For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

rolf's avatar
rolf
Icon for Cirrus rankCirrus
Feb 24, 2009

hot to get the monitor source ip = mauto map ip??

Hi,

 

 

I wonder if it is possible to get the monitor ip = "auto map" ip or the SNAT ip? (without fancy firewall NAT tricks )

 

We had a strange phenomena where the physical IP of the BigIP was able to access a resource, but the SNAT/auto map IP wasn't.

 

 

Thanks for your help!

 

 

Best Regards,

 

Rolf

2 Replies

  • I don't think it's possible (maybe in a db key?). Probably because we don't want to use up ephemeral ports on the SNAT IP for monitoring traffic, since we need them for processing client traffic. I just did a quick scan of the db keys on 9.4.3 and I didn't see anything promising...

     

     

    Denny
  • hoolio's avatar
    hoolio
    Icon for Cirrostratus rankCirrostratus
    As Denny suggests, it's not possible. Both units in an active-standby pair need to independently poll the pool members to ensure they have valid state information for the nodes. But only the active unit can make requests from a shared IP address. So both units use static self IP addresses.

     

     

    Aaron