Forum Discussion
genseek_32178
Feb 07, 2012Nimbostratus
F5 Issue
Hi,
Below is the config of virtual, pool and snatpool on F5 that is in production. need assitance.
snatpool vlan12_sp { member 63.25.36.7 }
pool reversenpath_vlan12_pl { member 63.25.36.1:any }
virtual reversenpath_vlan20_vs {
snatpool vlan12_sp
pool reversenpath_vlan25_pl
destination any:any
mask 0.0.0.0
profiles fastl4_reversenpath_default {}
vlans 20 enable
Internet is not working on the servers connected to vlan 20.
Thanks - genseek
- nitassEmployeeTrace from the server to internet is getting dropped at upstream router.can you run tcpdump on bigip to see whether bigip sends traffic to pool with correct snat address? if you are able to see bigip sending packet but no reply, next step might have to check at upstream router.
- genseek_32178Nimbostratusnitass..
- nitassEmployeecan you plz send me the exact tcpdump command to be run on bigip in this context, with all IPs? tcpdump -nni 0.0:nnn -s0 -w /var/tmp/output.pcap host destination-ip-address
- genseek_32178Nimbostratus
- genseek_32178NimbostratusAlso, another question....
- genseek_32178Nimbostratus
- nitassEmployeewhat is the host and destination IP address here? is it any internet based URL/IP?only destination-ip-address has to be replaced with internet address.
- genseek_32178Nimbostratusserver has its gwy as bigip floating ip. Hence, the outbound traffic for internet passes through bigip.
- genseek_32178NimbostratusAnu update nitass?
- nitassEmployeeIf it is for outbound traffic ---> say, if a server with bigip as its gwy initiates traffic for yahoo.com, how is this pool used? under virtual server configuration, there are address translation and port translation setting. when they are turned off (uncheck), bigip won't translate destination address and port (virtual server address and port) when sending traffic to pool. so, pool will route traffic then.
Recent Discussions
Related Content
Â
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects