Forum Discussion
F5 LTM SNAT
Internet --- FW ---42.x.x.x =nat= 10.10.1.1/24 --- F5 --- SPAM Filters (10.10.2.4/24, 10.10.2.5)
I have
- Internet incoming SMTP traffic going to 42.x.x.x NAT to F5 VS IP 10.10.1.1/24.
- F5 then load-balance traffic to SPAM Filters @ 10.10.2.4/24 and 10.10.2.5/24.
- SPAM Filters then sends back to the F5 floating IP (as the default gateway).
- F5 uses SNAT to map 10.10.2.4/24 and 10.10.2.5 to 10.10.1.1/24 to send to Internal Exchange.
- If email needs to go to Internet, FW wil NAT 10.10.1.1/24 = 42.x.x.x
Is this the recommended approach?
Or
The SPAM filters should be deployed at 10.10.1.x with FW as it's default gateway? I.e., any outgoing email from SPAM filters will be directly from itself rather than F5 VS IP.
1 Reply
- Cory_50405
Noctilucent
I would imagine you could set SMTP routes on your spam filter servers (if they are true email proxies). You could set the default route on your spam filters to the firewall, but have an SMTP route in place for the Exchange environment, and route that to the LTM virtual server for load balancing across the Exchange servers. Any email bound for external sources would be routed out of your network by your firewall and wouldn't need any load balancing from LTM.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com