For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Spidey_29396's avatar
Spidey_29396
Icon for Nimbostratus rankNimbostratus
Mar 06, 2014

load balancing inquiry

I have a LTM, VS is 10.10.10.1 and pool server of 172.16.20.111 and 172.16.20.112 which uses 300 different tcp ports but i configured it ANY, i have VS wildcard(SNAT AUto-map) for connection of server pool to external vlan.

 

I have client 10.10.10.5, when i initiate connection to vs(10.10.10.1), no problem.

 

Here's the problem, client wants to open all 300 ports, for example port 9999

 

from 172.16.20.111 and 172.16.20.112, initiate traffic to 10.10.10.5, in our lab, they use "telnet 10.10.10.5", now when 10.10.10.5 sends traffic using port 9999 , both 172.16.20.111 and .112 receives the traffic, client wants only one server will receive it. Is there a way?

 

16:55:34.320241 IP 10.10.10.5.distinct > 10.10.10.2.44990: P 3958366787:3958366853(66) ack 2101193945 win 258 16:55:34.320257 IP 10.10.10.5.distinct > 172.16.20.112.44990: P 3958366787:3958366853(66) ack 2101193945 win 258 16:55:34.320290 IP 10.10.10.5.distinct > 10.10.10.2.51213: P 2524488983:2524489049(66) ack 2229976739 win 258 16:55:34.320307 IP 10.10.10.5.distinct > 172.16.20.111.51213: P 2524488983:2524489049(66) ack 2229976739 win 258

 

1 Reply

  • Not sure if I understood you need, but you can try bigip report: https://devcentral.f5.com/wiki/iControl.Powershell-BigIP-Report-Generator.ashx?NoRedirect=1Requirements_2&NS=iControl

     

    Or you can try this version. I rewrote it a bit so it exports the config to csv files in case that's what you need: http://climbi.com/b/0hconu

     

    /Patrik