Forum Discussion
LTM in front of HSM
We have some Safenet Luna HSM's that require the connecting host to be in an ACL on the HSM. It doesn't use http or a common protocol. The problem we're running into is that the ACL only holds 16 ip addresses. Fine for prod, but not good for dev and qa.
When I asked Safenet about supporting a load balancer their support responded with "unless the Load balancer encapsulate the data packets and make HSM to believe that request is only for a single host in the list of IPs , After receiving reply from HSM load balancer would distributes to designated host".
I'm a newbie on the LTM outside of setting up virtual servers to front web server pools so I'm asking for help. Would this be NAT'ing the request? Can anyone give me some pointers on how to set this up on an LTM, if it's even possible?
1 Reply
- Vijay_E
Cirrus
You can use SNAT (automap or snatpool). However, each SNAT IP will provide you with 65K connections. Even if you use all the SNAT IP in the ACL (16 in total) in HSM, you will have a theoretical limitation of 16*65K (1,040 K) connections, if my understanding is right. You will hit limits as far as scale is concerned.
sol7820: Overview of SNAT features
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com