Forum Discussion
My first iRule
Hi, I'm hoping, and pretty sure this is a simple one, but I am not sure exactly how to accomplish the following: Our customer wants their real servers/nodes to be able to reach their own VIP and get load balanced. The nodes are in routed mode pointing to the F5 as their gateway in the ‘internal’ VLAN and the virtual servers live in the external VLAN. The gateway for the F5 is a Cisco firewall DMZ interface (same VLAN as external). The firewall will allow this hair pin connection but the traffic is not even reaching the firewall, I suspect because the forwarding virtual server is not forwarding traffic that is destined to itself. I researched DevCentral and found an iRule to use SNAT/Automap when the client and server are on the same VLAN but in this case the client and server are not on the same VLAN so I’m not convinced this will work. Also, I’ve never successfully created an iRule so I’m reaching out for any guidance. Is there a checkbox I can check or a simple iRule I can create to allow just these nodes in routed mode to hit the virtual server they load balance for? All other traffic sourcing from outside the F5 works fine.
Thanks,
4 Replies
- ssievers_87378
Nimbostratus
Do you use dns doctoring on your firewall ? - dbowles65_19789
Altostratus
Hi. No I do not. - dbowles65_19789
Altostratus
So, the traffic sourced by the nodes never reaches the firewall as shown by packet captures. The destination IP is in the external vlan on the F5. The firewall does not play a role in this specific traffic flow. - dbowles65_19789
Altostratus
fixed.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com