Forum Discussion
iRules conflicting with SNAT'ed requests
I've F5 BIGIP 8900 running TMOS 10.x. My configuration is one-armed wherein client and server blades lie on same network. To avoid server blades responding directly to client, i'm SNAT'ng the requests once the F5 load balancing is executed. Distribution is done via iRules which use IP address contained within the request PDU.
My problem is while the server blades respond back to F5 (on return path), final response never reach the final destination (client). It seems F5 is not routing the response out to Client. When i remove the iRule from VS config and use a default pool of server blades, i get the correct behaviour. Responses are correctly routed back to client via F5.
Clearly, something doesn't work in favour of iRules. Did i miss any critical configuration portion ?
2 Replies
- Richard__HarlanHistoric F5 AccountI would check the /var/log/ltm log file for errors from the iRule, this will point you in the correct direction.
- Mohamed_Lrhazi
Altocumulus
Use tcpdump to findout what's happening.
final response never reach the final destination (client)
why? does it leave the LTM with wrong destination IP? or does not leave the LTM at all? is this TCP or UDP? what protocol is it? what does the iRule do? does it use "snat"? or the SNAT enabled on the virtual server level only?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
