Forum Discussion
Spidey_29396
Nimbostratus
May 09, 2013F5 as NAT device
HI All,
we have a deployment where F5 will be use as NAT device to replace a router. Im thinking what is the best practice for this, use route domain of just use vlan?
Thanks!
Ferdz
16 Replies
- What_Lies_Bene1
Cirrostratus
I'd avoid using Route Domains unless there is a real need for them. As I've asked in your other post, can you provide some further detail please. - Spidey_29396
Nimbostratus
Hi Steve,
The reason why we need to NAT IP addresses because of the conflicting IPs,
Here's the flow
Company A <> Router Company A <> F5 <> Router Compny B <> Company B
Thanks!
Ferdz - Spidey_29396
Nimbostratus
Hi Steve,
The reason why we need to NAT IP addresses because of the conflicting IPs, we are currently replacing a Cisco router using an F5.
Here some snapshots from NAT Router:
ip nat pool SUN1 172.26.0.2 172.26.31.254 netmask 255.255.224.0
ip nat inside source list 11 pool SUN1
access-list 11 permit 10.19.0.0 0.0.31.255
ip nat inside source static 10.157.8.84 172.26.210.84
ip nat outside source static 10.103.33.11 10.171.14.111
Here's the flow
Company A <> Router Company A <> F5 <> Router Compny B <> Company B
Thanks!
Ferdz - What_Lies_Bene1
Cirrostratus
OK, thanks. So what are you thinking, configure a VLAN on the F5 to be the 'outside' replacement for the router? I presume the F5 already has a leg into your internal network or whatever? So, if that's the case you'll need a network wildcard VS for the outside and inside VLANs and a dedicated SNAT Pool for each. Shouldn't be too hard but please confirm before I get into the nitty gritty. - Spidey_29396
Nimbostratus
Can we use NAT instead of SNAT so it will be bi-directional? and for the Dynamic NATing?
Origin:
10.19.0.0/19
Translation:
172.26.0.2 -172.26.31.254 - What_Lies_Bene1
Cirrostratus
Should be able to do static NATs for these two: 10.157.8.84 <> 172.26.210.84 and 10.103.33.11 <> 10.171.14.111 and an overload/dynamic SNAT one way for;
Origin: 10.19.0.0/19
Translation: 172.26.0.2 -172.26.31.254
Does that meet your needs? - Spidey_29396
Nimbostratus
Hi steve,
Is f5 NAT bi-directional? For example,
Origin:10.157.8.84
NAT: 172.26.210.84
Can i initiate traffic to 172.26.210.84?
Also,in the snat u gave? What are the ways i can initiate thru the snat ip addresses? - What_Lies_Bene1
Cirrostratus
Yes a NAT is bi-directional (perhaps it needs to be enabled on the relevant VLANs though, can't remember)
Regarding the SNAT, you would need two as you have now, one for each direction and only one side could initiate; no different to how it would work on the Cisco router. - Spidey_29396
Nimbostratus
Hi Steve,
Thanks for the help.I will be testing it on our lab setup before going to live migration.
Thanks!
Ferdz - What_Lies_Bene1
Cirrostratus
You're welcome, post back if you have any issues.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects