ACE Load Balancer SSL Certificate Part II: Install the SSL Certificate


ACE Load Balancer SSL Certificate Part II: Install the SSL Certificate


Once you´ve obtained an actual certificate from one of the Certificate Authorities, such as VeriSign or Thawte you may proceed to the certificate implementation.

As you may see on the picture below, the SSL certificate in this architecture ends on the ACE Load Balancer, therefore saving you the time and money needed to implement the certificate on each of the balanced Servers within the Server Farm behind the ACE Load Balancer.


The next step is performed on the Load Balancer, and it consists of identifying the KEY created and described in the first part of this guide. Once the right KEY is identified we need to EXPORT it and save it temporarily (I tend to simply paste it into the advanced hard-to-use Windows feature called "The Notepad").

LB_Active# crypto export CSRPPPREVOLRSAKEY.PEM

Within the same notepad file we should then paste the CERTIFICATE, so that it looks something like this:


-----BEGIN RSA PRIVATE KEY-----
MIIEowIBAAKCAQEAsXfx5rMSu+BM6XuE/ewBuhEa9fN57r7hpOmYL5lON5uguR+t
6F9l9h0TKGAF27q2szy/GIvpSvOWCPhEZ1SUB9SAfBpeZM47dCCqyC91GnKTXiVh
5w3YPK2A/WJur3DeHkzI4/4J8joe6G8PJAEgsmVJ6mclQU6EQ5HZhEZ1bQdMaBlY
LKRpRBvcZlIsYcw3mMDM9+9fVZNk3Ew8NA5iwZnjkyyxyJCnumXyxdfXEEK8024n
HVPbwtOMDT6KS4WMrIOZ8xelgHyfig7voqx0gjTffN81kFlAtxMTiuTme4d+OZ/O
K7luaT2arBffM66CGJZOi9fFUj3rSJHblnMZrQIDAQABAoIBAQCOaiLFb47pFeai
t2zSGEKKfo+UL/75iFSrcomeKPiLx2gDJ1j30RaRmmN1Uxlga0WSMH1pxV1BuJf+
Or0p7sWcQvuYm9CENLuhRVXHr83Zm3iHZJhcQs/0YYfRztvkDj8xMY1E6OgyalHD
VNxhmEYU4xOd94f+EHQzhSd47tHs20gP3vWnqFUg6jPQZkxsNVDkOLci13d0aayv
rXbKzFrM1+6FzAzg76Z+omLRD6f5fLOh8/d3UQele6bTYJjZhoYGtQFxWYxavG+M
EhSUyxDu9XohTzIlGKKqBdwkhPWiUB/KStG7VOPwqhdyGdIsd3a/OctmvyCffZtP
KjumtZIBAoGBAN8tCRAS/nOigK4Al2PAftk1ZamqMYjwnKOEQaNnKa2NGjoG4rX+
YJnM4P5shJGPZOQF0T2UwCcNNVvuaVh96B37IscVbancEHXWahzz4hm3ZheMuZnF
y5EQ9xPHTrqsGDHH3c+Wq0MKv5Cs/ttTImXz+5MLUQzaL4wN9lg95xR1AoGBAMuR
8kUbwsqsR4Mo7pdRdtD8HWZN53RcPEyNa1+YJs2JnGxr1qBezfbOFuY8Q1bnkii3
nPG78ChVVsmht54Wq/+lVKJkWOscPbHgfwv4jAVOZegl/wo1MzoIgu4Iva+hTN1B
V1CQCeOwqwQEnwe9m+eKKSC/K6PWOYtTgL8ntWlZAoGAVd9dSlsUn2favZkqp05N
QMSkDomXL8rtapmcLASo68eMXOGDYGW1w9gqhps4001qk7aNUXWoDh6t9mahEFS5
+LdGJXZgUOiFSOIsyGErEZwY41zZmYqbDoGJoImjCH7pfFYcSiD+WviKx19ZXQj7
BmG/3k+PazOU8f35WPDQtnUCgYBoIbwARfcanY3nNeT2WqGgvZZ8YpVnHFdsAVtP
hxEySpZNj8w2NMi+2yUzmNgJeGN3mJUbwrtSpnTCp4q5v3c0SmpEt3gUrFmSx/e1
M+rMPBI88lLH8fbGVNxEzwvY73XWKDp153hnlFOmtoZy+zbo9e+b5K56HHdLIefV
4IYX4QKBgCmbunIgF80jh8KjeTH6fSt46LZqgJTB5DpxCuxKfU52L/3ZEPfDmOxb
7/+GSZA76C7igjbpYl5g47pGf3aMEFHz2T4VfUmWTJ9OCIzYrBRlAxzMJQVIJpPu
Rj5n/iyg4kwUKCgBcQVIRho9PRYmqsqQqC3/xXhSfc6Pcjhw3Q2R
-----END RSA PRIVATE KEY-----
-----BEGIN CERTIFICATE-----
MIIFUzCCBDugAwIBAgIQEQb+49tSPm7wc6cPDoitLTANBgkqhkiG9w0BAQUFADCB
tTELMAkGA1UEBhMCVVMxFzAVBgNVBAoTDlZlcmlTaWduLCBJbmMuMR8wHQYDVQQL
ExZWZXJpU2lnbiBUcnVzdCBOZXR3b3JrMTswOQYDVQQLEzJUZXJtcyBvZiB1c2Ug
YXQgaHR0cHM6Ly93d3cudmVyaXNpZ24uY29tL3JwYSAoYykxMDEvMC0GA1UEAxMm
VmVyaVNpZ24gQ2xhc3MgMyBTZWN1cmUgU2VydmVyIENBIC0gRzMwHhcNMTIwNzE4
MDAwMDAwWhcNMTQwNzE5MjM1OTU5WjCBjDELMAkGA1UEBhMCRlIxDjAMBgNVBAgT
BVBBUklTMQ4wDAYDVQQHFAVQQVJJUzEkMCIGA1UEChQbR0lFIEFYQSBURUNITk9M
T0dZIFNFUlZJQ0VTMRgwFgYDVQQLFA9TRVJWSUNFIENPTlRST0wxHTAbBgNVBAMU
FHByZXZvbC5heGEtaXRhbGlhLml0MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIB
CgKCAQEAsXfx5rMSu+BM6XuE/ewBuhEa9fN57r7hpOmYL5lON5uguR+t6F9l9h0T
KGAF27q2szy/GIvpSvOWCPhEZ1SUB9SAfBpeZM47dCCqyC91GnKTXiVh5w3YPK2A
/WJur3DeHkzI4/4J8joe6G8PJAEgsmVJ6mclQU6EQ5HZhEZ1bQdMaBlYLKRpRBvc
ZlIsYcw3mMDM9+9fVZNk3Ew8NA5iwZnjkyyxyJCnumXyxdfXEEK8024nHVPbwtOM
DT6KS4WMrIOZ8xelgHyfig7voqx0gjTffN81kFlAtxMTiuTme4d+OZ/OK7luaT2a
rBffM66CGJZOi9fFUj3rSJHblnMZrQIDAQABo4IBhDCCAYAwHwYDVR0RBBgwFoIU
cHJldm9sLmF4YS1pdGFsaWEuaXQwCQYDVR0TBAIwADAOBgNVHQ8BAf8EBAMCBaAw
RQYDVR0fBD4wPDA6oDigNoY0aHR0cDovL1NWUlNlY3VyZS1HMy1jcmwudmVyaXNp
Z24uY29tL1NWUlNlY3VyZUczLmNybDBDBgNVHSAEPDA6MDgGCmCGSAGG+EUBBzYw
KjAoBggrBgEFBQcCARYcaHR0cHM6Ly93d3cudmVyaXNpZ24uY29tL2NwczAdBgNV
HSUEFjAUBggrBgEFBQcDAQYIKwYBBQUHAwIwHwYDVR0jBBgwFoAUDURcFlNEwYJ+
HSCrJfQBY9i+eaUwdgYIKwYBBQUHAQEEajBoMCQGCCsGAQUFBzABhhhodHRwOi8v
b2NzcC52ZXJpc2lnbi5jb20wQAYIKwYBBQUHMAKGNGh0dHA6Ly9TVlJTZWN1cmUt
RzMtYWlhLnZlcmlzaWduLmNvbS9TVlJTZWN1cmVHMy5jZXIwDQYJKoZIhvcNAQEF
BQADggEBAHtvROLZir+tNcJbX2q+zI+thJxqXqIX00DV8K7gHCjwqhon+jxRdj8Y
OiybDWHb32Ov5ZwyTVpRUkw64QSrhvpVtjI+q5pil4iE0QA2AtK/G8x3M8gFIaYW
pBBTE7loXfEk6hxVBXcrG13VT0vE60TLyFDvGrFPLAkVx9DhX36HM/gbmgBASEcN
CjE7a+g6eW4CT2fNkPkoE+uV4A4+7DVL7Q8W+ftGvrh6302d06Fkt8N3Ma8rsv0V
vqRzKyeVm6XWu1A+DOCNdUk3Fhpd82twDwfRwzjMqtbAJsXlYA/soBJDzvv3q5nm
Z/2Tgd4J4uGoqFLG3xlKVsGK/Y2ioZc=
-----END CERTIFICATE-----

