Forum Discussion
crate_17871
Nimbostratus
Sep 07, 2010same subnet lb + SSL
Guys,
Having an issue with full communication with some remote devices.
The network set as follows:
Handheld devices communicate via GPRS to a router through a firewall t...
Hamish
Cirrocumulus
Sep 07, 2010That's not fatal. The only requirement is that the F5 see both flows of the TCP connection. So you then have 2 choices.
1. Implement policy based routing such that all traffic FROM the poolmember port on the server is routed via the F5 (Floating IP)
2. Or simply put the F5's floating selfip as the default router.
3. Move the servers off to a dedicated subnet BEHIND the F5...
Option 1 is cleaner... At the expense of some systems won't let you do this... Linux and iptables are pretty simple (I've done it myself, takes a couple of iptables lines to tag the packets and a tagged packet routing table entry). Option 2 is not as clean and has the disadvantage that hosts on the same subnet (Besides the F5 of course) will be unable to access the load balanced service (That may or may not be a problem for you). Option 2 & 3 also require a wildcard network VS to be created on the F5 and also a route TO the servers via the F5 from the actual router (It starts to get messy on option 2 pretty rapidly).
H
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects