


 



<?xml version="1.0"?>
<?xml-stylesheet type="text/css" href="http://docwiki.cisco.com/w/skins/common/feed.css?270"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>http://docwiki.cisco.com/w/index.php?title=FTP_Load_Balancing_on_ACE_in_One-Arm_Mode_Configuration_Example&amp;feed=atom&amp;action=history</id>
		<title>FTP Load Balancing on ACE in One-Arm Mode Configuration Example - Revision history</title>
		<link rel="self" type="application/atom+xml" href="http://docwiki.cisco.com/w/index.php?title=FTP_Load_Balancing_on_ACE_in_One-Arm_Mode_Configuration_Example&amp;feed=atom&amp;action=history"/>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=FTP_Load_Balancing_on_ACE_in_One-Arm_Mode_Configuration_Example&amp;action=history"/>
		<updated>2013-06-18T23:25:13Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.16.0</generator>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=FTP_Load_Balancing_on_ACE_in_One-Arm_Mode_Configuration_Example&amp;diff=24586&amp;oldid=prev</id>
		<title>Docwikibot: Bot: Adding {{Template:Required Metadata}}</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=FTP_Load_Balancing_on_ACE_in_One-Arm_Mode_Configuration_Example&amp;diff=24586&amp;oldid=prev"/>
				<updated>2009-12-18T17:29:57Z</updated>
		
		<summary type="html">&lt;p&gt;Bot: Adding {{Template:Required Metadata}}&lt;/p&gt;
&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
			&lt;col class='diff-marker' /&gt;
			&lt;col class='diff-content' /&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='2' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 17:29, 18 December 2009&lt;/td&gt;
		&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot;&gt;&amp;nbsp;&lt;/td&gt;&lt;td class='diff-marker'&gt;+&lt;/td&gt;&lt;td style=&quot;background: #cfc; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;color: red; font-weight: bold; text-decoration: none;&quot;&gt;{{Template:Required Metadata}}&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;==Goal==&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;==Goal==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;The goal of this document is to configure an ACE Module or ACE 4710 to perform FTP load balancing in a one-arm topology.&amp;nbsp; It will cover the basics of the FTP protocol, and explain why specific configuration elements are necessary to allow FTP to function.&lt;/div&gt;&lt;/td&gt;&lt;td class='diff-marker'&gt; &lt;/td&gt;&lt;td style=&quot;background: #eee; color:black; font-size: smaller;&quot;&gt;&lt;div&gt;The goal of this document is to configure an ACE Module or ACE 4710 to perform FTP load balancing in a one-arm topology.&amp;nbsp; It will cover the basics of the FTP protocol, and explain why specific configuration elements are necessary to allow FTP to function.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>Docwikibot</name></author>	</entry>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=FTP_Load_Balancing_on_ACE_in_One-Arm_Mode_Configuration_Example&amp;diff=7906&amp;oldid=prev</id>
		<title>Pzimmerm: 1 revision</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=FTP_Load_Balancing_on_ACE_in_One-Arm_Mode_Configuration_Example&amp;diff=7906&amp;oldid=prev"/>
				<updated>2008-12-04T18:37:28Z</updated>
		
		<summary type="html">&lt;p&gt;1 revision&lt;/p&gt;
&lt;table style=&quot;background-color: white; color:black;&quot;&gt;
		&lt;tr valign='top'&gt;
		&lt;td colspan='1' style=&quot;background-color: white; color:black;&quot;&gt;← Older revision&lt;/td&gt;
		&lt;td colspan='1' style=&quot;background-color: white; color:black;&quot;&gt;Revision as of 18:37, 4 December 2008&lt;/td&gt;
		&lt;/tr&gt;&lt;/table&gt;</summary>
		<author><name>Pzimmerm</name></author>	</entry>

	<entry>
		<id>http://docwiki.cisco.com/w/index.php?title=FTP_Load_Balancing_on_ACE_in_One-Arm_Mode_Configuration_Example&amp;diff=7905&amp;oldid=prev</id>
		<title>Pzimmerm: Initial posting</title>
		<link rel="alternate" type="text/html" href="http://docwiki.cisco.com/w/index.php?title=FTP_Load_Balancing_on_ACE_in_One-Arm_Mode_Configuration_Example&amp;diff=7905&amp;oldid=prev"/>
				<updated>2008-12-03T20:39:22Z</updated>
		
		<summary type="html">&lt;p&gt;Initial posting&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;==Goal==&lt;br /&gt;
The goal of this document is to configure an ACE Module or ACE 4710 to perform FTP load balancing in a one-arm topology.  It will cover the basics of the FTP protocol, and explain why specific configuration elements are necessary to allow FTP to function.&lt;br /&gt;
&lt;br /&gt;
==FTP Protocol Basics==&lt;br /&gt;
&lt;br /&gt;
FTP is a protocol which allows client PCs running FTP client software, to transfer files to and from a remote FTP server.  An FTP session is itself composed of two TCP flows, each with a very specific role.  The first flow is created as the user initiates the FTP connection to the server.  It is used to pass FTP commands (such as GET, PUT, etc) back and forth between the client and server, and is known as the control channel.  This flow is always sourced from the client PC, with the destination being the FTP server (generally TCP port 21), never the other way around.  The next TCP flow is known as the data channel, and it is created when data needs to flow between the client and the server (file copies, directory listings, etc).  This flow can be established in either direction, depending on whether ACTIVE FTP or PASSIVE FTP is being used.  To establish the data connection during an Active FTP session, the server initiates the TCP connection to the client PC.  To establish the data connection during a Passive FTP session, the client initiates the TCP connection to the FTP Server.  It is important to note that when an FTP session authenticates properly but then hangs on directory listings or file transfers, generally some piece of network equipment is preventing the data channel from being properly established.&lt;br /&gt;
&lt;br /&gt;
==Design==&lt;br /&gt;
&lt;br /&gt;
Clients will establish an FTP control channel connection with the VIP configured on the ACE.  Once established, the ACE will forward the control connection to one of the configured real servers.  The ACE will inspect the commands being sent through the control connection, and will take action as necessary to ensure the data connection can also be established between the client and the server in the appropriate direction when necessary.  Generally this will involve performing NAT on the IP addresses embedded within the FTP control channel messages, as well as opening any necessary ports in the ACE access-lists.  The ACE will also source nat the request as it is passed to the real server.  This will ensure that the server response is sent back to the ACE, rather than being sent through the MSFC, bypassing the ACE completely.  Only the TCP port for the control channel must be explicitly permitted in the ACE access-list.  The TCP port for the data channel is dynamically assigned by the client or server (depending on which FTP mode is used), and ACE will open a pin-hole in its access-list to allow traffic through to the real server on this port.&lt;br /&gt;
&lt;br /&gt;
[[Image:FTP load balancing-3.jpg]]&lt;br /&gt;
 &lt;br /&gt;
==Configuration==&lt;br /&gt;
&lt;br /&gt;
The ACE configuration is performed in a layered fashion, making the order it is built in important.  Each configuration step builds upon the previous step; the order this document will follow is outlined below.&lt;br /&gt;
* Configure a management policy to allow admin access to the ACE&lt;br /&gt;
* Configure access-list to permit traffic into the ACE from the client facing interface&lt;br /&gt;
* Define real server addresses (create the rservers)&lt;br /&gt;
* Group rservers together (create a serverfarm)&lt;br /&gt;
* Define the virtual address (VIP)&lt;br /&gt;
* Define how traffic is to be handled once it is received (L7 policy-map)&lt;br /&gt;
* Associate traffic handling policy with VIP address (multi-match policy)&lt;br /&gt;
* Create VLAN interface and net-pool, then apply service-policy, access-list, and management policy to it&lt;br /&gt;
* Add a default route&lt;br /&gt;
&lt;br /&gt;
To begin the configuration, configure a management policy-map to allow all types of management access to the ACE.  This policy will be applied to the necessary interface in a later step.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;ACE-1/onearm(config)# policy-map type management first-match remote-access&lt;br /&gt;
ACE-1/onearm(config-pmap-mgmt)# class class-default&lt;br /&gt;
ACE-1/onearm(config-pmap-mgmt-c)# permit&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next configure an access-list to permit the desired traffic to enter the ACE.  Before the traffic can reach any configured virtual servers, it must be permitted by an access-list.&lt;br /&gt;
