Forum Discussion
sachin_80710
Nimbostratus
Sep 04, 2014Link Controller - Create Link(ISP) object
Hi All,
I have to install LC, Need your suggestions and help on configuration. I don't want to do any changes(no NAT changes) on existing customer firewall.
1) My LC deployment architecture...
StephanManthey
Nacreous
Sep 05, 2014The link definition will specify the next hop for outgoing connection from the LC´s perspective.
So it will be the "internal" interface of your ISP router which can be reached locally from your LC. These interfaces (typically you are using two or even more ISP links) will be grouped as well in a "default_gateway_pool" which should be assigned as default route to your LC in the network settings. (At least in the past this was a mandatory step to get the LC automatically configured as a server in the GTM configuration [LC is a hybrid of LTM & GTM].) When forwarding requests (initiated by internal) clients to servers in the public internet somehow you need to make sure the responses will be routed back properly and symmetrically (return via same ISP link). This can be achieved by applying SNAT for outgoing traffic. To capture outgoing traffic a wildcard network virtual server 0.0.0.0/0 has to be configured to listen on the LC´s internal interface. It will run in PerformanceL4 mode, with SNAT automap (requires floating self IPs on your interfaces towards the ISP router) use the default_gateway_pool and has the destination address affinty profile as recommended by Chris. By default, the BIG-IP will SNAT only tcp and udp. To SNAT i.e. ICMP or ESP as well, you need to enable it first, please:tmsh modify ltm global-settings general snat-packet-forward enabled
tmsh save sys config
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
