Forum Discussion
Confirmation of Precedence for SNAT vs WC VS
It looks like we're gong to have to deploy a wildcard VS with an irule to perform selective SNATs for a couple of applications. Since we have many other applications already deployed that could be caught by this wildcard, what is the best way to handle these? I can't quite tell from the precedence doc if the existing defined SNATs for the other applications will pick them up prior to the wildcard VS grabbing the traffic.
1 Reply
- MichaelatF5
Employee
A good rule of thumb, is Most Specific First.
To be specific about it:
- Existing Connections
- Packet Filter
- Virtual Server
- SNAT
- NAT
- SELF-IP
- DROP
However, if you have a wildcard VS that is LESS specific than your SNAT entry, then SNAT will win. If you have existing VS that are configured specifically for application traffic (Source, Destination, Protocol, Port, etc) that will win over a WC Virtual Server with NO PORT, NO DESTINATION, NO SUBNET, etc.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com