Forum Discussion
Routing Between DMZ & LAN using F5
Hello Everybody,
I'm new on the F5 world, and I have a question about a configuration that I'll want to simulate using F5.
This is related to Vmware View architecture, that's the security server must reside on the DMZ network.
But all the rest of the servers reside on the LAN network.
So for that I want to use F5 with its functions, plus routing the traffic between the two networks.
I hope that I give an approach scenario of my issue.
Thanks in advance
45 Replies
- Jimb2k_159873
Nimbostratus
tcpdump -nni 0.0:nnn -s0 -w /var/tmp/output.pcap host 0.0.0.0 or host 0.0.0.0 -v tcpdump: listening on 0.0:nnn, link-type EN10MB (Ethernet), capture size 65535 b ytes Got 0 Got 0
- nitass
Employee
cpdump -nni 0.0:nnn -s0 -w /var/tmp/output.pcap host 0.0.0.0 or host 0.0.0.0 -v
source ip should be client ip you execute ping.
destination ip should be ip you ping to.if no packet is captured, it means packet does not reach bigip. in that case you may have to check your network.
- Techgeeeg
Nimbostratus
Hi Jim,
Can you just fall to basics and start from checking the interface physical connectivity, check in the GUI if the interfaces are shown as up, just do a shut and no shut on the switch interfaces and then follow the above procedure of creating the IP Forwarding VS with source and destination as any , any . it should work.
Regards,
- Jimb2k_159873
Nimbostratus
Hi Friends,
I'm glad to have this support from you.
Below the result :
[root@F5-BIG-IP01:Active:Standalone] config tcpdump -nni 0.0:nnn -s0 -w /var/tmp/output.pcap host 192.168.2.1 or host 55.10.252.10 -vtcpdump: listening on 0.0:nnn, link-type EN10MB (Ethernet), capture size 65535 bytes ^Ct 12 12 packets captured 12 packets received by filter 0 packets dropped by kernel
[root@F5-BIG-IP01:Active:Standalone] config tcpdump -nni 0.0:nnn -s0 -w /var/tmp/output.pcap host 192.168.2.10 or host 55.10.252.1 -v tcpdump: listening on 0.0:nnn, link-type EN10MB (Ethernet), capture size 65535 bytes ^Ct 12 12 packets captured 12 packets received by filter 0 packets dropped by kernel
But for example, my server 192.168.2.10 can't ping the gateway of the F5 55.10.252.1
And ths opposite is true too.
Thank you again
- nitass
Employee
you have to check the output file (/var/tmp/output.pcap). download it to your laptop and use tool such as wireshark to view it. - Jimb2k_159873
Nimbostratus
How can I do that please.
- nitass
Employee
How can I do that please.
what we expect to see is (1) incoming icmp echo request from source to bigip, then (2) outgoing from bigip to destination, then (3) incoming icmp echo reply from destination back to bigip and then (4) outgoing from bigip to source.
for (1), source ip should be ip you execute ping. destination ip should be ip you ping to.
for (2), source ip should be floating self ip (since you use snat automap). destination ip should still be ip you ping to.
for (3), source ip should be ip you ping to. destination ip should be floating self ip.
for (4), source ip should be ip you ping to. destination ip should be ip you execute ping.you may also use mac address to differentiate between (1) and (2) and between (3) and (4). (1) and (4) are between source and bigip. (2) and (3) are between bigip and destination.
- nitass
Employee
i understand 192.168.2.1 is bigip's self ip, isn't it? why don't you ping server?
sol3475: The BIG-IP system may not respond to ICMP ping requests for a self IP address
http://support.f5.com/kb/en-us/solutions/public/3000/400/sol3475.html - Jimb2k_159873
Nimbostratus
Yes 192.168.2.1 it's a self ip associated to the nic card of the LAN.
My server on LAN which have this IP as gateway,ping on it very well. the same thing on DMZ.
But when I Tried to ping the self IP of the DMZ from the server on the LAN, and also from server on the DMZ to the self IP of LAN, that doesn't work.
And because of that my servers from both networks can't communicate to each other.
Thank you again.
- nitass
Employee
But when I Tried to ping the self IP of the DMZ from the server on the LAN, and also from server on the DMZ to the self IP of LAN, that doesn't work.
it is by design.
sol3475: The BIG-IP system may not respond to ICMP ping requests for a self IP address
http://support.f5.com/kb/en-us/solutions/public/3000/400/sol3475.html - Jimb2k_159873
Nimbostratus
So what will be the solution at your opinion please.
Thank you in advance.
- nitass
Employee
So what will be the solution at your opinion please.
have you tried to ping server ip (not self ip)? pinging server ip should work.
- Jimb2k_159873
Nimbostratus
No, It's not working too - nitass
Employee
have you checked tcpdump? - Jimb2k_159873
Nimbostratus
I Have already paste the result of the tcpdump
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com