For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Abi80_167352's avatar
Abi80_167352
Icon for Nimbostratus rankNimbostratus
Sep 17, 2014

loadbalcing with 2 records

Is it possible to have 2 different global Ips point to one VIP on the F5 . If yes what are the prerequsits

 

6 Replies

  • Are you talking about DNS pointing two names to a single IP, or a single VIP listening on multiple addresses?

     

  • So then yes, sort of. You cannot specify multiple single addresses for a VIP, but you can define a subnet-based range of addresses, and then use either an iRule or IP filter to limit access to specific addresses.

     

  • Hi kevin Thanks for the reply Let me explain you the setup to a much clearer picture

     

    I have my webserver in netherlands which is behind a FW . My dns name resolves to my Gloabl Ip which is configured on the FW which inturn is natted to F5 VIP

     

    the requirement is for US users who are acesssing these servers should hit US firewall they should be comming from US firewall which will also have a different DNS name which will resolve to the Global Ip on the FW which will be pointing to the same VIP

     

    can this be achieved

     

  • Okay, so then it was the other use case. There are two different DNS names that need to point to the same IP address. If that's the case, then it's probably much easier to implement than multiple IP listeners on a single VIP. Your DNS server (GTM?) just has to point both DNS names at the same IP.

     

  • shaggy's avatar
    shaggy
    Icon for Nimbostratus rankNimbostratus

    That shouldn't be a problem as F5 matches traffic based on destination IP/port, not hostname. If it is an HTTPS application, you may run into SSL issues if the web-server's SSL certificate is not configured with the necessary common name/subject-alternative-names.