Forum Discussion
Preserving source IP in L4 VIP
So I created a VIP for sending log data to a couple of syslog servers. I created a L4 vip and it works fine, except the data shows up with the interface IP of the F5 which is to be expected (automap.) Since it is L4 I can't use X-forwarded for, I am wondering if I can use an Irule to preserve the source address of the traffic so it makes a little more sense when it gets in the syslog server. I am running a basic Irule to restrict traffic, would that conflict? Or since the traffic only gets pushed to the syslog servers can I do none for SNAT to preserve the original IP address? Would this have any affect on my other VIPS? Being UDP traffic I don't need to worry about asymmetric traffic do I? I am running 11.5.1, I read you can use HTTP profiles in 12 for L4 VIPs but there were a lot of restrictions, is X-forwarded for not allowed? Any guidance on this would be super helpful! Thank you as always! Joe
2 Replies
- Kevin_Stewart
Employee
Syslog traffic is generally one-way, so you shouldn't need SNAT.
- Jinshu
Cirrus
You got the answer in question itself mate..!!
since the traffic only gets pushed to the syslog servers you can do none for SNAT to preserve the original IP address.
Cheers
-Jinshu
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com