Forum Discussion
Jeepha_42175
Nimbostratus
Dec 14, 2008Newbie Question. Big IP as Gateway v4.5
Hello,
I have recently taken over for another technician that was 'excused' due not getting projects completed. One of my tasks is implementing this F5 to load balance two https servers.
This is a LTM 2400 series running 4.5. It has been sitting in the rack since it was purchased new without being configured. (One of his unfinished projects). So it is currently out of support, and updating the kernel is probably not going to happen. It is pretty simple what I need to do, and so far all is going well except I cannot get my nodes to browse the internet. Here is what I have done so far:
Big ip has two enabled interfaces, one on the outside world with a public IP, and the other with a local ip. I have two web servers on the internal IP network that need to be accessed by the world. They both are using the internal interface of the BIG IP as their gateways. they are able to resolve DNS, however they cannot browse accross the BigIP. I have created a virtual server and can effectivly browse the sites on the Nodes from the Internet via the virtual server.
The problem I am having is accessing the Internet from the web servers. I have tried creating a wildcard forwarding server with ip 0.0.0.0/0.0.0.0, but still no dice. Here are the settings:
Virtual Server 0.0.0.0:0
Status ENABLED
Virtual Server Address Status: Enabled
Enable translation: NO
Enable Reset on Service Down: No
Enable Connection Rebind: NO
Enable ARP: YES
Enable Reset on Timeout:YES
Disable FasFlow Acceleration: NO
Connection Limit: 0
Last hop pool: choose
No disabled LAnS
Resources Forwarding
I have been reading posts all day that refer to Creating a FastL4 Profile...but I dont believe that option is available to me on this version. I am sure I am missing something very basic, but the solution eludes me. Please give me a hand if you can.
Thank you Very much
Curtis
- strongarm_46960
Nimbostratus
Curtis, There far too many variables at play here, its hard to point at one particular entity. - hoolio
Cirrostratus
Without addressing potential security issues, from a technical perspective you should be able to pass this traffic if you configure SNAT on the wildcard VIP. This ensures BIG-IP performs source address translation on outbound requests. - Jeepha_42175
Nimbostratus
- Jeepha_42175
Nimbostratus
Thank you very much for your help.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects