Forum Discussion
jeffo_42365
Mar 15, 2011Nimbostratus
Reverse NAT on a 3900
I'd like to know if it is possible to put 1000+ clients behind a 3900 on private addresses and allow them to make outbound connections using a public IP on the 3900 (reverse NAT/outbound NAT).
...
hooleylist
Mar 15, 2011Cirrostratus
Hi Jeff,
Welcome to the F5 world :)
You can use a 0.0.0.0:0 all protocol virtual server (forwarding if you want to use the routing table or performance layer 4 with a fastL4 profile if you have multiple gateways you want to load balance between) enabled just on the VLAN the clients are on with SNAT enabled. LTM will then accept any connection in on that ingress VLAN and route the traffic out with source address translation. You might want to use a SNAT pool if you have a lot of active connections. This will help avoid port exhaustion.
If this sounds right and you want details on how to configure this let us know.
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects