Forum Discussion
'HairPinning' on LTM ?
Can you use an iRule to control who can access /urihere? Would seem to be the easiest way, given the information you've provided. There are cleaner ways, but this is a start...
when HTTP_REQUEST {
if { [HTTP::path] starts_with "/urihere" } {
switch -glob [IP::client_addr] {
"10.*" { return }
"172.12.*" { return }
"192.168.*" { return }
default { discard }
}
}
}
- Randy_Johnson_LJul 13, 2017
Nimbostratus
Thaks, ekaleido-- Not quite what I'm going for, as my internal webservers do not seem to be able to even reach 'themselves' through the externally facing VIP / hairpinning. However, these 'internal' webservers are able to ping and traceroute from the internal servers to the external company.com. However, when attempting to connect to https://company.com, I get a 'Connection Reset'.
- ekaleido_26616Jul 13, 2017
Cirrocumulus
Do you need to enable or disable SNAT AutoMap on the virtual server?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com