Forum Discussion
rmd1023
Mar 10, 2012Nimbostratus
Monitoring traffic vs forwarding virtual server
So, I've got a pair of HA LTMs running in layer 3 mode. Most of my virtual servers are using SNAT so that the virtual server traffic flows through the LTM but the LTM isn't the default gateway for the VLANs hosting the real servers. The exception is one VLAN, 10.0.213.200/29, which is a stub VLAN that lives behind the LTM and for which the LTM is the default gateway. I've got a floating IP, 10.0.213.201, and two physical self-ips - .202 and .203 - one on each of the LTMs.
I've got two forwarding virtual servers handling traffic on and off of that vlan. The one that handles traffic to the stub VLAN is written to handle traffic for the entire 10.0.213.200/29 network.
The problem is that the active LTM, which is hosting the .201 shared and .202 specific self-IPs, won't reply to pings for those IPs. I assume it's because the forwarding virtual server is picking up the traffic and trying to forward it rather than letting the LTM say "hey, that's one of my IP's, I can answer that ICMP echo request!"
Is there a way to get around this? Should the forwarding virtual server not handle traffic for the whole network range?
Thanks,
--r
- nitassEmployeehave you enabled ARP of that network virtual address i.e. 10.0.213.200/29?
- rmd1023NimbostratusI have not, since I don't want it to proxy arp. But I wouldn't think it's a matter of responding to ARPs - it's a layer 3 device and routing is working happily, so things upstream are routing the packets to the outside IP of the LTM, and the LTM is picking up the packets.
- nitassEmployeewhat about this one?
- rmd1023NimbostratusSure enough, that looks like the situation I'm in. I had poked around in the KB but I missed that article.
- nitassEmployeehe is my brother. :-D
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects