Forum Discussion
Cannot establish IPHTTPS connection.
I've a Direct Access test lab with a weird problem that I'm unable to resolve.
During setup I've configured a VIP for IPHTTPS as per F5 & UAG guide. (http://www.f5.com/pdf/deployment-guides/f5-uag-dg.pdf)
The VIP type that I used is Perfomance (Layer 4) as mentioned in the guide.
However, when clients from the internet tries to establish an IPHTTPS tunnel to one of my DA servers it fails with the following error:
Interface Status: failed to connect to the IPHTTPS server. Waiting to reconnect
But:
If I change the type of the VIP from Performance (Layer 4) to Performance (HTTP), then clients connections starts working just fine.
It does take too long until a connection is established but eventually it works.
I was wondering how can I make it work when VIP is configured with Performance (Layer 4)?
Thanks in advance,
JrMaster
- Erick_Hammersm1Historic F5 AccountMy guess is that your servers are not sending reply traffic back through the BIG-IP. One of the features of the Performance HTTP profile is to automatically translate the source address of the connection from the client's real address to an address owned by the BIG-IP (in BIG-IP parlance, this behavior is called "SNAT"). You can achieve the same behavior with a Performance L4 profile by manually enabling SNAT on the virtual server.
- JrMaster_47117NimbostratusThanks Erick! I will give it a shot and let you know how it went.
- JrMaster_47117NimbostratusWorked like a charm! Thanks!!!
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com