Forum Discussion
jmloveless_4477
Nimbostratus
Dec 19, 2009LC SNAT Issue
I have a pair of LCs with 3 ISPs. We are using one isp solely for inbound production services (web,ftp,mail,etc). I have VIPs set up for these services and snat for some of the services like mail. My problem is the snat connections are not going out the right ISP. They have the right snat address (ISP 1 Subnet)but are routing ISP2 and ISP3. This is creating an asymmetric routing that ISP3 is blocking which is causing sporadic issues. Any ideas why this would be taking place?
7 Replies
Sort By
- hoolio
Cirrostratus
Hi, - jmloveless_4477
Nimbostratus
Thanks for the reply, no this is not resolved, I am using a work around but its not ideal. This is for outbound traffic, the connection is nated to the correct SNAT address but then still following the default gateway pool. - hoolio
Cirrostratus
Can you post an anonymized copy of the VIP (b virtual VIP_NAME list), gateway pool (b pool POOL_NAME list) and routing table (netstat -nr) to clarify the configuration? - jmloveless_4477
Nimbostratus
List did not work for virtual so I provided the show, let me know if this not what you are looking for. The VIP is currently disable. Thanks for your help! - hoolio
Cirrostratus
It looks like you're using simple (source address) persistence on the default gateway pool. Can you change this to destination address persistence and see if the issue clears? - jmloveless_4477
Nimbostratus
I will try, is there a way to clear current persistance connections? - hoolio
Cirrostratus
You can use the 'b persist' command to manage the persistence table and 'b persist help' for command usage details. If you change the persistence method on the pool though, I don't think any other persistence record from a different persistence method would be considered valid. So you probably don't need to clear the records.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects