Forum Discussion
Daniel_55334
Altostratus
Apr 15, 2015NAT on LTM or firewall?
We are going to add LTM to a customer network to do outgoing ISP load balance.
Internet router --- LTM --- firewall --- core switch
Firewall currently performs NAT for outgoing Internet tra...
BinaryCanary_19
Apr 15, 2015Historic F5 Account
It's all up to you. If you are not making any decisions based on Source IP, then it doesn't really matter where you NAT.
If you are using for example, Source Address Affinity persistence, then you may want to do the NAT on the LTM.
dragonflymr
Cirrostratus
Apr 16, 2015Hi,
Maybe I am wrong but if NAT (using F5 definition of NAT) is used to access internal servers then source IP is preserved, only destination IP is changed - Am I wrong? Source IP is changed only if SNAT is used for accessing servers (strange config I guess but possible).
I would say that using BIG-IP device to perform just NAT seems to be like not utilizing 99% of features of the device.
Not an expert here but I would change this setup so:
Internet router --- firewall --- LTM --- core switch
Then for outgoing traffic (initiated from LAN to Internet) SNAT can be configured on LTM (probably best practice is rather to set wildcard virtual server (VS)?)
For traffic coming from Internet to servers in LAN appropriate VSs should be created.
Piotr
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
