Forum Discussion
Exchange 2010 CAS Array advice
http://devcentral.f5.com/wiki/default.aspx/iRules/Exchange2010_SNATPool_Persist.html
I should point out that a similar approach to SNAT pool persistence also fixed some nagging issues with OpenText clients -- rolling SNAT IP addresses caused sessions to randomly invalidate.
Joel
- hoolioCirrostratusHi Joel,
- Joel_MosesNimbostratus
Correct; NTLM will do this as well, although the behavior is masked because the server will just 401 again and repeat the authentication. It would lead to an increase number of 401s overall, though.
Since running into this with RPC, as I mentioned, I've since discovered that it affects other applications -- including some web applications. OpenText was the first, but I've also seen it occur in a few SSO products as well. Essentially, anything that partially bases its session model on incoming IP address will suffer from this.
I'd also like to see an iRule function to list all possible SNAT addresses for the current virtual regardless of its configuration ("LB::snat list"?). For automap or single SNAT, it'd return a list of all possible automap SNAT IPs or the single SNAT IP. For a pool, it would return a list of all SNAT IPs, ordered the same way they're ordered in the GUI. It'd make it easier to write a rule that did manual SNAT ordering.
- L4L7_53191NimbostratusThere's an existing CR for this behavior (SNAT persistence). I'll try and track it down and post it for people's reference.
- r_dynamo_79563NimbostratusI'm doing an Exchange 2010 F5 build between 2 sites, with an internal/external GTM, and internal/external LTM on each site.
- BenTAltocumulusHow do you track the realtime connections by snat pool member? I've recently applied a similar irule, but the connections being snatted by the irule no longer show up under the snat translations statistics.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com