For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Norman_Zhang_14's avatar
Norman_Zhang_14
Icon for Nimbostratus rankNimbostratus
Mar 12, 2014

F5 LTM SNAT

Internet --- FW ---42.x.x.x =nat= 10.10.1.1/24 --- F5 --- SPAM Filters (10.10.2.4/24, 10.10.2.5)

 

I have

 

  • Internet incoming SMTP traffic going to 42.x.x.x NAT to F5 VS IP 10.10.1.1/24.
  • F5 then load-balance traffic to SPAM Filters @ 10.10.2.4/24 and 10.10.2.5/24.
  • SPAM Filters then sends back to the F5 floating IP (as the default gateway).
  • F5 uses SNAT to map 10.10.2.4/24 and 10.10.2.5 to 10.10.1.1/24 to send to Internal Exchange.
  • If email needs to go to Internet, FW wil NAT 10.10.1.1/24 = 42.x.x.x

Is this the recommended approach?

 

Or

 

The SPAM filters should be deployed at 10.10.1.x with FW as it's default gateway? I.e., any outgoing email from SPAM filters will be directly from itself rather than F5 VS IP.

 

1 Reply

  • I would imagine you could set SMTP routes on your spam filter servers (if they are true email proxies). You could set the default route on your spam filters to the firewall, but have an SMTP route in place for the Exchange environment, and route that to the LTM virtual server for load balancing across the Exchange servers. Any email bound for external sources would be routed out of your network by your firewall and wouldn't need any load balancing from LTM.