For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

paulpatriot_129's avatar
paulpatriot_129
Icon for Nimbostratus rankNimbostratus
Dec 17, 2013

load balancing to log servers SNAT shows as the source

We are trying to load balance log servers on a different subnet then the F5. When we do this the SNAT address shows up as the source instead of the actual server. So the logs look as if they are coming from the F5 instead of the actual source. Is there anything I can do so the actual source ip shows the device that sent the log. Thanks

 

4 Replies

  • giltjr's avatar
    giltjr
    Icon for Nimbostratus rankNimbostratus

    Will SNAT is source NAT, it is doing exactly what you want it to do.

     

    What type of logging? Standard syslog udp 514? If so then you should not need SNAT, but then again, if you are doing standard syslog udp 514, I don't think load balancing to different syslog servers is a good idea.

     

  • giltjr's avatar
    giltjr
    Icon for Nimbostratus rankNimbostratus

    Not much you can do. SNAT is working as designed.

     

    I am assuming that you are doing something to make a specific source server to always go to the same target server.

     

    Otherwise you could have syslog messages from the same source going to different syslog servers.

     

  • giltjr's avatar
    giltjr
    Icon for Nimbostratus rankNimbostratus

    IP does not have a "original" IP address or "original" device identifier.

     

    What you MIGHT be able to do if you have a enough IP addresses in the subnet your syslog server is on is do a static one-to-one SNAT. So that each real device has a specific SNAT address. This assumes you don't have a ton of devices though.