Note:  While this example shows a “permit any any”, it is recommend ACLs be used to only permit specific traffic through the ACE. &lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;ACE-1/onearm(config)# access-list everyone extended permit ip any any&lt;br /&gt;
ACE-1/onearm(config)# access-list everyone extended permit icmp any any &amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The ultimate goal of this configuration is for ACE to distribute FTP connections to a group of real servers.  The ACE must have each of these real servers configured as rservers, so that it knows each of their IP addresses.  Note that unlike previous SLB products, a TCP/UDP port is NOT specified during this step; it will be defined when the rservers are added to a serverfarm.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;ACE-1/onearm(config)# rserver host lnx1&lt;br /&gt;
ACE-1/onearm(config-rserver-host)# ip address 192.168.5.11&lt;br /&gt;
ACE-1/onearm(config-rserver-host)# inservice&lt;br /&gt;
ACE-1/onearm(config-rserver-host)# rserver host lnx2&lt;br /&gt;
ACE-1/onearm(config-rserver-host)# ip address 192.168.5.12&lt;br /&gt;
ACE-1/onearm(config-rserver-host)# inservice	&lt;br /&gt;
ACE-1/onearm(config-rserver-host)# rserver host lnx3&lt;br /&gt;
ACE-1/onearm(config-rserver-host)# ip address 192.168.5.13&lt;br /&gt;
ACE-1/onearm(config-rserver-host)# inservice&lt;br /&gt;
ACE-1/onearm(config-rserver-host)# rserver host lnx4&lt;br /&gt;
ACE-1/onearm(config-rserver-host)# ip address 192.168.5.14&lt;br /&gt;
ACE-1/onearm(config-rserver-host)# inservice&lt;br /&gt;
ACE-1/onearm(config-rserver-host)# rserver host lnx5&lt;br /&gt;
ACE-1/onearm(config-rserver-host)# ip address 192.168.5.15&lt;br /&gt;
ACE-1/onearm(config-rserver-host)# inservice&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The rservers must be grouped into a serverfarm, accomplishing two things.  It allows the whole group of rservers to be attached to any load balancing actions with a single command, and it provides an opportunity to define the port on which the rservers are configured to accept traffic.&lt;br /&gt;
&lt;br /&gt;
{{note|In this example, no port is configured on the rservers.  This instructs the ACE to inherit the port from the virtual server which will be defined in a later step.}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;ACE-1/onearm(config)# serverfarm host ftp&lt;br /&gt;
ACE-1/onearm(config-sfarm-host)# rserver lnx1&lt;br /&gt;
ACE-1/onearm(config-sfarm-host-rs)# inservice&lt;br /&gt;
ACE-1/onearm(config-sfarm-host-rs)# rserver lnx2&lt;br /&gt;
ACE-1/onearm(config-sfarm-host-rs)# inservice&lt;br /&gt;
ACE-1/onearm(config-sfarm-host-rs)# rserver lnx3&lt;br /&gt;
ACE-1/onearm(config-sfarm-host-rs)# inservice&lt;br /&gt;
ACE-1/onearm(config-sfarm-host-rs)# rserver lnx4&lt;br /&gt;
ACE-1/onearm(config-sfarm-host-rs)# inservice&lt;br /&gt;
ACE-1/onearm(config-sfarm-host-rs)# rserver lnx5&lt;br /&gt;
ACE-1/onearm(config-sfarm-host-rs)# inservice&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
In order for the ACE to accept traffic on a virtual server IP, it must be configured using a class-map.  In this example the VIP address is configured to accept traffic on TCP port 21, the standard port for FTP control channel connections.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;ACE-1/onearm(config)# class-map match-all slb-vip&lt;br /&gt;
ACE-1/onearm(config-cmap)# 2 match virtual-address 172.16.5.103 tcp eq ftp&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Once the ACE accepts traffic destined to the virtual address, it must be told how to handle the traffic.  This is accomplished by configuring an L7 policy-map.  In this example the policy-map is configured to match all traffic (class-default matches anything), and to send it to the ftp serverfarm.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;ACE-1/onearm(config)# policy-map type loadbalance first-match slb&lt;br /&gt;
ACE-1/onearm(config-pmap-lb)# class class-default&lt;br /&gt;
ACE-1/onearm(config-pmap-lb-c)# serverfarm ftp&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The final “glue” which ties all of the previous steps together, is the multi-match policy.  It can contain multiple class references; each would be configured with a different VIP address.  In this case only one class is referenced, instructing the ACE to only accept traffic destined to the single VIP address.  The class reference also references the L7 policy-map, and a command to put the VIP in service.&lt;br /&gt;
&lt;br /&gt;
{{caution|Since this configuration is an example of FTP load balancing, the class reference also contains the “inspect ftp” command.  It instructs the ACE to inspect the FTP control channel commands, and perform any necessary fixups to allow the data channel to establish properly.  Without this command, FTP load balancing '''WILL NOT WORK!'''}}&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;ACE-1/onearm(config)# policy-map multi-match client-vips&lt;br /&gt;
ACE-1/onearm(config-pmap)# class slb-vip&lt;br /&gt;
ACE-1/onearm(config-pmap-c)# loadbalance vip inservice&lt;br /&gt;
ACE-1/onearm(config-pmap-c)# loadbalance policy slb&lt;br /&gt;
ACE-1/onearm(config-pmap-c)# inspect ftp&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
At this point the traffic handling logic is completely defined within the configuration.  The final step is to apply this logic to the interfaces of the ACE.  The following steps create the one-arm VLAN interface, and apply the multi-match policy and access-list to it.  A NAT pool is also added to the interface, to allow the ACE to source nat the client requests.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;ACE-1/onearm(config)# interface vlan 50&lt;br /&gt;
ACE-1/onearm(config-if)# description “Client-Server VLAN”&lt;br /&gt;
ACE-1/onearm(config-if)# ip address 172.16.5.5 255.255.255.0&lt;br /&gt;
ACE-1/onearm(config-if)# nat-pool 5 172.16.5.200 172.16.5.209 netmask 255.255.255.0 pat&lt;br /&gt;
ACE-1/onearm(config-if)# access-group input everyone&lt;br /&gt;
ACE-1/onearm(config-if)# service-policy input client-vips&lt;br /&gt;
ACE-1/onearm(config-if)# service-policy input remote-access&lt;br /&gt;
ACE-1/onearm(config-if)# no shutdown&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Next, apply the nat-pool which was configured.  The nat-pool is applied to the class reference within the multi-match policy.  This instructs the ACE to source NAT all client requests destined for the VIP address.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;ACE-1/onearm(config)# policy-map multi-match client-vips&lt;br /&gt;
ACE-1/onearm(config-pmap)# class slb-vip&lt;br /&gt;
ACE-1/onearm(config-pmap-c)# nat dynamic 5 vlan 50&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The last step is to add a default route.  This allows the ACE to be reachable from remote networks, and allows the ACE to return traffic to distant clients.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;ACE-1/onearm(config)# ip route 0.0.0.0 0.0.0.0 172.16.5.1&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
Related show Commands&lt;br /&gt;
&lt;br /&gt;
The following command can be used to verify that both the control channel and the data channel were successfully established.  In this example conn-id 3 illustrates the control channel being established from the client to the VIP on TCP port 21, and conn-id 19 illustrates the data channel being established from the VIP to the client on TCP port 4726.  The directionality of the data channel indicates that this is an active mode FTP session.  Note that normally the data channel is torn down immediately after use; in order to observe its behavior a long-running file transfer must be in progress.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;ACE-1/onearm# sho conn &lt;br /&gt;
total current connections : 4&lt;br /&gt;
conn-id    np dir proto vlan source                destination           state&lt;br /&gt;
----------+--+---+-----+----+---------------------+---------------------+------+&lt;br /&gt;
20         1  in  TCP   40   192.168.5.11:20       209.165.201.11:4726   ESTAB&lt;br /&gt;
19         1  out TCP   20   209.165.201.11:4726   172.16.5.103:20       ESTAB&lt;br /&gt;
3          2  in  TCP   20   209.165.201.11:2045   172.16.5.103:21       ESTAB&lt;br /&gt;
18         2  out TCP   40   192.168.5.11:21       209.165.201.11:2045   ESTAB&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
The following command can be used to observe the behavior of the FTP inspection engine.  The hit count should increase over time, and dropped connections should not increment.&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;ACE-1/onearm# show service-policy client-vips detail&lt;br /&gt;
Status     : ACTIVE&lt;br /&gt;
Description: -&lt;br /&gt;
-----------------------------------------&lt;br /&gt;
Interface: vlan 50 &lt;br /&gt;
  service-policy: client-vips&lt;br /&gt;
    class: slb-vip&lt;br /&gt;
     VIP Address:    Protocol:  Port:&lt;br /&gt;
     172.16.5.103    tcp        eq    21   &lt;br /&gt;
      loadbalance:&lt;br /&gt;
        L7 loadbalance policy: slb&lt;br /&gt;
        VIP Route Metric     : 77&lt;br /&gt;
        VIP Route Advertise  : DISABLED&lt;br /&gt;
        VIP ICMP Reply       : DISABLED&lt;br /&gt;
        VIP State: INSERVICE&lt;br /&gt;
        curr conns       : 0         , hit count        : 8         &lt;br /&gt;
        dropped conns    : 0         &lt;br /&gt;
        client pkt count : 169       , client byte count: 7771                &lt;br /&gt;
        server pkt count : 193       , server byte count: 12506               &lt;br /&gt;
        conn-rate-limit      : 0         , drop-count : 0         &lt;br /&gt;
        bandwidth-rate-limit : 0         , drop-count : 0         &lt;br /&gt;
        L7 Loadbalance policy : slb&lt;br /&gt;
          class/match : class-default&lt;br /&gt;
            LB action : &lt;br /&gt;
               primary serverfarm: ftp&lt;br /&gt;
                    state: UP&lt;br /&gt;
                backup serverfarm : -&lt;br /&gt;
            hit count        : 8         &lt;br /&gt;
            dropped conns    : 0         &lt;br /&gt;
      inspect ftp:&lt;br /&gt;
        L7 inspect policy : -&lt;br /&gt;
        strict ftp: DISABLED&lt;br /&gt;
        curr conns       : 0         , hit count        : 8         &lt;br /&gt;
        dropped conns    : 0         &lt;br /&gt;
        client pkt count : 169       , client byte count: 7771                &lt;br /&gt;
        server pkt count : 193       , server byte count: 12506               &lt;br /&gt;
        conn-rate-limit      : 0         , drop-count : 0         &lt;br /&gt;
        bandwidth-rate-limit : 0         , drop-count : 0   &amp;lt;/pre&amp;gt;    &lt;br /&gt;
&lt;br /&gt;
==Show running-config==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;pre&amp;gt;access-list everyone line 8 extended permit ip any any &lt;br /&gt;
access-list everyone line 16 extended permit icmp any any &lt;br /&gt;
&lt;br /&gt;
rserver host lnx1&lt;br /&gt;
  ip address 192.168.5.11&lt;br /&gt;
  inservice&lt;br /&gt;
rserver host lnx2&lt;br /&gt;
  ip address 192.168.5.12&lt;br /&gt;
  inservice&lt;br /&gt;
rserver host lnx3&lt;br /&gt;
  ip address 192.168.5.13&lt;br /&gt;
  inservice&lt;br /&gt;
rserver host lnx4&lt;br /&gt;
  ip address 192.168.5.14&lt;br /&gt;
  inservice&lt;br /&gt;
rserver host lnx5&lt;br /&gt;
  ip address 192.168.5.15&lt;br /&gt;
  inservice&lt;br /&gt;
&lt;br /&gt;
serverfarm host ftp&lt;br /&gt;
  rserver lnx1&lt;br /&gt;
    inservice&lt;br /&gt;
  rserver lnx2&lt;br /&gt;
    inservice&lt;br /&gt;
  rserver lnx3&lt;br /&gt;
    inservice&lt;br /&gt;
  rserver lnx4&lt;br /&gt;
    inservice&lt;br /&gt;
  rserver lnx5&lt;br /&gt;
    inservice&lt;br /&gt;
&lt;br /&gt;
class-map match-all slb-vip&lt;br /&gt;
  2 match virtual-address 172.16.5.103 tcp eq ftp&lt;br /&gt;
&lt;br /&gt;
policy-map type management first-match remote-access&lt;br /&gt;
  class class-default&lt;br /&gt;
    permit&lt;br /&gt;
&lt;br /&gt;
policy-map type loadbalance first-match slb&lt;br /&gt;
  class class-default&lt;br /&gt;
    serverfarm ftp&lt;br /&gt;
&lt;br /&gt;
policy-map multi-match client-vips&lt;br /&gt;
  class slb-vip&lt;br /&gt;
    loadbalance vip inservice&lt;br /&gt;
    loadbalance policy slb&lt;br /&gt;
    inspect ftp&lt;br /&gt;
    nat dynamic 5 vlan 50&lt;br /&gt;
&lt;br /&gt;
interface vlan 50&lt;br /&gt;
  description Client-Server VLAN&lt;br /&gt;
  ip address 172.16.5.5 255.255.255.0&lt;br /&gt;
  access-group input everyone&lt;br /&gt;
  nat-pool 5 172.16.5.200 172.16.5.209 netmask 255.255.255.0 pat&lt;br /&gt;
  service-policy input client-vips&lt;br /&gt;
  service-policy input remote-access&lt;br /&gt;
  no shutdown&lt;br /&gt;
&lt;br /&gt;
ip route 0.0.0.0 0.0.0.0 172.16.5.1&amp;lt;/pre&amp;gt;&lt;br /&gt;
&lt;br /&gt;
==Related Information==&lt;br /&gt;
[http://www.cisco.com/web/psa/products/index.html Technical Support &amp;amp; Documentation - Cisco Systems]&lt;br /&gt;
&lt;br /&gt;
&amp;lt;!--List links to related information--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
[[Category:Data Center Application Services Configuration Examples]]&lt;/div&gt;</summary>
		<author><name>Pzimmerm</name></author>	</entry>

	</feed>