Then we paste the entire Notepad file contect into the ACTIVE ACE Load Balancer using the command:

LBA_Active# crypto import terminal cisqueros.blogger.com
Please enter PEM formatted data. End with "quit" on a new line.
*** paste the Notepad Content HERE!!! ***

TIP: You have to import the SSL certificate into BOTH of the ACE Balancers (Active and Standby) before you save the configuration

Check the certificates using the command:

LBA_Active# show crypto certificate cisqueros.blogger.com

If you need to delete the old certificate before or after installing a new one, use the following command:

LBA_Active(config)# crypto delete CERTIFICATE_NAME

VTP - Should we use it?

VLAN Trunking Protocol: most commands can be configured in PRIVILEGED, CONFIGURE or DATABASE mode

- Have in mind that there is no way to dis-configure the VTP DOMAIN NAME (by default its NULL). You have to delete flash:vlan.dat and erase the Startup config and reload the router

VTP messages source IP (the IP from which the VTP messages are sourced):
(config)#vtp interface Loopback 1 [only] <- It will not be propagated

Restrict FLOOD TRAFFIC to the TRUNK Interfaces - use VTP PRUNING>
There are 4 types of VTP Advertisments exchanged between the switches:
1. Summary Advertisments - every time VTP database changes (every 300 ms)
2. Subset Advertisments - sent right after SUMMARY, includes what exactly changed
3. Advertisments requested from clients - client requests info to update the VTP database, server responds
4. VTP Membership announcements - when PRUNING is enabled, they tell the neighbor WHAT VLANs they want (if the VLAN is not announced with this message, it is not on the trunk)

Check the PRUNING STATUS:
#show interfaces pruning
Pruning not currently enabled in this device's VTP administrative domain.

ENABLE PRUNING>
#vtp pruning <--- PROPAGATED TO ALL SWITCHES WITHIN THE VTP DOMAIN
Pruning switched on

*VLAN 1 CANNOT BE PRUNED!!!
**VLANs that are used locally also CANNOT BE PRUNED

Spanning Tree: Root Election and Path Tuning



The concept is rather simple - The Switches send these probes called the BPDUs (Bridge Protocol Data Units) to discover loops in the network. If the BPDU “returns” – there is a loop in the network!

BPDU = 4-bit-PRIORITY + MAC Address

Spanning tree is no game, so be extremely careful when tuning the Priorities, Costs and Port-Priorities in order to manually make the Switch set your desired path as preferred. Each problem and mis-configuration can easily cause a major critical situation, as most of the Layer2 Loop Problems cause your Switches to immediately increase the CPU usage drastically. For your own stress-free dreams be sure to test in the Pre-Production environment everything you need to change in your production network regarding the Spanning Tree.
I´m not going to get into the explaining the Spanning Tree basics here, as I guess most of the CCIE candidates should be familiar with it. The focus of this post will be the pure control of the Root Bridge in your network, and the preferred links.


Set the Root Bridge

There are two ways to set which Switch within your network will take the roll or the Root Bridge. They are both based on setting the priority parameter, and therefore the Bridge ID.


BRIDGE ID = PRIORITY* + VLAN No + MAC Address
*PRIORITY = N x 4096 (values between 0 and 61440, with 32768 being the mid-value chosen as a "default priority")

Remember about the STP: LOWER PRIORITY IS BETTER!!!


1st Way of setting the PRIORITY – SET PRIMARY/SECONDARY

(config)# spanning-tree vlan 1 root [primary | secondary]

Honestly I don’t like this way because theres a general confusion among the network engineers that this command somehow dynamically sets the Switch to maintain its role as a Root Bridge. It doesn’t!!! It just sets the priority value to the lower value that the CURRENT Root Bridge has (case of primary), or sets the FIXED value to the 28672 (case of secondary).


2nd way of setting the PRIORITY – Manual priority command

(config)# spanning-tree vlan 1 priority X*
*X = N x 4096 (values between 0 and 32768)


Personally I prefer this way, makes me that I´ve got much more control over the L2 network when I set the parameters myself, no automatic stuff and elections!

Be extremely careful when manually adjusting this parameter as it will totally alter your Layer 2 Switching Paths. What basically happens here is that each switch in the network does the following process:

1. Determine who the Root Bridge is
2. Find the shortest path to the Root Bridge looking at the COST parameter
1. Block all the other paths*

*In the basic version of the Per-VLAN Spanning Tree Protocol, 802.1D the ports have one of the following states:

- ROOT Port – Used to reach the Root Bridge (Port TOWARDS the Root Bridge)
DESIGNATED Port – Forwarding Port (One-Per-Link, Port AWAY from the Root Bridge)
BLOCKING (Non-DESIGNATED) Port – the link where “the tree fell”

On the NEWER versions of this protocol, such as Rapid STP (802.1w) two new port roles are introduced instead of the BLOCKING port:

-      ALTERNATE Port – The improvement where the Switch actually “remembers” its alternative path to reach the Root Bridge in order to failover immediately in case the primary link goes down
-      EDGE Port – towards the NON-SWITCH devices, has portfast feature configured

Link Cost

You´ve already chosen the Root Bridge, everything is fine, but for some reason – you don’t want your traffic to prefer a certain link… Why? Well, maybe you´ve got insider information that the cable is bad, that the cleaning lady sometimes unplugs it by accident, or… well, or you simply consider it better for your design. Cisco allows you to manually set the COST of one link to a higher value so that the other link is chosen as the preferred, and that way you gain the control of the Root Port election on your switch. 



This is a GNS3 diagram of 3 Switches, and it will serve for this example. Lets say SW3 is the Root Bridge, and all the links are 100Mbps, which would be the COST of 19. Naturally the SW1 chooses the direct link towards the SW3 cause it costs him 19 to get there.

Lets sat that for some reason we want to force the SW1 to use the other path to reach the SW3 (the link SW1-SW2-SW3). The cost of that link is 38, so what do we do? We set the cost of the direct link SW1-SW3 to the value greater than 38. Let’s go with the value of 39:

(config-if)# spanning-tree vlan 1 cost 39


*Notice that the configuration is done on the Interface level



Port Priority

This command is used only when there are more ways to reach the SAME SWITCH. Sometimes it’s a tie-breaker so be careful, it determines which ports are in the FWD and which in the BLK state. The default port priority is 128, so you need to define the lower value in order for the link to be preferred. The value range is between 0 and 255.


Check the output of the *show spanning tree interface x details* command on the Cat2 device:



Cat1(config-if)#spanning-tree vlan 1 port-priority 64
Cat2#show spanning-tree vlan 1 int fa0/24 detail Port 24 (FastEthernet0/24) of VLAN0001 is root forwarding   Port path cost 19, Port priority 128, Port Identifier 128.24.   Designated root has priority 24577, address 0018.1820.2700   Designated bridge has priority 24577, address 0018.1820.2700   Designated port id is 64.26, designated path cost 0   Timers: message age 2, forward delay 0, hold 0   Number of transitions to forwarding state: 2   Link type is point-to-point by default   BPDU: sent 1993, received 697

The important thing is that the UPSREAM value needs to be changed because it’s the RECEIVED port priority that really matters! For the port to be preferred we need to set a smaller value on the Cat1 device, so let’s go with 64:

And when we check the output of the *show spanning tree interface x details* command again:

Cat2#show spanning-tree vlan 1 interface fa0/24 details
Port 24 (FastEthernet0/24) of VLAN0001 is alternate blocking
Port path cost 19, Port priority 128, Port Identifier 128.24.
Designated root has priority 24577, address 0018.1820.2700
Designated bridge has priority 24577, address 0018.1820.2700
Designated port id is 128.26, designated path cost 0
Timers: message age 1, forward delay 0, hold 0
Number of transitions to forwarding state: 1
Link type is point-to-point by default
BPDU: sent 1992, received 306

For more details please check the Cisco official Spanning Tree Configuration reference: Cisco Configuration Guide

Dot1q Tunneling: 802.1q, QinQ Tunneling

When a TUNNEL port receives Customers Traffic - INGRESS PORT adds 2 Byte EtherType field 0x8100 + 2 Bytes for CoS and VLAN
Eggress tunnel port STRIPS THESE 4 BYTES
 (config-if)#switchport access vlan 100
 (config-if)#switchport mode dot1q-tunnel

You can also configure L2 TUNNELING (CDP, STP and VTP can be tunneled)
(config-if)#l2protocol-tunnel [cdp | stp | vtp]

#show l2protocol-tunnel summary

*Take SPECIAL CARE about the MTU SIZE on Swithches (might need to increase to 1504 due to the ADDED 4 BYTES IN THE TUNNEL)

CONTROL Plane Policy

CBAC and Zone Based FW are all DATA Plane policies. Another type of Security Policies is a Control Plane Policy. This is quite similar to Cisco's MQC used for the QoS traffic shaping and policing. You can also use the commands like from MQC to limit (POLICE) the Control Traffic.

You can use STANDARD CLASS-MAPS like in MQC to match PROTOCOL or ACLs (access-group), but you can also use, example, the LOGGING TYPE CLASS-MAPS:
(config)#class-map type logging match-any LOGGING
(config-cmap)#match packets ?
  dropped    Packets dropped by control-plane protection features <-IN ORDER TO VIEW THE CONTROL PLANE
  error      Error packets dropped by control-plane protection features
  permitted  Packets permitted by control-plane protection features

(config)#policy-map POLICE_50KBPS
(config-pmap)#class CONTROL_BW
(config-pmap-c)#police 50000 conform-action transmit exceed-action drop violate-action drop

The trick is to APPLY the Policy Map to the CONTROL PLANE:
(config)#control-plane
(config-cp)#service-policy input POLICE_50KBPS

BANNER and MENU Configuration

If you need to define a BANNNER to display the user restrictions, have in mind that you can use the variables:
$(hostname) $(line) $(domain)

You also have an option of creating the DYNAMIC ENTRIES as a banner, and let user use the VARIABLES as a response:
Cisco Docs: Cisco IOS Configuration Fundamentals Configuration Guide, Release 12.4T>Banner Configuration

Step 1: Define the MENU TITLE
(config)#menu MYMENU title & This is the AXA menu

Step 2: Define the TEXT ITEMS:
(config)#meny MYMENU text 1  Display all interfaces with their IPs
(config)#meny MYMENU text 2  Display the configuration of Fa1/0/1
(config)#meny MYMENU text 3  Logout
(config)#meny MYMENU text 4  Exit the Menu

Step 3: Specify the UNDERLYING COMMAND of each item in the MENU:
(config)#menu MYMENU command 1 sh ip int br
(config)#menu MYMENU command 2 sh run int fa1/0/1
(config)#menu MYMENU command 9 sh menu-exit

Step 4: Define the DEFAULT action:
(config)#menu MYMENU default 9

Step 5: Define the GLOBAL commands, for example to clean the screen when the MENU starts:
(config)#menu MYMENU clear-screen

Etherchannel L2 vs L3

PAgP (Port Aggregation Protocol) - Cisco Prop. DESIRABLE or AUTO or NONEGOTIATE
*in case the link is configured as ACCESS, or the "switchport nonegotiate" command
- Protocol Value: 0x0104
- Same multicast group MAC like CDP

LACP (Link Aggregation Control Protocol) - 802.3ad - ACTIVE or PASSIVE
- Multicast MAC: 01-80-C2-00-00-02
- During Detection transmits packets every second

LACP>
Check the DEFAULT PARAMETERS:
2#show lacp 1 internal
Flags:  S - Device is requesting Slow LACPDUs
        F - Device is requesting Fast LACPDUs
        A - Device is in Active mode       P - Device is in Passive mode

Channel group 1
                            LACP port     Admin     Oper    Port        Port
Port      Flags   State     Priority      Key       Key     Number      State
Gi3/0/19  SA      bndl      32768         0x1       0x1     0x7F        0x3D
Gi3/0/20  SA      bndl      32768         0x1       0x1     0x80        0x3D

"ON" - Doesnt use LACP or PaGP. BOTH sides MUST BE ON!!!
#do show etherch protocol
                Channel-group listing:
                ----------------------

Group: 13
----------
Protocol:   -  (Mode ON)


You can configure MAX 16 PORTS, out of which:
MAXIMUM 8 ACTIVE PORTS, and the other HOT STANDBY (activate if one of the first 8 fail). Which ones belong to
the ACTIVE group depends on the LACP PRIORITY, that can be configured:
(config-if)#lacp port-priority 1 <--- LOWER IS BETTER!!! (default is 32768)

L3 ETHERCHANNEL: Configure the Port-Channel interface statically, and all L3 configuration under it
Summary: 32     Po32(RU)         -        Gi1/0/23(P) Gi1/0/24(P)

L2 ETHERCHANNEL: LOGICAL INTERFACE CREATED AUTOMATICALLY. Best Practice (CONFIGURATION):
- Default Interface
- Channel Protocol and Group on physical interface (this creates Port Channel)
- Configure TRUNKING ENCAPSULATION under the PORT CHANNEL directly
- SHUT -> NO SHUT on PHYSICAL INTERFACES
Summary: 24     Po24(SU)        PAgP      Gi1/0/21(P) Gi1/0/22(P)

* "show interface trunk" Will show only Port Channel, but "show interface XX switchport" will show that the INT IS TRUNK


LOAD BALANCE the Etherchannel>
*CONFIGURED in the Global Config mode:
 (config)#port-channel load-balance ?
  dst-ip       Dst IP Addr
  dst-mac      Dst Mac Addr
  src-dst-ip   Src XOR Dst IP Addr
  src-dst-mac  Src XOR Dst Mac Addr
  src-ip       Src IP Addr
  src-mac      Src Mac Addr

 #show etherchannel load-balance
EtherChannel Load-Balancing Configuration:
        dst-mac

EtherChannel Load-Balancing Addresses Used Per-Protocol:
Non-IP: Destination MAC address
  IPv4: Destination MAC address
  IPv6: Destination MAC address

Most Popular Posts