Forum Discussion
ucriola_95120
Nimbostratus
Mar 23, 2010MQ Series
Hi All,
I was wondering if anyone else may have run into this issue, I have confgured a server in line with our F5 LTM (ie, no SNAT, servers default gateway is the F5) and im able to ge...
L4L7_53191
Nimbostratus
Mar 23, 2010Two things stand out, mostly as a hunch based on a quick scan of the info found here: http://www.capitalware.biz/dl/docs/MQFirewalls.pdf . It sounds like you may have already done some or all of this, but just in case...
1) For your return traffic sourcing from the queue, be sure and create a SNAT address that matches your external facing VS address. So create that in a snat pool, then bind that to your 0.0.0.0 VS. This way your queue consumers will see nothing but the BigIP VS address no matter how the traffic is flowing.
2) You may need to disable port translation, especially on the external facing VIP. If the LTM translates that port either way it could break. I'm thinking that a flow like this is what may be causing your problem (again just a guess after only a few minutes of looking at that slide deck on firewalls and MQ):
src_address:src_port --> Vip_addr:1414 -->(client src_port translation may occur here)-->MQ server
So when MQ "responds", it may be that it's trying to use to this tuple: client src_address:translated src_port, in which case it'll break.
Please update this post so we'll all benefit from your work! IMO there's a bunch more of this type of design in our future, so thanks for the post.
-Matt
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
