Forum Discussion
dleija_23325
Nimbostratus
Aug 24, 2015Private VIP Access Control Options
We have an 'Inline BigIP F5' deployment. Our F5 sits in front of our content servers, sitting between the private and public. We use NATs on the public side to distribute traffic to our internal/priv...
Kevin_Stewart
Employee
Aug 25, 2015You're pretty much stuck with SNAT as long as all of the clients and servers are on the same subnet. So you really have two options:
-
Move your ACLs to the BIG-IP, as arpydays relates.
-
If this is HTTP traffic you can inject an X-Forwarded-For header with the real client address and configure your servers to look for the XFF HTTP header instead of layer 3 IP addresses.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
