Forum Discussion
jessej1111_1443
Nimbostratus
Apr 16, 2014all ip's in a subnet behind my F5 respond to ping even though I only have 4 devices active
Hello Everyone,
I was wondering if you could point out a likely configuration mistake. Currently I have an F5 that has a subnet behind it for virtual servers. The virtual servers that are curren...
Cory_50405
Noctilucent
Apr 16, 2014Can you elaborate a bit more about your environment and how clients reach assets in the subnet behind your BIG-IP? And more in general, how routing works in your environment? You mention being able to SSH to the devices behind the F5. Do these communications go through a virtual server on the BIG-IP?
- jessej1111_1443Apr 16, 2014
Nimbostratus
Let me go a little more into the details. All IP's have been changed. I have a private IP range on the F5 lets call it 192.168.100.0/24. The F5 is the gateway for this subnet and has 192.168.100.1, 192.168.100.2, & 192.168.100.3 as I have 2 in an active / standby setup so .1 is the gateway. These are my real servers that sit behind the F5. I have public IP's that my virtual servers are using. In this case I have multiple virtual servers hosting websites passing to my real servers on port 80 and 443. I have Ethernet connections that go from my F5's to my core cisco. I have other private subnets that can access the real servers with no problem using their private IP addresses. The real servers can also access my other private subnets without issue. Connectivity is functioning and I get no logs suggesting a network connectivity issue. The weirdness is that if I ping an IP in the subnet the real servers are on that I know is not in use it returns an echo reply. This behavior is also only happening on the subnet behind the F5 and all of my other private subnets are functioning properly. I only noticed this when I ran a scan with my ipam tool and it told me the range was full. - Cory_50405Apr 16, 2014
Noctilucent
For the IP addresses in your real server range that are responding to ping despite there not being a real server with that IP address, what is the MAC address being seen in the pinging machine's ARP table for that address? Is the BIG-IP responding to the ARP requests, or is something else?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
