Forum Discussion
JCMATTOS_41723
Nimbostratus
Aug 25, 2009NAT the clientside?
We have an LTM 9.4.7 and we wanted to replace our reverse proxy layer with the F5. We are trying to configure NAT for the clientside. Essentially we would like all connections from the client get NAT'd to a routable address on the inside of our DMZ. I see lot of options not sure where to begin. Thx!
NEW
CLIENT 1.1.1.1
|
Firewall
|
F5 EXT VIP 10.0.0.100 (All clients should get nat'd the same way to RP 10.0.1.100)
|
Firewall
|
F5 INT VIP 172.16.x.x
/\
APP1 APP2 (application)
CURRENT
CLIENT 1.1.1.1
|
Firewall
|
F5 EXT VIP 10.0.0.100
/\
PXY1 PXY2 10.0.1.100 and .101 (Clients get nat'd to one of these IP's)
\/
Firewall
|
F5 INT VIP 172.16.x.x
/\
APP1 APP2 (application)
1 Reply
Sort By
- JRahm
Admin
You could create a snatpool with the 10.0.1.100 (and the 10.0.1.101 if you are concerned about tcp port exhaustion) and apply it to your EXT VIP.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects