Forum Discussion
jondyke_46152
Nimbostratus
Jun 25, 2008IP address restriction to IIS
I have some virtual directories in IIS that are locked down by IP address. As now all traffic to my servers is coming from the IP of the 'loadbalancer' not the source IP of the client how do I get around this problem?
Would it be better to allow the load balancer to handle this or is there a way of passing through IP addresses?
I am suspecting that an irule is the way forward but the ones available only seen to be allow/deny on ip to a whole virtual server. I want to allow/deny at virtual deirectory level.
- Deb_Allen_18Historic F5 AccountDo you need to translate the source address for response traffic to return to the load balancer? (iow, is some other device besides LTM the default route for the servers?)
- hoolio
Cirrostratus
Here is a post with some related info: - jondyke_46152
Nimbostratus
Ok - may help if I give a bit more detail:- - jondyke_46152
Nimbostratus
Just reading the other thread again and it may be that's all we need to do is switch of address translation and set the gateway IP's of each client to the load balancer. All of our nodes have different IP addresses so I am guessing this is an option? Is this just a case of unticking address translation in the VS settings? What if a server needed to talk out directly not though the load balancer? - hoolio
Cirrostratus
You can set SNAT to none on the virtual server. Leave address translation enabled as that refers to destination address translation. As long as the web servers' default gateway is set to the BIG-IP, that part will work. If you want to allow outgoing connections from the servers through the BIG-IP, you can configure a forwarding virtual server (IP forwarding with SNAT enabled). If you only want to allow traffic from the web servers to pass though this VIP, enable it only on the VLAN they're on.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects