Forum Discussion
IvyPhamLe_15115
Nimbostratus
Apr 16, 2014LBM for internal vlans,
Hello,
Our team has inherited the F5 with Chassis serial number is bip216816s, and i'd like to test the simple LBM web server for our lab.
This is our network:
We have around 20 internal VLANS inte...
Cory_50405
Noctilucent
Apr 17, 2014Change your virtual server to SNAT auto map and see if this fixes your issue.
- IvyPhamLe_15115Apr 17, 2014
Nimbostratus
Thanks for your reply, but it's still not fixed. - Cory_50405Apr 17, 2014
Noctilucent
Try doing a tcpdump on your BIG-IP to see what communications are going between it and the servers: tcpdump -nni 0.0 host 10.10.10.10 or host 10.10.10.11 - IvyPhamLe_15115Apr 17, 2014
Nimbostratus
Under System>Console, i ran the command, i got the message below BIGpipe parsing error: 012e0008:3: The requested command (tcpdump -nni 0.0 host 10.10.10.11) is invalid - Cory_50405Apr 17, 2014
Noctilucent
You'll need to do this from CLI, in the bash shell. To get to bash from TMSH, type 'run util bash' - IvyPhamLe_15115Apr 17, 2014
Nimbostratus
Is the System>Console is the CLI ? The console is the only option where we can type the commands in. - Cory_50405Apr 17, 2014
Noctilucent
You should be able to SSH to the BIG-IP using Putty or some other SSH client. - IvyPhamLe_15115Apr 17, 2014
Nimbostratus
This is my version BIG-IP 9.4.5 Build 1049.80 Final. Sorry i am still finding how to open the bash shell and TMSH - IvyPhamLe_15115Apr 17, 2014
Nimbostratus
Now I can have the tcpdump on host 10.10.10.10 and .11, what would we expect to see ? - Cory_50405Apr 17, 2014
Noctilucent
You are looking for two way traffic between the BIG-IP and your two servers. Look to see if a three-way handshake is completing (SYN, SYN ACK, ACK). Feel free to post the tcpdump results here for us to take a look at. Though if there are sensitive IP addresses used, you might want to sanitize those before posting. - Cory_50405Apr 17, 2014
Noctilucent
Okay, so your BIG-IP (10.10.10.13) is attempting to contact the server (10.10.10.10) on port 80. You can see the SYN packets leaving the BIG-IP on vlan 300, but no SYN ACK ever comes back from the server. ARP is working, so layer 2 looks to be good. Is there a firewall or some other device that could be blocking the packets from getting to your 10.10.10.10 server?
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects