Forum Discussion
Need to bypass SNAT for internal IPs
I have configured SNAT towards the Public Network for 2 local servers whose GW is the F5 BIG-IP itself.
IPs of servers : 192.168.10.1 & 192.168.10.2 GW : 192.168.10.254/24 (configured on BIG-IP) SNAT IP : 77.240.x.x
Now when the servers 192.168.10.1 & 192.168.10.2 need to communicate to 192.168.20.1 in the local network, it’s taking the NATed IP 77.240.x.x which is blocked through FWs in the network due to restrictions and will cause asymmetrical routing. I need to bypass the SNAT if matched with certain IP networks with an iRULE. Please suggest how and what needs to be done. If anyone have any sample iRULE or document that can help, it will be really helpful.
7 Replies
- nitass
Employee
IPs of servers : 192.168.10.1 & 192.168.10.2
GW : 192.168.10.254/24 (configured on BIG-IP)
SNAT IP : 77.240.x.xhow is snat configured on bigip? are you using snat list?
Now when the servers 192.168.10.1 & 192.168.10.2 need to communicate to 192.168.20.1 in the local network
what object listener are you using? is it virtual server or snat list?
- Tabish_Patel_20
Nimbostratus
I configured using the SNAT List - Tabish_Patel_20
Nimbostratus
Yes VS is also configured for inbound connections and its working with no problem.
- nitass_89166
Noctilucent
IPs of servers : 192.168.10.1 & 192.168.10.2
GW : 192.168.10.254/24 (configured on BIG-IP)
SNAT IP : 77.240.x.xhow is snat configured on bigip? are you using snat list?
Now when the servers 192.168.10.1 & 192.168.10.2 need to communicate to 192.168.20.1 in the local network
what object listener are you using? is it virtual server or snat list?
- Tabish_Patel_20
Nimbostratus
I configured using the SNAT List - Tabish_Patel_20
Nimbostratus
Yes VS is also configured for inbound connections and its working with no problem.
- Pawan_Goswami
Nimbostratus
Please use SNAT list for inbound to outbound traffic.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com