Forum Discussion
Does anyone have 11.6 LTM doing IPsec with 3rd party device
- Feb 08, 2015
my experience with big ip for ipsec, it doesn't work properly i tried a lot with link controller to terminate and to by pass ipsec traffic nothing works, many technical cases with no progress
So after yeoman work by Damon at F5, we got all of the issues resolved. First, follow the instructions to get the connection working, sort of. Once we had the tunnel set up between the systems (getting the parameters right helps), we still ran into problems with TCP connections initiated from the F5 end. Now comes the weird part. We created a route to the remote network inside the tunnel and pointed it to the gateway for the network that contains the F5 endpoint. Once this route was added to the mix, all of the TCP and other connections worked. So the missing instruction is to be sure you add a route to the target remote networks to the F5 using the endpoint gateway as the next hop. This is basically the way that Cisco used to work where you put the IPsec association on the endpoint interface.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com