Forum Discussion
GTM with two floating IP in same vlan
Hi Guru, I would like to confirm if there is implication of configuring two floating ip address in the same VLAN.
The customer network has two different ISP and terminated in the Firewall. For FW perspective I cannot NAT two public ip address in the same private IP address..
In order to NAT ISP 1 range to GTM . I need two different floating ip address in the same segment. then FW will NAT ISP1 to floating IP 1 and ISP 2 to floating IP 2.
then from the DNS Manager when i configure delegation I will assign the following NS1= GTM( ISP 1)
NS2= GTM (ISP 2)
from the FW i will NAT ISP1>>> GTM floating IP 1( 10.10.10.1)
ISP2>>> GTM floating IP 2( 10.10.10.2)
Network Configuration VLAN 10
GTM Primary = self ip 10.10.10.3
GTM Secondary = self ip 10.10.10.4
Floating ip 1= 10.10.10.1
Floating ip 2= 10.10.10.2
This is to achieve high availability incase ISP1 is down or ISP 2 is down I can still reach the GTM to query A record.
thanks in advance
1 Reply
- Hamish
Cirrocumulus
Two separate floating IP's is fine from an LTM POV... However GTM really wants to be configured on a non-floating IP. I've never tried configuring a GTM listener on a floating IP before... That may be where you strike any issues.Even if it works straight away, I've had strange behaviours in the past from GTM when bending the rules slightly.
If you do get it configured like that. Make sure you check out the sync between any other GTM's you have configured (The above GTM Primary/Secondary implies your'e running two GTM's in a sync'ed config). That's probably where it will go bad if it does.
What I'd suggest though is configuring TWO separate NON-floating IP's per GTM and creating GTM listeners on those. (For a total of 4 separate GTM listeners)
H
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com