Forum Discussion
Exchange 2010 CAS Array advice
http://devcentral.f5.com/wiki/default.aspx/iRules/Exchange2010_SNATPool_Persist.html
I should point out that a similar approach to SNAT pool persistence also fixed some nagging issues with OpenText clients -- rolling SNAT IP addresses caused sessions to randomly invalidate.
Joel
- hoolio
Cirrostratus
Hi Joel, - Joel_Moses
Nimbostratus
Correct; NTLM will do this as well, although the behavior is masked because the server will just 401 again and repeat the authentication. It would lead to an increase number of 401s overall, though.
Since running into this with RPC, as I mentioned, I've since discovered that it affects other applications -- including some web applications. OpenText was the first, but I've also seen it occur in a few SSO products as well. Essentially, anything that partially bases its session model on incoming IP address will suffer from this.
I'd also like to see an iRule function to list all possible SNAT addresses for the current virtual regardless of its configuration ("LB::snat list"?). For automap or single SNAT, it'd return a list of all possible automap SNAT IPs or the single SNAT IP. For a pool, it would return a list of all SNAT IPs, ordered the same way they're ordered in the GUI. It'd make it easier to write a rule that did manual SNAT ordering.
- L4L7_53191
Nimbostratus
There's an existing CR for this behavior (SNAT persistence). I'll try and track it down and post it for people's reference. - r_dynamo_79563
Nimbostratus
I'm doing an Exchange 2010 F5 build between 2 sites, with an internal/external GTM, and internal/external LTM on each site. - BenT
Altocumulus
How do you track the realtime connections by snat pool member? I've recently applied a similar irule, but the connections being snatted by the irule no longer show up under the snat translations statistics.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com