For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

cjunior_138458's avatar
cjunior_138458
Icon for Altostratus rankAltostratus
Oct 02, 2015

ARP for NAT - Active/Active cluster

Hi folks,

 

I'm facing a NAT issue in Active/Active cluster in BIG-IP v11.4.1 HF4.

 

Could you tell me if the BIG-IP should send GARP to report the new MAC for the NAT address when the current device for traffic group changed?

 

I have a NAT address that responds in active box 1 "traffic-group-1 (floating)", but when this traffic group switches to the box 2, the NAT address still arriving on box 1. Even the box in standby, the request still arrives there. Am I doing something wrong? Can't NAT be applied in this active/active scenario?

 

I appreciate any help.

 

Tks

 

2 Replies

  • It should send a GARP for all floating addresses (inc NAT/SNAT). Have you tried running a tcpdump to see the GARP?

     

    Could it be that the receiving device is not updating it's arp table or the GARP is getting lost?

     

    I prefer not to rely on hosts updating their arp tables when failover occurs as it often gores wrong, instead I use Mac masquerade. That way the MAC address doesn't change during failover so exetrnal hosts don't have to update anything. A GARP is still sent, but only for the purpose of getting the switch to update it's MAC address table which happens at a lower layer than ARP so is a simpler operation.

     

    • cjunior's avatar
      cjunior
      Icon for Nacreous rankNacreous
      First, I thank you for the reply. Yes, I made some analysis and now I can see the GARP, but the requests arrives on active box and the standby box is sending the reply, thus is not working yet. I've tried the MAC masquerade but I had no luck.