Forum Discussion
Floating IP not needed if SNAT used
Hello,
I implemented 2 BIG-IP active/active with two traffic-groups. The VS are links to SNAT pool, so the floating IP is not needed, the servers in pool communicate with SNAT IP not with floating IP. So I didn't built any floating ip.
It seems to work properly, but I would like to know if this design is approved by F5. Or if floating ip is mandatory even if not used.
Thank you
4 Replies
- Vitaliy_Savrans
Nacreous
Hi,
from guide :"A floating self IP address enables a destination server to successfully send a response when the relevant BIG-IP unit is unavailable. When two units share a floating self IP address, a destination server can send traffic to that address instead of a static self IP address. If the target unit is unavailable, the peer unit can receive and process that traffic. Without this shared floating IP address, the delivery of server traffic to a unit of a redundant system can fail."
In case of one device failure it's usefull feature.
- JG
Cumulonimbus
However, if you have configured MAC masquerading, that helps.
See:
[sol11880: BIG-IP objects configured on a different subnet than the self IP address do not send gratuitous ARP requests during failover.](https://support.f5.com/kb/en-us/solutions/public/11000/800/sol11880.html) - steph_01_143006
Nimbostratus
Hello, thank you for your answers.
The SNAT Automap feature use floating IP, but SNAT pool not because the IPs are defined into the SNAT pool.
So I have only setup MAC masquerading in traffic group for sending gratuitous ARP during the failover. No floating self IP is enabled. I'm continuous to test my design in order to check if all is ok, currently it seems to work properly.
Regards
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com