Forum Discussion
drhawkings_2156
May 04, 2010Nimbostratus
LTM migration for Proxy, Anti-Spam and web servers
Can anyone advise on the configuration of LTM for Proxy, Anti-Spam and web servers?
The objective is to load balance server traffic or active/passive.
Attached is the diagram
The confusion is whether to apply or not SNAT for inbound and outbound traffic.
- Michael_YatesNimbostratusThe F5 LTM is a Proxy.
- hooleylistCirrostratusIn addition to Michael's helpful comments...
- drhawkings_2156NimbostratusAnd all inbound connection or client connection source IP (example 10.10.10.10) address must not change. Otherwise proxy server cannot sees the client IP. Same goes with Anti-Spam server.
- Michael_YatesNimbostratusIf you don't have to use SNAT'ing, I wouldn't.
- drhawkings_2156NimbostratusDoes that means that SNAT natted client IP address (direction traffic from client to F5) which means ingress to F5? or
- Michael_YatesNimbostratusClient (10.10.10.10) to F5 Load Balancer (20.20.20.20) to Server (30.30.30.30)
- hc_andy_35682NimbostratusYou can do away with SNAT if you create a self IP and floating IP on the LTM. This means you'll need 3 IP's per inside vlan - one for the active unit, one for the standby unit and one floating IP across both units (provided you have a HA set up).
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects