Forum Discussion
Raymond_Feng_97
Jul 20, 2006Historic F5 Account
how to persistant client when using bigip load balance firepass
There is two problem when using bigip load balance firepass:
1> For ADSL client, when user logon the firepass, his adsl line dropped and reconnected adsl, so the client ip address had been change...
blacksan_10396
Nimbostratus
Dec 11, 2006This last i-rule is passing all of our bigip/firepass testing except one minor one.
Many-users behind one NATed IP Address on the Internet (AOL Mega-proxy and companies Internet Access). I personally don't consider this a major problem but it can cause performance issues if all users from one company NATed IP hits the same firepass.
Any chance the I-Rule can remove the source-IP-Address persistence after the sid-cookies has been established?
Right now this is my concept on how everything works:
FYI - No Default/Fallback persistence enabled, only I-Rule.
1 - user A hits the BigIP VS
2 - I-Rules Activates
3 - BigIP selects a Firepass member and I-Rule gets no "MRHSession" cookie plus I-Rule assigns a Source-IP-Address to persistence table
4 - user A hits Firepass Login Page
5 - user A login and gets a "MRHSession" Cookie, I-Rule adds Universal sid-cookie to persistence table.
6 - user A connection successful
7 - new user B hits the BigIP VS from same IP Address as user A
8 - persistence table assigns user B to the same Firepass due to Source-IP-Address in persistence table
9 - user B hits Firepass Login Page
10 - user B login and gets a "MRHSession" Cookie, I-Rule adds Universal sid-cookie to persistence table.
11 - user B connection successful
12 - user A decides to "roam" and changes IP Address
13 - persistence table keeps users on the correct firepass due to Universal sid-cookie and the I-Rule adds New Source-IP-Address to persistence table
14 - user A connection sucessful
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
