Quantcast
Channel: Troubleshooting - KEMP Technologies Community Forums
Viewing all 69 articles
Browse latest View live

Cant Access Web interface

$
0
0
Hello, I just got the LM2000 from my company but I cant set it up! I first did a factory reset. It is activated properly. I plugged an ethernet into eth0 on the four port selection in the front and connected via vga. Works fine. I properly set my ip and my default gateway. When I try to connect via web it cant access it but it knows a computer is at that address. I can ping the device, but I cant access the web interface. I read the guide, and followed the instructions but I cant access it. I tried changing the ports but no difference. I also set it an ip and then connected ethernet directly to it and assigned ip in same subnet to laptop but still i cant connect to it.

Cannot ping from other vlan

$
0
0
I just setup my first VLM-1000 and I am unable to ping the machine from my laptop. If i remote into a server on the same Vlan i can ping it and connect to the web interface but i get nothing when trying from my location. I have looked at it now for a while and cannot see anything that would be causing this.

Firmware 7.0 and Safari on iOS

$
0
0
Hello,

after upgrading to firmware 7.0 on a LoadMaster 2500 the web frontend will not be displayed correctly on iOS (tested on iPhone 5 and iOS Simulator).
Best regards

Markus Knaup

Load Balancer as Default Gateway and RDP

$
0
0

Currently all of our load balance services either run at L4 or in non-transparent mode but we now have a requirement to configure an SMTP service as L7 transparent due to the source IP address.

The first issue we have is that the service doesn't work when the default gateway on the server is set to the shared IP address of the HA pair. However it does work when using either of the partner IP addresses.

The second issue is that when the default gateway is set we're unable to RDP to the servers from a remote subnet.

The loadbalancers have a default gateway of 192.168.20.1 and all our services run on the 192.168.20.0/24 range.

image

Adaptive Script returns value 0 in real Servers Statistik

$
0
0
Hi!

We have a Windows 2008R2 Terminal Server Farm with 12 Servers up and running.
I´ve tried to geht the next two Servers to work, but were not able to get the adaptive Script working properly.

The Servers are cloned and prepared with sysprep. After getting IIS up and running again, I get performance values from the script by opening the website. ( http://servername/load/lmperfagent.exe). These values are correct.
Meanwhile I´ve added the server to the Virtual Service on the Loadbalancer (LM-2200 - LoadMaster Version
6.0-28.20120206-1924).
The Problem is, that the loadbalancer only retuns 0 (zero) for the new server, while the website shows the correct value.

I have no Idea, whats wrong.

Thanks in advance.



Error when trying to access a VS from the Internet

$
0
0

I have a VS set up and it works perfectly when accessing it from the internal network.  When I try to access it from the Internet I receive the following error in the loadmaster logs:

Jun  4 17:38:01 xjab-lb1 vsslproxy: Client 24.xx.x.xxx failed SSL negotiation!
Jun  4 17:38:23 xjab-lb1 last message repeated 3 times

 

 

 

 

Not able to monitor Ironport as a real server

$
0
0

I have created an SMTP virtual service for KEMP which directs traffic to an Ironmail  (real) server, however the server cannot be monitored on port 25 using SMTP protocol. However, if I disable monitoring I am able to telnet through the virtual service to Ironmail. Also, if I add an Exchange 2007 server as a real server it is able to monitor that service. Both Ironmail and the Ex2007 server are on different subnets to the appliance. Below is the error I get, please let me know if you have any ideas:

Jun  5 11:47:18 NYXNLB1 l4d: Removing RS 10.38.1.7:25 from VS 10.96.1.18:25(SMTP out) - EOF or Incorrect data received
Jun 5 11:47:18 NYXNLB1 l4d: VS 10.96.1.18:25(SMTP out) Taken out of service due to failed Real Servers

KEMP and Cisco ASA5550 - Connections being reset

$
0
0
We have a working test configuration for Exchange 2010 sat behind a KEMP LM-3600 (HA Pair). This all works fine internally, but our Networks team are wanting to put this behind an Cisco ASA5550.

We have found that this configuration is not working and upon testing (the ASA5550 keeps a stateful table and tracks the tcp connection state) we find that the KEMP sends a TCP Reset (after the initial connection) back to the client and the ASA then removes the stateful entry.

Further traffic from the client to the KEMP is denied because the ASA sees this traffic trying to pass through a reset session.

A workaround exists in that we can turn stateful tcp tracking off but this is far from ideal.

Is there any configuration on the KEMP to resolve this?



Migration Scenario: Ex2003 ->2010 HA via LM problem accessing 2010 HA from 2003 (Routinggroupconn.)

$
0
0
Hello Board,

i´m having problems in setting up my needed routinggroupconnector to connect 2003 server with an ex2010 system.

My configuration so far:

One Exchange Server 2003
IP:10.0.255.107

Two Exchange Server 2010
IP:192.168.25.103,104 (gw points to LM on each 2010 Server)

Two Loadmaster LM 2200 configured in HA-Mode (2-Arm). One Virtual IP (10.0.255.106) to point to the Exchange 2010 servers. My problem is that i cannot get a direct connection to the EX2010 Servers from the old Exchange 2003 server because the RG-Connector needs the FQDN of the Exchange 2010 Server. I tried the FQDN cas.mydomain.local but that doesnt stick since i need a real Exchange Server name.

My solution to this problem is to switch the two loadmaster 2200 of and disconnect them, then give the two Exchange 2010 system IPs from the same subnet. When my migration from 2003 is done then i would reconnect the Loadmasters and finally using HA.

Is there a more painless workaround to this issue? Maybe i can make both exchangeservers accessible from the same net in which the 2003 server resides and keeping the LM online?

Thanks in advance



Exchange 2010 CAS gateway with Kemp virtual VLM 1000

$
0
0
Hello,

We have deployed a VLM 1000 for our Exchange 2010 CAS array. The servers and the load balancer are in the same VLAN and same subnet. If I turn off the transparency in the virtual service confiuration, then everything works.

However, if I turn on the transparency and then add load balancer's IP address to the Exchange CAS server's TCP/IP gateway, the CAS server loses all connectivity. It seems like it cannot route through the VLM.

Are there any particular settings on the VLM that need to be configured to allow Exchange CAS servers to use it as a gateway?

Thanks.

SMTP Relay for Servers in same Subnet

$
0
0

I've just setup a HA pair of VLM-1000 servers and configured a VIP for load balancing SMTP traffic for application servers and scanners (scan2mail). I have 2 Exchange 2010 servers in Multi-role setup (CAS-HUB-MBX). The application servers, the Exchange servers and VLM servers are all on the same subnet.

I would like the VIP to support L7 Transparency so I can direct the server to a specific Receive Connector based on the Client IP. I've selected Real Servers are Local and L7 Transparency options as well as unchecking the Enable Non-Local Real Servers and unchecking Server NAT option.

How can I get the application servers to connect through the VLM to the Exchange server with their own client IP while not moving any servers to another subnet?

I've read something about an additional L7 Header as X-Forwarded-For. Will this work for SMTP traffic as well?

Exchange 2013 and 2 x Kemp VLM-100; can't seem to get this to run

$
0
0

I have 2 Exchange 2013 VM's running both roles, a DAG has been set-up
between these two and that works excellent.

I have followed this link mostly for Load Balancing:
http://www.msexchange.org/articles-tutorials/exchange-server-2013/high-availability-recovery/introducing-load-balancing-exchange-server-2013-part2.html

The Kemp's have been setup, high availability between the two works (HA
first and second mode) and they have each other as preferred failover.

For some reason i can't get load balancing to work with Layer 4 LB and multiple namespaces, my configuration is as following:
(not using the Kemp templates anymore, used to but that didn't work either so i
reset the Kemps and am using default services now)

DNS Records:
http://imgur.com/5zpeDS0
http://imgur.com/0JepfFH

In Exchange ECP - Virtual Directories:
(For all services the Internal name is: local path per server (i.e. https://exchange-srv1.amr-noah.local) + service extension as below (i.e. /ecp))

Outlook Anywhere - External name: outlook.amr-noah.local / Internal name: outlook.amr-noah.local
Autodiscover - 
ecp - External name: https://ecp.amr-noah.local/ecp
EWS- External name: https://ews.amr-noah.local/ews/exchange.asmx
Microsoft-Server-ActiveSync - External name: https://eas.amr-noah.local/Microsoft-Server-ActiveSync
OAB - External name: https://oab.amr-noah.local/OAB
owa - External name: https://owa.amr-noah.local/owa
PowerShell - External name: https://powershell.amr-noah.local/powershell

On Kemp Load Balancer(s):
http://imgur.com/5jg22b4
http://imgur.com/vdPnwlO

Paths per service: 
owa /owa/auth/logon.aspx
AutoDiscover /AutoDiscover/AutoDiscover.xml
EWS /EWS/Exchange.asmx
EAS /Microsoft-Server-ActiveSync
Outlook Anywhere /rpc/rpcproxy.dll
Offline Address Book /OAB

Can anyone tell me what i configured wrong here and why i can't connect to these DNS adresses?

Random connections drops

$
0
0

I'm having an issue with my users getting random connection drops. Sometimes after 3 mins and other times after 10 mins. Users are directed to the main URL, lets say 123abc.com and then depending on the server load they are directed to 1 of 3 servers. They are able to connect but randomly their connection drops and its users in different locations.

if I have the users hit the server IP directly, thus bypassing the loadbalancer they dont get any dropped connections. Please bear with me and this product, I just started this job and the Sys Admin before me is MIA..... so lucky me.

OWA Time out for Public and Private

$
0
0
We have a problem with OWA timing out after 5-10 minutes when both real server are enabled in the VIP. When only one real server is enabled OWA works fine. We have verified the timeout setting on both CAS/HUB servers. We are running Exchange 2010 SP3.

LoadBalancer Backup wget

$
0
0
Hello, 
we take backups every day with this method 

wget --no-check-certificate https://backupuser:backuppassword@192.168.30.244/progs/admin/backup?ba=C... -O LoadBalancer-backup_20090716

wget --no-check-certificate https://backupuser:backupkennwort@192.168.30.244/progs/do3rdcert/certbackup --post-data="pass=MYPASSPHRASE&ba=Create+Backup+File" -O LoadBalancer-backup_ssl-certs_20090716

 http://www.loadbalancerblog.com/blog/2009/07/example-loadmaster-scripting-automated-backup

Since a couple weeks this jobs fails. 

"

--2013-08-07 09:09:33--  (try: 2)  https://***:*****@x.x.x.x/progs/admin/backup?ba=Create+Backup+File

Connecting to x.x.x.x:443... connected.

WARNING: cannot verify x.x.x.x's certificate, issued by `/C=US/ST=New York/L=New York/O=KEMP Technologies/OU=Support/emailAddress=support@kemptechnologies.com/CN=KEMP Technologies':

  Unable to locally verify the issuer's authority.

HTTP request sent, awaiting response... 401 Authorization Required

Failed writing HTTP request: Bad file descriptor.

Retrying.

"

Version Vers:6.0-42

I think the Loadmaster accept the requests in this form not more . 

Have anyone an idea how I solve it? 


Greetings





Exchange 2010 Resets after 30 seconds

$
0
0

Hi,

We have a two-member Exchange 2010 CAS Array behind a LoadMaster (6.0-28a). We've been struggling with Outlook users constantly being prompted for credentials for some time. Other than that, everything works fine.

I put a sniffer on a client and I can see that without fail, the client sends about 5 RSTs in a row to the IP of the Virtual Server, which causes Outlook to fail back to the configured address of the public CAS server, which triggers the authentication prompt.

If I change the host file to send the client directly to each CAS member's IP address (bypassing the LM), this does not happen. In addition, disabling one real server at a time produces the logon prompt when each server operates alone.

So, it would seem that the LoadMaster is causing this RST. Any idea what I can check for?

Thanks,

-Thomas

 

Modify URL Server->Client

$
0
0
Is there a way to hide or remove the URL back to the client?

Right now I've got a scenario where when I go to:
www.myservice.org
I get redirected by Content Rules to
myserver1/whateverurl/
which in turn generates a URL with a lot of code identifying the session.
it looks something like this when it gets back to the client:
www.myservice.org/whateverurl/A-LOT-OF-CODE-IDENTIFYING-MY-SESSION
I would like to remove this last part of the URL on the way back to the client.

Is this possible? Some kind of workaround?

Regards,

Max

SharePoint 2013 Host Header

$
0
0

Hi @ all,

 

We want to Publish some of our SharePoint Sites with our two Loadmaster.

The SharePoint FE Server are configured to listen on 443 and host heaers.

So we create new SAN certificates for the LoadMaster und try to publish different sites like this:

VIP: 30.0.0.1:443 -> SSL Offload -> X-Forward-For -> 192.168.2.1:443 & 192.168.2.1

The first configured VIP works great. No Problems at all.

Configured the 2. or 3. like this:

VIP: 30.0.0.2:443 -> SSL Offload -> X-Forward-For -> 192.168.2.1:443 & 192.168.2.1

VIP: 30.0.0.3:443 -> SSL Offload -> X-Forward-For -> 192.168.2.1:443 & 192.168.2.1

 

We get the following message in the Logs and in the traces we cant find a connection to the RS.

Connection timed out (30.0.0.25:60606->30.0.0.2:443-><nodest>)[0] (waiting for initial client request)

 

Please help !

Thank's

Sign

delete me

usa housing market

$
0
0

הדרכה מקצועית בשביל מתענייני נדלן בארה"ב. בא לכם לקבל הדרכה איך מבצעים השקעות נדל"ן באמריקה על הצד הטוב ביותר? הציצו כאן
http://www.jonpa.com/blog/880/us-real-estate/
Viewing all 69 articles
Browse latest View live