Forum Discussion
How to nexthop all requests from VPN clients?
- Sep 17, 2025
Hello,
You have to create a new Performance L4 Virtual server with destinatin IP 0.0.0.0/0, port * and protocol ANY
Set as default pool a pool which will have as pool member the router you want to use
Enable Virtual server only on specific vlan and select the vpn tunnel you are using
Deselect Destination address translation
With the above all traffic from vpn will be catched by the new VS and forwarded to the router you want.
I would create a new route domain with a default gateway to this router and route the VPN traffic into this route domain. There is a route domain assignment action in the VPE.
- Injeyan_KostasSep 18, 2025
Nacreous
Definitely gonna work too.
Just a note that a new vlan is needed in this case, assigned to the new route domain. Vpn subnet needs to be routed back to the floating IP of the new vlan. Strict Isolation might also need to be disabled both in default and new route domain.
- LarsKristenssonSep 18, 2025
Altocumulus
There is currently no separate VLAN between the BIG-IP and the central router. While one could be created, I would prefer a solution that doesn't require it.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com