Forum Discussion
F5 Lync iApp with Cisco firewalls
I have configured the Lync iApp on a F5 LTM in our DMZ behind a Cisco firewall.
The client AV traffic goes through the firewall, hits the F5, which sends it on to one of the edge servers (in the same network as the F5) but when the edge server then replies direct to the client the firewal drops the packet as it hasnt seen a SYN packet from the client to the edge (the original SYN went from the client to the F5).
Am I configuring something wrong here, shouldnt the F5 tell the client to re-connect to the edge directly?
Any help appreciated.
Thanks
Richard
- mikeshimkus_111Historic F5 AccountHi Richard, this is one reason we recommend using public IPs for your external Lync Edge services: https://devcentral.f5.com/blogs/us/the-hopefully-definitive-guide-to-load-balancing-lync-edge-servers-with-a-hardware-load-balancer
- Richard_22613Nimbostratus
Thanks Mike.
We do have the edge servers on public addresses, however they sit behind a firewall for security reasons. There is no nat on the firewall for the edge and F5 services.
I dont really want to enable SNAT for the AV service, as you say, as it means peer to peer connections suffer.
The only other option is not to use the F5s iApp template for the AV and SIP side (which seems a waste of the F5s!)
RIchard
- mikeshimkus_111Historic F5 Account
Richard, did you happen to configure the default gateway on the Edge servers' external interfaces to use the self-IP address of the BIG-IP, and set up a default route on the BIG-IP that points to the firewall?
Also, you would need a forwarding virtual server to receive internet-bound traffic from the Edge servers.
- Richard_22613NimbostratusHi Mike,
- mikeshimkus_111Historic F5 AccountI wouldn't think there would be any load/latency problems. You're not proxying that traffic with LTM, just routing it, so there's really nothing being done to it that might put load on the BIG-IP.
- Richard_22613NimbostratusI am going to give this a try with our spare test Edge server that isnt yet in production.
- Ryan_Korock_46Historic F5 AccountRichard.... one solution would be to point the default gateway of the Edge servers to the BIG-IP Self-IP, and the default gateway of the BIG-IP to the firewall. This will route connections that are being load balanced by the BIG-IP correctly without having to SNAT anything.
- Dave_20158NimbostratusRyan - Thank you so much for this information. We ran into this exact issue with the asymmetric routing and I could not understand why the BIG-IP was not forwarding the traffic. Once I created the new fast-L4 profile and enabled loose initiation and loose close, everything worked perfectly.
- Richard_22613Nimbostratus
Ryan
- Ryan_Korock_46Historic F5 AccountSure Richard... so just to reiterate, we need this forwarding VIP because we want the BIG-IP to forward traffic from the Edge Servers out through the firewall. This creates a bit of an assymetric loop for traffic coming in from remote clients directly to Edge Server (The incoming connection will go from the firewall directly to the Edge Server, however the Edge Server will send all return traffic to the BIG-IP and rely on the BIG-IP to forward it to the firewall). This is why we need to set 'Loose Connections' on this forwarding VIP.
- MVANimbostratusHi, thanks for the info, especially on the FastL4 profile. I did just that but still don't see return traffic coming to the Edge Server. I see on the F5 the Edge server sending a SYN to the external client and our Firewall logs shows a connection from the Edge server to the External client as allowed. We also do not see the F5 Self-IP being blocked on the Firewall, which we were seeing previously. From my troubleshooting so far, it seems all is in place but for some reason we're still not seeing a return connection to the Edge server. Any suggestions are appreciated.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com