Forum Discussion

Korai_331784's avatar
Korai_331784
Icon for Altostratus rankAltostratus
Sep 20, 2018

Inside Server Cant reach Internet through F5

Hi,

 

we have inside server and needs to allow internet access to that server through F5 node.based on the requirement I configured IP forwarding virtual server with SNAT (public IP) to Internet.

 

I can see traffic on Internet firewall that NAT happening on F5 but still internet website is not accessible. I configured IP forwarding Virtual server as per attached pic.

 

Please suggest if anything I needs to do to fix this issue.

 

  • Hi Korai,

     

    How is name resolving configured on the inside server? Also through the F5 forwarding VS? If that is the case, you need a forwarding virtual server that is listening on port 53 (DNS). Or modify the virtual server to listen on all ports.

     

    You crossed out the destination IP in the forwarding virtual server so I think you put one of your own IP-addresses there. In a forwarding virtual server, the destination should be 0.0.0.0/0

     

    Hope this helps.

     

    Regards,

     

    Martijn

     

    • Korai_331784's avatar
      Korai_331784
      Icon for Altostratus rankAltostratus

      Hi,

       

      Thanks for response, Yes I put destination as 0.0.0.0/0 as its towards internet. regarding port 53 for DNS, I can test it with all ports but we have flow like this

       

      host----proxy----fw---ip_forwarding_VS----Internet

       

    • MvdG's avatar
      MvdG
      Icon for Cirrus rankCirrus

      HI,

       

      So the proxy will setup the connection to the internet. Correct?

       

      So the proxy must be able to contact DNS servers and do HTTP and HTTPS. If you do not use an internal DNS server, but one on the internet, the forwarding VS must be configured to listen on port 53 also. This means a second VS or a VS configured with all ports.

       

      Did you look create network traces to see what is going on?

       

      Regards,

       

      Martijn

       

  • Hi Korai,

     

    How is name resolving configured on the inside server? Also through the F5 forwarding VS? If that is the case, you need a forwarding virtual server that is listening on port 53 (DNS). Or modify the virtual server to listen on all ports.

     

    You crossed out the destination IP in the forwarding virtual server so I think you put one of your own IP-addresses there. In a forwarding virtual server, the destination should be 0.0.0.0/0

     

    Hope this helps.

     

    Regards,

     

    Martijn

     

    • Korai_331784's avatar
      Korai_331784
      Icon for Altostratus rankAltostratus

      Hi,

       

      Thanks for response, Yes I put destination as 0.0.0.0/0 as its towards internet. regarding port 53 for DNS, I can test it with all ports but we have flow like this

       

      host----proxy----fw---ip_forwarding_VS----Internet

       

    • Martijn_144688's avatar
      Martijn_144688
      Icon for Cirrostratus rankCirrostratus

      HI,

       

      So the proxy will setup the connection to the internet. Correct?

       

      So the proxy must be able to contact DNS servers and do HTTP and HTTPS. If you do not use an internal DNS server, but one on the internet, the forwarding VS must be configured to listen on port 53 also. This means a second VS or a VS configured with all ports.

       

      Did you look create network traces to see what is going on?

       

      Regards,

       

      Martijn

       

  • can you share packet capture filtered by nat address and do you configure any route domain in the appliance or just default ?? if yes make sure that SNAT address and destination address in the same route domain percentage that you want to forward traffic to it.