Forum Discussion
LOAD-BALANCING FOR INTERNAL TRAFFIC
Hi I want to confirm if this is feasible. We have a requirement to have internal servers initiate tcp traffic to a VS interface on the loadbalancers outside interface, which will then talke to other internal servers? This has been setup and we can have ping connectivity but when we try http the page doesnt display. On looking closer I can see that there are issues with MSS negotiations between the internal servers.
458828 IP (tos 0x0, ttl 128, id 15724, offset 0, flags [DF], proto: TCP (6), length: 52) 172.22.13.16.57876 > 172.22.14.8.8983: S, cksum 0x7926 (correct), 4215431734:4215431734(0) win 8192 458865 IP (tos 0x0, ttl 255, id 11617, offset 0, flags [DF], proto: TCP (6), length: 48) 172.22.14.8.8983 > 172.22.13.16.57876: S, cksum 0x7367 (incorrect (-> 0x0d19), 1754343263:1754343263(0) ack 4215431735 win 4380 460378 IP (tos 0x0, ttl 128, id 15725, offset 0, flags [DF], proto: TCP (6), length: 40) 172.22.13.16.57876 > 172.22.14.8.8983: ., cksum 0x4f07 (correct), 1:1(0) ack 1 win 64240 460452 IP (tos 0x0, ttl 255, id 11620, offset 0, flags [DF], proto: TCP (6), length: 48) 172.22.13.16.57876 > 172.22.13.50.8983: S, cksum 0x7291 (incorrect (-> 0xb7d8), 1927401647:1927401647(0) win 4380 461752 IP (tos 0x0, ttl 128, id 15727, offset 0, flags [DF], proto: TCP (6), length: 304) 172.22.13.16.57876 > 172.22.14.8.8983: P 1:265(264) ack 1 win 64240 461768 IP (tos 0x0, ttl 255, id 11623, offset 0, flags [DF], proto: TCP (6), length: 40) 172.22.14.8.8983 > 172.22.13.16.57876: ., cksum 0x735f (incorrect (-> 0x36cc), 1:1(0) ack 265 win 4644 460494 IP (tos 0x0, ttl 255, id 11630, offset 0, flags [DF], proto: TCP (6), length: 48) 172.22.13.16.57876 > 172.22.13.50.8983: S, cksum 0x7291 (incorrect (-> 0xb7d8), 1927401647:1927401647(0) win 4380 461895 IP (tos 0x0, ttl 255, id 11643, offset 0, flags [DF], proto: TCP (6), length: 48) 172.22.13.16.57876 > 172.22.13.50.8983: S, cksum 0x7291 (incorrect (-> 0xb7d8), 1927401647:1927401647(0) win 4380 461331 IP (tos 0x0, ttl 255, id 11652, offset 0, flags [DF], proto: TCP (6), length: 48) 172.22.13.16.57876 > 172.22.13.50.8983: S, cksum 0x7291 (incorrect (-> 0xb7d8), 1927401647:1927401647(0) win 4380 462315 IP (tos 0x0, ttl 255, id 11668, offset 0, flags [DF], proto: TCP (6), length: 40) 172.22.14.8.8983 > 172.22.13.16.57876: R, cksum 0x735f (incorrect (-> 0x36c8), 1:1(0) ack 265 win 4644
7 Replies
- Techgeeeg
Nimbostratus
Hi C2,
Just make sure you have selected Snat automap in VS configuration (This is the VS to which servers are sending the connection). I believe it will work if you have not enabled it initially.
Regards,
- c2zer0_13011
Nimbostratus
Techgeeg hi
Thanks for that, it did the trick.
- Techgeeeg
Nimbostratus
And what was that something which was stopping it from working??
- c2zer0_13011
Nimbostratus
Yes once this was changed on the VS the page was displayed.
- Techgeeeg
Nimbostratus
You mean you just enabled the snat on the VS?
- c2zer0_13011
Nimbostratus
Yes we enabled the snat on the specific VS and http traffic started to work, where as it did not work prior to this change.
- Techgeeeg
Nimbostratus
ok that's great vote my answer pls... :P :)
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com