW Models
Hello all, Is it possible to run GSLb between two different HW? and two different ACOS ?
-
Way to accelerate an internet application using A10 ADC
Hi All, Im looking for a way to optimize an application that's on internet by having a local ADC to "intercept" the traffics from client , probably through client amending their host FQDN file pointing to A10 ADC instead of directly hitting www.example.com. Is that possible ? Attached with high level concept. Highly likely…
-
Configure Auto-Translate Port
Hi ! i try to create a Range for Auto Port translation for Oracle Web App (port 7777). I dont see this option! :/ I have ACOS 2.7.2-P10(build: 86) - TH1030S " To configure Auto-Translate Port: 1. Select Confi g Mode > Service > SLB 2. On the menu bar, select Global > Auto Translation 3. Click on one of the range names. The…
-
Load Balance Link with Health Monitor Compound method
I want to create health monitor compound (and,or,not)for checking MPLS link for all site 1 if site2-link1 has down all site use link2 only. I create health-monitor with(sub site1-link1 sub site2-link1 sub site3-link1 and and and) and it work. 2 if site2 down two link site1 and site3 use 2 link same normal. 3 if site2 down…
-
URL access restriction
Hi all, I'm working on a vThunder 2.7.2-P10 that is publicing many URL form a single virtual IP. Now I need to deny access from some IPs only for some URLs (not for all). For example I have 3 sites: site1.example.com site2.example.com site3.example.com And some IPs let's say: 1.2.3.4 1.2.3.5 1.2.3.6 I need those IPs can…
-
Configuring load balancing down to app. pool level
Hello, BACKGROUND: Our organization is using the A10 Thunder 3030S to load balance two Windows VM Servers (on the same VM host) that are hosting an IIS Web App. The load balancer is using a round robin algorithm with sticky sessions enabled (Source IP Persistence) between the client and server. ISSUE: Using the round robin…
-
Service IP health status for remote GSLB slave
Hi - This is probably a stupid question, but I have a configuration of master > slave for our GSLB configuration. We do both GSLB and SLB on each device (different datacenters) as most people do. We do not do any health monitoring at the GSLB level specifically. We want to rely on the up/down status of the VIP itself. Here…
-
Ansible and A10 Networks
If you are operating an infrastructure with Ansible and are looking for A10 Networks modules, have a look at this Ansible Fork. It has not been scheduled to be included as it needs some airtime. You can try this out on ACOS 2.7.1 and higher as it needs aXAPI 2.1. When you find anything that is not working please let me…
-
Link Load Balance A10 Thunder
Hi Everyone! I would like to know, what is the best form to make load balance on my A10 if i have 3 ISP links. Example LOCAL NET ---> Inside -- A10 --Outside ----3 ISP links i understand that is with a Wildcard VS, but i would like be sure of that. Please if you can help me.
-
outbound nat based on IP
I'm trying to configure LLB for ISP links and having some trouble with the outbound NAT. Basically when it goes out ISP1 it should default to NAT pool ISP_C for most users, but when it comes from one range (using individual IP in my testing) it needs to use NAT pool ISP_CTHSE Under my 0.0.0.0 VIP this aflex works: when…
-
axdebug via axapi
Hi all, Does anybody know how to start/stop axdebug capture via axapi in ACOS 4.X? (Or if it's possible in the first place?) The reference manual only told me how to export capture files. I'm trying to automate whole our testing process and I'd like to know if I could do it all with axapi only (for now, I've managed to do…
-
VCS UNSYNC
Hi all. how can we force the synchronization. vcs reload not work Image attached. Thanks
-
GSLB Always returns all DNS records in service
Hi - Old F5 customer here making the switch over to A10 and I am finding either GSLB does not behave as I am accustomed to or I don't know what I am doing. Probably the latter. I have set up GSLB using sub zone delegation whereby we have a delegated subzone that forwards requests to my A10 devices. For example: CNAME…
-
GSLB Service Port
What is the significance of the GSLB service port? I have set up my service IP ports to match my SLB configuration. I understand that service IP ports are in place because they can be used for health checking. However, at the service level, it seems the port is kind of redundant and I have simply set up port 53 to match…
-
Carrier LLB aFlex
Posted by a10jliu We are using AX 3200 for certain ISP as LLB solutions. For LLB we need NAT sticky functionality similar to LSN to make sure certain NAT used during client-> server connections. So we achieve this by define single IP nat pools and naming them accordingly. Code: when CLIENT_ACCEPTED { #Drop some packet…
-
SNI and AFLEX
Hi all, I have a problem with aflex configured on a VIP with a SNI template applied. On the VIP I have exposed application for domain1 (the default certificate in the SSL template) and 2 services for domain2. SNI template i sworking fine but now I need to add on the VIP an aflex like this: #Rewrite if {[HTTP::host] matches…
-
HTTP Template Redirect Rewrite
Hi all, I'm trying to do Rewrite with an HTTP template but I can't understand how it works. I configured correctly the template to balance on the service group inside the app swithcing part but I also want to redirect as shown below: When client request www.example.com I want rewrite to example.com/pwm So my rule on the…
-
doubt about snat log
Hi Everyone, Actually i have a doubt about what that's exactly means the following entry on my ACOS system: Dec 07 2017 14:26:28 Warning [ACOS] Obtaining Address/Port from NAT Pool Nat-137 failed due to Honor Misses Dec 07 2017 14:24:01 Warning [ACOS] Obtaining Address/Port from NAT Pool Nat-Uss-2 failed due to Honor…
-
AXAPI: Determine when configuration last updated
Hi folks, I've been scouring the SDK documentation for the 4.1.x ADC code and have been unable to figure out how to determine the date time of the last configuration change. In the CLI I can run 'show running-config' and look at the top where it indicates when it was last updated and when it was last saved. In the earlier…
-
axapi wildcard
Hi all, I've begun to use the axapi. Here's the question: First, I got the authentification token. Then I'm seeking the virtual servers inforation. curl -k GET https://1...7/axapi/v3/slb/virtual-server -H "Content-Type:application/json" -H "Authorization: A10 3a7ff8596db0249f25761b09548437" I'm after the oper status of…
-
HTTP not work properly
Hello, we use A10 Thunder for SSL Inspection as Explicit Proxy. If the users use Internet Explorer or FireFox and they are browse http content which normaly gets redirect to https like http://www.google.de the site doest not load and the browser shows a proxy timeout error. If the user browse URLs which only exists at http…
-
Can Thunder SSLi bypass inspection by OU ?
Can Thunder SSLi bypass or not inspection by OU ?
-
WAF messages filter
Hi all, I've applied a WAF template on my vThunder (release 2.7.2-P10) to test the impact on my application. I also added a logging template to send messages to my log server and it is working fine. Is there a way to filter messages sent by the vThunder so only denied actions are logged? Thanks Luca
-
"certificate revocation list" and A10 Thunder
Hello, i Need to configure CRL on the A10 Thunder device. How the device handle the CRL list's? Is the device update the list or i have to do it myself? When the device update the CRL. How it works? Which protocol will be use?
-
DNS Firewall
Hi Team: Can you please list down series of attack tools that we can use to test the DNS firewall of A10?
-
Clustering A10's devices
Do we have a process of adding a secondary unit to current active standalone A10 device and bringing both on them into Active-Standby cluster? Are there any caveats to be noted ? Thanks, Abhi