Forum Discussion
rlb63_75866
Jul 11, 2011Nimbostratus
IPsec VPN behind a GTM/Link controller
We are using a GTM/Link controller to load balance multiple internet links all in front of a firewall/vpn device.
The outside interface of the firewall terminates the vpn traffic and is setup as an LTM pool listening on any port
We have multiple ltm vip's also listening on "any" port facing the internet.(Performance L4 with any protocol, address translation but no port transtlation) with a resource of the previously mentioned ltm pool
The vpn client is using NAT-T (udp port 4500) and can connect successfully. After the ike phase 1 initiation and response, the udp traffic starts with some high source port from the client to the vpn/vip on port 4500.
Within a minute and a half, the client disconnects. A capture at the vpn device shows that it is responding to traffic from the original source port as well as another source port.
A tcpdump at the vlan interfaces of the gtm/ltm do not reflect this ... the dumps only show the original client source port.
AND, if we run a tcpdump on the vlan interfaces of the F5 to observe the client traffic, the client appears to stabilize and not drop.
has anyone observed this behavior? any ideas?
Thanks
- The_BhattmanNimbostratusWhat type of IP forwarding did you use to handle the IPSEC Tunnel? My thought is that you use a Virtual Forward set to ALL Protocols.
- rlb63_75866NimbostratusThanks
- Spidey_29396Nimbostratusrlb63, can you share the step by step procedure in making the VPN tunnel UP? Our Current setup
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects