Forum Discussion
jyulkbox_48590
Nimbostratus
Jun 15, 2010Publicly accessible internal VLAN
Hello,
I'm trying to use Big IP for load balancing SIP servers. Unlike many of the discussions I read here my setup is such that each server needs to be accessible individually as well as load balanced by Big IP.
All servers are pointing to Big IP as their default gateway (for the load balancing part). With a wildcard virtual server (0.0.0.0:0) configured on all VLAN, Big IP is able to forward any request from server to the outside.
The problem arises when an external client tries to access the server directly. For example, when I try to ssh into the server using its IP address (bypassing Big IP), the SYN packet reaches the server, the server sends a SYNACK to Big IP, and the Big IP sends a TCP RST back to the server. I attached a drawing of this behavior.
Is there a way to make Big IP forward packets even if it's not aware of the "connection"
? I thought that's what the wildcard virtual server was supposed to do...
Do you know a way that works?
- Chris_Miller
Altostratus
You want to look at "Loose Intiate" - hoolio
Cirrostratus
You could allow this to work using the loose initiate and possibly loose close options on a custom FastL4 profile, but it would be more efficient to configure LTM and the related network devices to route these connections symmetrically. See SOL7229 for details on allowing admin access to hosts behind LTM: - jyulkbox_48590
Nimbostratus
Thank you very much to both of you!
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects