Forum Discussion
Maverick_80689
Nimbostratus
Sep 10, 2014Internet access doesnt work with LB as gateway and snat disabled but if we use a snatpool it works. Does anybody know why?
Internet access doesnt work with LB as gateway and snat disabled but if we use a snatpool it works. I am not sure what will be the source addr of outbound internet traffic when it passes through our ...
Maverick_80689
Nimbostratus
Sep 11, 2014Ok here are the answers:
- Snatpool has only one ip address.
- LB is the default gateway and both the client and snat addr are private since we have a firewall in front of LB.
- Firewall is allowing the complete subnet that includes client pool members, lb self ips and vip subnet.
So the outbound traffic without snatpool will have the client as the source ip addr but i dont see that traffic hitting the firewall. But when snat pool is enabled, it goes through to the internet using firewall pat ip addr. It seems that LB is dropping traffic initiated from pool members if we dont enable snat.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
