Forum Discussion
GTM responds with public IP to external requests but private IP to internal
Hi.
I have a problem with my GTM/LTM configuration.
I have a GTM which is used for both Internal and External DNS. It has an LTM which it monitors. All the virtual servers on the LTM use private IP addresses so I have configured translation for all the relevant virtual servers that the GTM monitors on the LTM. This all works fine from external sources, the GTM will respond to the DNS query with the correct public IP.
However, when some internal sources request the DNS name, the response back is with the private IP. For various reasons I always need the GTM to respond with the public IP.
So, could someone firstly, please explain why this is happening? Is it by design?
And secondly, how can I make the GTM only ever respond with the public IP?
thanks.
3 Replies
- Pedro_HaoaRet. Employee
Hi,
What software version do you use?
How your users reach GTM Listeners, internal users via internal self-ip and external users via external self-ip or all users via external self-ip?
Do you have internal and external A records for the same Virtual Servers?
- Luca_55898
Nimbostratus
I'm on version 11.2.1 build 1042
All users (internal and external) reach the listener via the external self IP.
No, we only have external records for virtual servers on the GTM. We use translation to tranlsate them to the internal IP that the LTM knows about.
- Pedro_HaoaRet. Employee
Hi,
the GTM resolution must be only with public addresses.Basedon the informationyou have posted,If you have GTM listening only in the public block (with No NATing), the translation field should be blank.
However, a network diagram and config print screens with your environment will
.serveto better understand theactual design & config
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com