Forum Discussion
LJB_107563
Nimbostratus
Aug 28, 2008ICMP from the server pool
I have what is probably a really basic question, but I cannot find an answer in any of the ASM docs.
I have a pair of ASM 4100's that I have just started to configure. These are setup as inline active passive.
Behind them, I have two web servers in different pools with separate VIP's.
I have SNAT's setup so that the server owners can access those servers for maintenance.
From the actual server on the backside (pool) they cannot ping anything beyond the F5's. Do I need to create another SNAT for the reverse? The customers are freaked out that they cannot ping out from the servers, even though they really don't need too.
Thanks,
Len
- hoolio
Cirrostratus
Hi Len, - LJB_107563
Nimbostratus
I have two VIP-Pool mappings. One for the http/s service and the other for any port/protocol. I built the SNAT and everything is working perfectly, I just cant ping from the server to the public side. - hoolio
Cirrostratus
Are you able to make a TCP based request from the hosts to the destination they want to be able to ping through the SNAT? If so, you should just need to set the global option for SNAT packet forwarding to 'All Traffic'. - LJB_107563
Nimbostratus
Yes, they can access any service (backup, ftp, etc) to any server, but to those same servers, no icmp... - LJB_107563
Nimbostratus
DOH!
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects