Forum Discussion
schulerb_82266
Nimbostratus
Feb 02, 2008Forwarding Virtual Server not working
I am attempting to have hosts on the internal vlan connect to hosts on the other side of the F5.
------
65.x.x.x untrust
11.1.1.1 trust
11.1.1.20 self-ip of external
...
schulerb_82266
Nimbostratus
Feb 04, 2008Thanks for the reply KYY. I've implemented your suggestion. Unfortunately, I am in the same spot.
From the bigip.conf:
route default inet {
gateway 11.1.1.1
}
pool gw_pool {
member 11.1.1.1:any
}
virtual ip_forward {
destination any:any
pool gw_pool
mask none
}
On the F5, I ran 'tcpdump -n -i 0.0 tcp port 8093'.
From 10.1.1.130 with its gateway of 10.1.1.20, I ran to a known working IP -- 'telnet 12.162.xx.xxxx 8093'.
The F5 captured:
17:49:19.399399 802.1Q vlan4094 P0 10.1.1.130.36542 > 12.162.xx.xxxx.8093: S 168
875122:168875122(0) win 5840 2> (DF) [tos 0x10]
17:49:19.399468 802.1Q vlan4093 P0 10.1.1.130.36542 > 12.162.xx.xxxx.8093: S 168
875122:168875122(0) win 5840 2> (DF)
17:49:22.399520 802.1Q vlan4094 P0 10.1.1.130.36542 > 12.162.xx.xxxx.8093: S 168
875122:168875122(0) win 5840 2> (DF) [tos 0x10]
17:49:22.399546 802.1Q vlan4093 P0 10.1.1.130.36542 > 12.162.xx.xxxx.8093: S 168
875122:168875122(0) win 5840 2> (DF)
17:49:27.062530 802.1Q vlan4094 P0 12.162.xx.xxxx.8093 > 10.1.1.130.36542: R 0:0
(0) ack 168875123 win 0 (DF)
4093 is the external vlan and 4094 is the internal.
If I am reading this correctly, the .130 hosts connects to the internal vlan, which connects to the external, but then nothing more.
From the F5, I am able to run the telnet command successfully. I don't think it is routing, but I am in need of a clue as to what to look at next.
This is the same results I got with my original configuration attempt.
Ben
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
