Forum Discussion
kev_245_28249
Nimbostratus
Apr 21, 2011Nexthop
Hi,
I am trying to configure the nexthop global cmd via an iRule inorder to send traffic to a particular gateway depending upon which vlan it hits.
In a simple vm lab I have one vlan 'Prod' with a server node of 10.20.0.111. The virtual server is addressed as 10.20.0.250. I have removed the default route on the Ltm and configured the global nexthop irule and applied it to the VIP. What seems to happen when i attempt to pass traffic is that the VIP holds on to the traffic. For eg, for an FTP I get a connected to 'vip ip'
(I have tried using the mac address and ip address of the destination server with the same results.
irule
when CLIENT_ACCEPTED {
nexthop Prod 00:0C:29:16:04:7B
}
or
when CLIENT_ACCEPTED {
nexthop Prod 10.20.0.111
}
22 Replies
- nitass
Employee
may we see the virtual server config? - kev_245_28249
Nimbostratus
I am just trying SSH now,
Virtual Public_SSH {
snat automap
pool Public_SSH
destination 10.20.0.250:ssh
ip protocol tcp
rules Next_hop
}
i have tried this with the default route on the box as well as with it removed..
my tcpdumps on the ltm for say port 22 (for the above config) show me the ip address of the destination server (when I don't have the irule applied). The tcpdumps only show me the VIP address being involved when the irule is applied. - kev_245_28249
Nimbostratus
Got it sorted, reset my lab ltm's back to last known good build and also turned logging on for my iRule.
Closed - nitass
Employee
does it work? really? i got the same problem in my test unit.
i'm upgrading to 9.4.8. - nitass
Employee
it doesn't work even upgrading to 9.4.8. i'm going to escalate and will also update here.
any suggestions are welcome. thanks! - nitass
Employee
this is feedback from escalation engineer.
------------------------------
the virtual should be transparent.
translate address disable
translate service disable
------------------------------ - kev_245_28249
Nimbostratus
i'm using 10.1 virtual edition (if that helps) - nitass
Employee
PD is checking on this. The case is C870230. Will let you know when getting any feedback from them. - kev_245_28249
Nimbostratus
Just to confirm, I was testing over the weekend and just relying on the var/log/ltm file for proof.
Now in my work lab I confirm I don't see this working. - kev_245_28249
Nimbostratus
Just to confirm, I was testing from home over the easter weekend and just relying on the var/log/ltm file for proof.
Now in my work lab I confirm I don't see this working, despite seeing the iRule being correctly hit in the log file.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects