Forum Discussion
panos_101277
Nimbostratus
Jun 17, 2008Have a series 9 BigIP do switching instead of SNAT
Hi,
I've been trying to find a way to get a series 9 (9.4.4) BigIP to do switching instead of nat so that requests to servers come from the real originating IP and not the load balancer's IP.
This is not a problem for web servers as we can insert the IP in the x-forwarded-for header but we also need it for everything else, more importantly ftp and mail servers.
I have tried turning off snat/nat in the pool and virtual server, address translation etc but I then don't get a response back from the server (they are already using the LB as their default gateway).
Is there a way to do this?
Thanks.
Regards,
Panos
- dennypayne
Employee
Hi Panos, - panos_101277
Nimbostratus
Hi Denny, - dennypayne
Employee
I'm not sure where you are seeing an option for configuring SNAT on the pool, (other than disabling it), the actual configuration is on the virtual. Unless there's a new option in 9.4.4 that I haven't noticed yet... - panos_101277
Nimbostratus
Hi again, - Hamish
Cirrocumulus
Are you talking connections into the servers from external, or connections being initiated by the servers? - dennypayne
Employee
Do you have a forwarding virtual server defined? BIG-IP is a default deny box, just like a firewall, so if you aren't specifically allowing traffic to pass, then it won't. - dennypayne
Employee
I should also add that you could just add a global SNAT that is only enabled on the internal VLAN, so that only outbound connections are SNAT'ed. I just typically favor the forwarding/routing approach because it usually makes server admin easier.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects