Forum Discussion
Jeff_42220
Nimbostratus
Feb 27, 2009Getting return traffic from a server to the LTM without using SNAT?
Hello,
I wanted to see if anybody has an idea on how I can get past the following problem.
In an environment where back end servers connect to both an LTM and a firewall on separate interfaces/VLANs, we have run into a problem where the application on the server is only seeing the BigIP as the source address. We do have automap SNAT enabled which is what is causing the address translation in the first place. This is needed because the routing on the servers would otherwise send return traffic to the firewall and not back through the LTM, and the firewall would drop this asymmetric connection.
We have tried inserting the X-Forwarded-For HTTP header, but the application being used on the back end server isn't able to pick that up.
So, is there anyway, if SNAT is disabled, that we could still get the server to return the traffic back through the LTM, although that would be against what the server's routing table says?
Thanks!!
Jeff
- The_Bhattman
Nimbostratus
Hi Jeff,
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects