For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

StuKirby's avatar
StuKirby
Icon for Nimbostratus rankNimbostratus
Nov 13, 2015

Forwarding VIP SNAT Rule

Hello

 

Ok my predicament, we have a DMZ Network sat behind our F5 that we want to Route the traffic via the F5. I have 2 IP forwarding VIP's for TCP and UDP. The first couple of servers we pointed through it worked fine but now subsequent ones will not work. If I check the logs there are constant Inet port exhaustion (proto 17) due to our DNS server being on the internal network that the DMZ servers are trying to route to. At the moment our Forwarding VIP is set to Auto Map which maps to the Self IP, I don't want to do a SNAT pool for the internal as I don't have enough free IP's.

 

My question is how can I set a rule or NAT to basically say if you come from this Source IP to this Destination IP then NAT to this IP ? I want to give each of my DMZ servers a 1 to 1 NAT but only to the internal network not the external.

 

Hope that makes sense!

 

1 Reply

  • Emad's avatar
    Emad
    Icon for Cirrostratus rankCirrostratus

    If you do not want internal ip addresses to NAT then add source based nat rule to you forwarding VIP. e.g

    when CLIENT_ACCEPTED{ 
    if {[IP::addr [IP::client_addr] equals SOURCE_IP]}{
        snat  NAT_IP       
        }
    }