Forum Discussion
Tom_Bell_15050
Nimbostratus
Jun 29, 2010Issues getting second F5 to answer on real world IP
We have a mirrored configuration. Namely an ASA forwarding traffic to a F5 serving traffic from a pool of nodes behind it.
At one site we've successfully setup and tested the following. ...
Tom_Bell_15050
Nimbostratus
Jun 30, 2010First up, thanx for your replys guys.
Chris: From the functioning F5 I'm able to telnet to the VIP on 443 (https) and I get a socket. On the second F5 I'm unable to telnet to port 80 (http) on the VIP I infact get a "No route to host" error even though there's a route in the route table for this address range.
Michael: Both F5's have IP's in all of the relevant networks. All other currently configured VIP's function as expected. I've played with SNAT on or off and see no change in behaviour. If I disable the VIP I see the F5 send a RST packet back to the client otherwise nothing. Also with SNAT on, even on working networks, I've noted using automap that the F5 seems to pick random IP's to SNAT behind .. and often these IP's arent even on the network it's SNAT'ing into. I've used static NAT entries in some instances to resolve this.
Watkins: Both virtuals in these examples are serving HTTP or HTTPs data I've tried both configurations on either side. The working F5 will do either happily and obviously the borked one will do neither. Out networks are pretty messed up and I've been tasked with their simplification which is why I'm trying to get these IPs onto the F5 in the first place, as a consquence I've been chasing routing loops for a fortnight and have nearly all of them resolved and am basically certain that there isn't one in this case. The pool I'm using as a test case has only 1 node .. and running tcpdump on this host shows that it's not seeing ANY packets related to this query, so I'm kinda certain for some reason the F5 has decided not to answer ? as to why ? Thats why I'm here.
Thanks again guys
Tom
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects