Forum Discussion
Question on Routing when F5 is Default Gateway
I have a setup where the F5 serves as default gateway for 25 VLANs on the DMZ. The F5s default gateway is a Palo Alto 5000. The Palo has a route to 10.10.0.0/24 via 10.1.0.2 and is redistributing that route via OSPF. The F5 has a IP-forwarding virtual server configured.
PA (10.1.0.1/28) <--VLAN 1--> (10.1.0.2/28) F5 (10.10.0.1/24) <--VLAN 10--> Server (10.10.0.100/24)
Here's my conundrum:
- Pings from the PA to 10.1.0.2: successful
- Pings from the PA to 10.10.0.1: unsuccessful
- Pings from the PA to 10.10.0.100: successful
- Pings from the F5 (VLAN 10) to 10.1.0.1: unsuccessful
- Pings from the Server to 10.1.0.1: successful
All in all, the setup works but if I try to ping or traceroute from interface VLAN 10 on the F5 to anything left of the F5, I receive "Destination Host Unreachable".
Any ideas?
1 Reply
- Stanislas_Piro2
Cumulonimbus
Hi,
For security reasons, F5 does not allow packet to self IP from another VLAN than defined in Self.
As F5 does not filter self IP sources in port lockdown, filter is only done on VLAN.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com