Forum Discussion
MB1
Nimbostratus
Oct 21, 2019Help with securing self ip's and forwarding virtual server for a DMZ server using non-http
I have external DNS servers on private IP's in a DMZ vlan. Normally, for servers behind the F5 we just use Automap and the servers default gateway points at the Firewall. However, we want to se...
Mandragor
Altostratus
Oct 30, 2019Port Lockdown only handles traffic destined directly to the self IP, not for traffic which it would forward.
If you're not using a remote logging destination and able to see your traffic there you can simply use tcpdump from your BIG-IP device and filter on traffic from your DNS server to see which virtual server it is going through.
Something along the lines
tcpdump -i 0.0 -nn host <IP-address of DNS-server>
at the end of the line you should see something along the lines of
in slot1/tmm0 lis=/Common/your_forwarding_vs
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects