Forum Discussion
Danny_Arroyo
Oct 07, 2014Cirrus
How to generate traffic from a VIP on the F5
In many cases I am asked if I can generate traffic from a VIP on the F5. In other words, I am asked to initiate a communication from a VIP that exists on the F5. Lets say a VIP on the F5 was actual...
gsharri
Oct 07, 2014Altostratus
It is possible to have the source address of node initiated outbound traffic appear to come from a vip . You will need to translate the server (node) source address to the vip on the way out. Nodes are not allowed, by default, to initiate connections out through the bigip.
One way to allow this create a snat where the translation address=vip and address list includes the servers source IP. Enable the snat on the source vlan only (the vlan where the server's outbound connection originates).
Another method which allows outbound connections is the forwarding (ip) virtual server type. You will need a snat pool that contains the vip address. Assign that to the fwd(ip) VS. The fwd virtual allows you to control the destination to which the traffic is allowed and you could use iRules to perform more selective traffic processing. Again enable the fwd VS only on the vlan where the nodes connection is originating.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects