Forum Discussion
crate_17871
Nimbostratus
Sep 07, 2010same subnet lb + SSL
Guys,
Having an issue with full communication with some remote devices.
The network set as follows:
Handheld devices communicate via GPRS to a router through a firewall to a pair LTM 1600 terminating an SSL connection which then connects to a server for service offered.
The handheld devices as 1.1.1.0/24 goes to a NAT in front of the firewall for the LTM 2.2.2.2:30000 (TCP)
The LTMs configured with IP 3.3.3.3/24 and ClientSSL takes this traffic and gives this to a server 3.3.3.4:20000.
The gateway for the LTMs are 3.3.3.1 (firewall interface) and the server is 3.3.3.20 (router interface).
The initial connection setup is done however the devices are not completing the connection to retrieve the data.
Can anyone start with a nudge or a point in the right direction?
Almost forgot when doing some dumps, saw some TCP Zero Window Segments
- Jason_Keating
Altostratus
Not 100% sure I have understood your network config - sounds like a one-arm config, if your server 3.3.3.4 has a default gateway other than the ltm you likely need to set up a SNAT on the ltm. I'd recommend a configuring a SNAT Pool with at least one self IP from the VLAN of egress. - Cspillane_18296
Nimbostratus
I'd agree with jmkakabarb, try SNAT on the Virtual Server (either use AutoMap or create your own pool of addresses which should all be on the egress VLAN i.e. the VLAN where traffic leaves the BigIP to go to the server). - crate_17871
Nimbostratus
I wanted to do this however I will have to show all ips to the server - Chris_Miller
Altostratus
Posted By crate on 09/07/2010 07:29 AM - crate_17871
Nimbostratus
The Server providing the service must see all devices IP in order to communicate efficiently. If any duplicates are seen the Server will drop the connection - Hamish
Cirrocumulus
That's not fatal. The only requirement is that the F5 see both flows of the TCP connection. So you then have 2 choices. - crate_17871
Nimbostratus
Posted By Hamish on 09/07/2010 08:33 AM - Hamish
Cirrocumulus
Mm.... No... I wasn't suggesting extra hardware... - Jason_Keating
Altostratus
Re Hamish's suggestion: - crate_17871
Nimbostratus
Guys,
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects