Forum Discussion
Sven_89244
Nimbostratus
Jan 13, 2009Assistance needed for SNATing plus other irules
I've got a task to do some snat and some other traffic modification.
connections with destination-port 6200,6201,6202 should have a timeout of 6 hours.
connections with certain i...
hoolio
Cirrostratus
Jan 13, 2009When you say the connection couldn't be established, what do you see in a tcpdump? Is the connection from the client to the VIP address established? Do you see any serverside packets sent? Is there a RST from the VIP address back to the client and/or a RST sent from the LTM address to the destination? Or does it time out with no response?
If you're using a fastL4 profile, you'll need to run tcpdump on the port number to see all packets (tcpdump -ni 1.1 host CLIENT_IP or host DESTINATION_IP).
Also, I think you mean to use TCP::local_port instead of TCP::client_port in the first iRule as I assume you want to check the port the client made the request to--not from.
Can you add logging to each case in the iRules and post anonymized copies of the debug from /var/log/ltm for the failure?
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
