Forum Discussion
robert_blair_75
Nimbostratus
Nov 05, 2009Monitoring Traffic?
I am running Big-ip 9.4.8
Setup:
ExternalA network:
- 10.10.10.0/24
ExternalB network:
- 20.20.20.0/24
Internal network:
- 30.30.30.0/24
Default_gateway_virtual_server
- Network: 0.0.0.0
- Pool: default_gateway_pool
- SNAT: Automap
Pool: Default_gateway_pool
-members: 10.10.10.1 & 20.20.20.1
Floating Self ip:
- 10.10.10.5
- 20.20.20.5
- 30.30.30.5
Virtual Server
- Ip: 10.10.10.100
- Pool: webserver
- Disabled
Virtual Server
- Ip: 20.20.20.100
- Pool: webserver
- Disabled
Pool: webserver
- node: 30.30.30.100
- no monitors on pool or members.
I am seeing some interesting traffic via TCPdump:
- Using TCPdump on the external vlans; I am seeing traffic from both external self ips (10.10.10.5 and 20.20.20.5) to the virtual servers 10.10.10.100 & 20.20.20.100 with a variety of ports (I assume this due to SNAT).
- TCPDump does not show the destination host traffic on the internal vlan.
- Found “Inet port exhaustion on 20.20.20.5 to 20.20.20.100:445 proto 6” in the local traffic log.
- Found “Inet port exhaustion on 10.10.10.5 to 10.10.10.100:1433 proto 6” in the local traffic log.
The monitors I do have defined are monitoring the internal ips 30.30.30.x, It appears that the Bigip is generating this traffic but I do not see why? Any insight would be great…
- hoolio
Cirrostratus
Hi Robert, - robert_blair_75
Nimbostratus
Aaron, - hoolio
Cirrostratus
Do you have clients originating traffic through a SNAT to the virtual servers? I'd guess this might be web server to app VIP type traffic. You could check the connection table using 'b conn all show all' to see who the clients are. - robert_blair_75
Nimbostratus
Clients do not access via SNAT (External ->Inbound Wide IP->Virtual Server) - hoolio
Cirrostratus
If you look at the full 'b conn all show all' output, do you see any client IP addresses who have a source port the same as one of the self IP connections? For example, from your last post, was there another connection also from port 52364? - robert_blair_75
Nimbostratus
Hopefully I am answering your question correctly, I searched the output for port 52364 as an example. - The_Bhattman
Nimbostratus
Yes. However, be aware that there is a limitation which are fixed on certain software branches and others still remain - hoolio
Cirrostratus
That's still quite curious. So you have GTM running in the environment? Is it an LTM/GTM combo or separate units? - robert_blair_75
Nimbostratus
This is a pair of 9.4.8 LTM running High Availability. - robert_blair_75
Nimbostratus
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects