Forum Discussion
How to Check Actual Source IP when SNAT-Automap is enable.
Hi All,
We have a VS configured with SNAT-Automap enabled. Due to some requirement we would like to check the actual requestor source IP sending traffic towards Pool members, as of now it's showing Self Floating IP. Please advise.
Regards
- uzair
Nimbostratus
-
Can we make snat to NONE
-
Are you looking to log client connection to vip? or from client to vip and corresponding connection from F5 to pool member?
For logging via iRule check below link. (https://devcentral.f5.com/Wiki/iRules.An_iRule_to_log_who_is_accessing_your_site.ashx)
-
- rct
Nimbostratus
Hi Uzair,
If you are deploying an HTTP virtual server, or an HTTPS virtual server with offload or SSL-briding, you may be able to make use of an additional HTTP header, X-Forwarded-For. This will actually add the client-IP address to the webserver logs. Please check K4816. It may be the solution that you are looking for.
(https://support.f5.com/csp/article/K4816)
K4816: Using the X-Forwarded-For HTTP header to preserve the original client IP address for traffic translated by a SNAT.
- Lee_Sutcliffe
Nacreous
If this is HTTP/S traffic, consider using an X-Forwarded-For header
https://support.f5.com/csp/article/K4816
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com