Forum Discussion
Least connection Method : Load balancing algorithm is not working as expected
Hi All,
Least connection method is not working as expected when used with source affnity persistance. All traffic is diverted to single server. I would like to let you know that Natting ( Public IP to Private IP) has been done on FW with the VIP ( contains two pool members in Pool).
Please let me know what need to be done to get the connections load balance across pool members.
Is it possible get it done using this way Or need to go with cookie persistance..If possible, what need to be done.
Please help !!
Thank you in Advance.
Regards, Rajneesh
6 Replies
Hi
Do you source nat the connection? If you have an http profile cookie persistence is generally recommended. :)
Don't forget to encrypt the cookie for security reasons!
https://support.f5.com/kb/en-us/solutions/public/14000/700/sol14784.html
/Patrik
- Amanpreet_Singh
Cirrostratus
Hi Rajneesh,
The problem is not with the combination of Source Affinity with Least connection. The problem is using NAT on firewall and using source affinity. LB is assuming all the connections to be originating from a single client IP. Have you tried using "only Destination NAT" with LB having default route towards firewall? (assuming it as a traffic coming from Internet)
Regards, Aman
- Amanpreet_Singh
Cirrostratus
The other reasons I found hypothetically as - 1. If you are running below HF versions with known issue of uneven load balancing https://support.f5.com/kb/en-us/solutions/public/16000/400/sol16487.html?sr=46343907 2. If you have OneConnect profile enabled for this virtual server https://support.f5.com/kb/en-us/solutions/public/2000/000/sol2055.html 3. For the sake of information- https://support.f5.com/kb/en-us/solutions/public/10000/400/sol10430.html - t_rajneesh_2252
Nimbostratus
Thanks Amanpreet. Image and hotfix details running currently on box. ALso we are not using anyconnect profile here Image: BIGIP-11.6.0.0.0.401.iso HF: Hotfix-BIGIP-11.6.0.4.0.420-HF4.iso Model: BIG-IP 2200 - Amanpreet_Singh
Cirrostratus
Hi, Ok, that should not be a issue. Try to avoid Source Affinity when you are using NAT on firewall. Source persistence. "Source address affinity persistence directs session requests to the same server based solely on the source IP address of a packet" If your traffic is HTTP, I would rather suggest to go for cookie persistence.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
