For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

wowchens's avatar
wowchens
Icon for Nimbostratus rankNimbostratus
Dec 07, 2007

BigIP as a Gateway

Hello Friends:

 

 

At the outset, I would like to make sure I am in the right place to get a direction for my problem, else I am happy to get kicked out and find solution elsewhere.

 

 

Here is my problem.

 

 

I have single VLAN, VLAN1 that has 2 member servers. All my clients are in a different VLAN which is routable and can reach the servers directly. I created a Standard Virtual Server and a pool with these member servers and try to browse(this is a web app) from a client PC it doesn't work, which is probably normal as the return traffic directly from the server to client doesn't get acknowledged.

 

 

I made the servers Default Gateway to the Self IP of F5 and this makes the Web app work fine. Part of my issue is resolved. But, I am not able to reach the servers for any other TCP communication like icmp/rdp or usual administration traffic. I have a feeling that I am missing a basic step some where. If anyone has had a similar issue or insight into this, please let me know. Any help is greatly appreciated.

 

 

- These are the things that I tried so far.

 

- I created a forwarding Virtual Server with 0.0.0.0 network, enabled for all Protocols and also enabled fastL4 with Loose Initiation and Loose Close enabled. No luck with this.

 

 

- I changed the actual Virtual Server to Performance L4 with fastL4 custom profile, no luck.

 

 

- Last but not the least, the business doesn't want to use SNAT as this application is used Globally and they need to preserve client IPs.

 

 

Thanks a bunch.

 

Chenna

4 Replies

  • Thanks for your reply. I haven't tried the loopback option. I will try and see if I can do that on the server. I have to check with the Business on that. I will let you know how it goes.

     

     

    Thanks a lot for your help.
  • I installed MS Loopback addapter on the servers and assign the VIP to them and everything is working great. I am sure application traffic is not controlled properly as none of the return traffic goes through BigIP. In any case, with the given resources this is all I can do.

     

     

    Thanks for your help.
  • hoolio's avatar
    hoolio
    Icon for Cirrostratus rankCirrostratus
    Hi Chenna,

     

     

    No worries. Good to hear it's working. It's an interesting configuration.

     

     

    Aaron