Forum Discussion
Getting client original source IP for SSL/TLS session terminated by the servers to perform authentication and authorization, not F5
If I configure F5's internal self-IP as the servers' default gateway, can F5 be functioning as the router forwarding the package to the true default router if the server's package is not originated from F5?
Forwarding and routing responses are two different things. At a minimum, you'd need to tell the server to route back through the F5 for any requests it received from the F5, and you can do that by setting the server's default route as the F5's internal self-IP. For that same server to be able to access the world through the F5, for traffic originating at the server, you'd need to also create an internal forwarding VIP (IP forwarding - 0.0.0.0/0:0 - SNAT outbound as required), and then apply a default route on the F5 that points to the true outbound router.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com