Forum Discussion
Mike_Harpe_6170
Nimbostratus
Oct 05, 2010Issue with SharePoint 2007 behind BIG-IP LTM 9.4.8
Two SharePoint 2007 servers behind an F5 BIG-IP LTM. Doing SSL offload on client side. Server side is port 80 in the clear.
User starts a session. Sniffer trace shows SSL handshake happens. ...
Ryan_Korock_46
Oct 05, 2010Historic F5 Account
I think Helen hit the nail on the head. In almost all load balanced environments (the exception being the npath/direct server return corner case), return traffic from the servers will need to pass back through the load balancer before it makes it back to the client.
Most implementations accomplish this by putting the servers 'behind' the BIG-IP, and point the default gateway of the servers at the BIG-IP.
Others will use SNAT functionality on the BIG-IP to swap out the source IP of the connection as it passes through the BIG-IP on its way to the servers. Now the servers will see the source IP being that of the BIG-IP, and send all return traffic towards it. This option allows you more flexibility in how you configure your servers routing tables, but has the drawback of making it look like all the connections were originated from the BIG-IP.
So Mike.... I would check 2 things. Are your servers pointing to the BIG-IP as their default gateway? If not, and you dont want to change their routing, check to see if SNAT is enabled on the VIP/BIG-IP.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects