For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Doug_123818's avatar
Doug_123818
Icon for Nimbostratus rankNimbostratus
Jul 13, 2017

iRule that will log source IP's when using SNAT with LDAP

Our F5’s are one-armed with automap on all VIP’s. What I need is to log the actual source addresses going to specific VIP’s. This is for LDAP so x-forward-for doesn’t work. Thanks

 

1 Reply

  • Hi,

     

    It's hard to insert some information within an LDAP query. I think, you should consider that for those TCP services, if you do configure SNAT, your backend server will be blind.

     

    You may stop using SNAT on the Virtual Server and configure your backend server to route traffic back to the bigip.

     

    Here is an interesting write-up on that topic.

     

    Bye

     

    Yann