Forum Discussion
yeser
Nimbostratus
Dec 05, 2008it's possible to rewrite mac address?
Hi,
I have this deployment in my customer's network
Internal client sends a request to a server without going through BIG IP (It might be in this way). Default route of this server is BIG IP self ip.
Server response obviously goes through big ip via VS_FORWARDING but BIG IP forward the response to fw with its mac address and the fw detects it like IP SPOOFING. It's possible that BIG IP send the response with client MAC address?
Thanks in advance
29 Replies
- James_Quinby_46Historic F5 AccountYou can view and manipulate the MAC address information with the LINK command.
http://devcentral.f5.com/wiki/default.aspx/iRules.LINK - James_Quinby_46Historic F5 AccountI need to amend my answer. The LINK::nexthop and Link::lasthop values are read-only.
- JRahm
Admin
a vlan group in transparent mode would be an option, as would an exception map in your firewall for layer2 inspection, depending on your product. - yeser
Nimbostratus
so, anything to do via iRules? - hoolio
Cirrostratus
I don't think there is a way to modify the source MAC address from an iRule.
Aaron - Spidey_29396
Nimbostratus
Hi Jason,
we have this setup,
server > F5 > Router > client
server originally gateway to Router but we want F5 to be it's gateway, client now unable to reach the servers.
What could be the possible problem?
IP:
202.126.40.7(server) > 202.126.40.6(F5 floating IP) > Router(202.126.40.3) > 222.126.40.5 - nitass
Employee
are you using vlangroup which Jason suggested? - Spidey_29396
Nimbostratus
Hi Nitass,
Not yet.
We're suspecting that F5 is not broadcasting mac-address of servers on core router:
Do you think vlan-group will solve this problem?as per our net admin, we have to use proxy arp on F5. - nitass
Employee
sorry i was confused. if you want bigip as server default gateway, i understand server and router should be in different subnet.
anyway, if you do not want to change subnet (server and router are in the same subnet), you may have to use vlangroup. and server default gateway could still be router.
Installing a BIG-IP System without Changing the IP Network
http://support.f5.com/kb/en-us/products/big-ip_ltm/manuals/product/ltm_implementation/sol_vlans.html1062182 - Spidey_29396
Nimbostratus
Hi Nitass,
we want to eliminate snat on inbound traffic that's why we change the server's default gateway to floating ip of F%.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects