Forum Discussion

bwilliam's avatar
bwilliam
Icon for Cirrus rankCirrus
Jun 02, 2015

Mobileiron Sentry using LTM 9.1 not distributing connections

I recently inherited the management of our F5's and have a question. Were migrating to new LTM 2000's, but until then I need to work out a problem we are having on our production F5's. Hopefully, someone has the same type of configuration and can provide some suggestions.

 

The configuration uses Mobileiron Sentry, which connects to our exchange VIP. The VIP is using port 443, has a standard type, with an http profile of http-xforwarded and is using SNAT Pool with Auto Map. The VIP connects to a single pool with two members, using a default persistence profile of source_addr_1hr. The pool is configured, using an https health monitor, allowing SNAT and NAT, load balancing with least connections and use an irule to drop http request to the specific sentrys.

 

Now the problem. The MI Sentry is outside the LTM, it connects to the LTM and establishes a connection to a server. When mobile devices connect to access email, they are going through the Sentry and connecting to the server established by the Sentry. The thought was to remove the persistence, but if the Sentry never drops its connection, will removing it have any impact. Is there a way for the F5 to see all the traffic coming from the MI Sentry and allowing the pool to manage the traffic, so the connections are equally distributed between the servers.

 

Thanks in advance for all help. Bret

 

No RepliesBe the first to reply