Forum Discussion
meena_60183
Nimbostratus
Jun 20, 2008clarification on SNAT and automap
Hi All,
I thought I understood SNAT very well but now I am really confused about SNAT and automap. I wish SNAT is called client NAT and Server NAT depending on which address gets NATed.
Here is my scenario. I have few web servers whose default gateway is the router and not the F5. I want to SNAT the client IP to a LTM IP so that the return traffic from the server is seen by F5 before getting to the client.
Do I set up a SNAT or SNAT pool or a SNAT translation list?
If I turn on automap, it works fine but I do not want to change the source IP as the F5 IP on the return traffic to the client. I want to preserve the server's IP.
Is iRule is the only way?
- Hamish
Cirrocumulus
First, drop all the pretense of S=Secure, and think of SNAT as Source NAT. i.e. NAT'ing the source address of the connection. That should probably make it a lot easier to remember what's happening. - meena_60183
Nimbostratus
I think I got it! - Hamish
Cirrocumulus
Yep. You got it. - Deb_Allen_18Historic F5 AccountGreat explanation, H, spot on.
- Micros_88999
Nimbostratus
Maybe related question, maybe not: - hoolio
Cirrostratus
Are you wanting to take the client IP and use that to SNAT the connections to the pool? If so, this would not be SNAT'ing--it's basically disabling using the client IP to source the connections to the pool members. If I've misunderstood the scenario, can you elaborate on what you're considering? - Micros_88999
Nimbostratus
Hi Aaron, - JRahm
Admin
once you snat the real IP is gone from layer 3. However, you can pass the 'real' IP in the X-Forwarded-For header by enabling that option in the http profile. - Micros_88999
Nimbostratus
Hi there, - JRahm
Admin
FYI...IIS can do nothing natively with the x-forwarded-for header. However, Joe recently released an update to his ISAPI filter that will do the heavy lifting for you. Check out his blog for details: Click here
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects