Forum Discussion
New bigip on network breaks old bigip snat
We have an old pair of bigips in production that we have used for years (version 9). We are replacing them with a new pair(version 11). We used different ip addresses for the self ips on the new pair so we could run them side by side for testing. When we plug in the external interfaces (behind firewall) of the new pair, after a time (few minutes to a few hours) the current bigips SNATs stop working until we fail over to the other bigip in the cluster. While in this state the bigip can get to the internet or the internal network fine, but it is not forwarding traffice from servers that use the bigip as it gateway.
-It is not an ip conflict
Do the bigips broadcast something out that make them not want to be on the same network as other bigips?
4 Replies
- DevBabu
Cirrus
Although you have said not an ip conflict. I would still think there is a device in network with similar IP that is claiming it has that IP address and sending it's MAC address at some intervals. Upon failover BIG-IP GARPS out and traffic is forwarded to it. But after certain interval again that device comes into play.
-
Take captures on the servers to see what mac address they are forwarding traffic to at the time of issue.
-
Take capture on F5 to see if it has received the traffic sent by the server.
-
- johnp-scout_211
Nimbostratus
When it sends out the GARP would all the servers on the network try to use that new bigip as its gateway?
- johnp-scout_211
Nimbostratus
Turns out part of the config was copied to this new bigip and the snat WAS conflicting.
- Stanislas_Piro2
Cumulonimbus
When you import configuration and you change IPs of virtual server ans SNAT, old IP addresses are still in the configuration as "Virtual address" and "SNAT translation list".
- When creating a VS, the virtual address is created with ARP Checked to enable proxy ARP
- When deleting a VS, the virtual address is delete
- When modify a VS address, the new address is created but the old one remains.
this is the same with SNAT pool and SNAT translation list...
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com