Forum Discussion
See real ip of the client - TCP VIP
SETUP:
VIP - 1.1.1.1:49
pool - 2.2.2.2:49 and 3.3.3.3:49
snat - automap
so this is a tacacs setup, so the pool members only allow real ip of the devices and not snat ip of the F5. How can we set this up on the VIP? By the way I tried x-forwarded-for but it doesn't work since it is for HTTP. Please help.
- MaryVNimbostratus
Not on the F5 as far as I know, but the clients should be able to to populate the rem_addr field?
- KoalanCirrus
i am sorry but i am not familar with rem_addr
- MaryVNimbostratus
If your F5 has an IP in the same subnet as your TACACS servers you don't need to enable SNAT. You just need autolast hop enabled
- KoalanCirrus
Hi thank you for your response. But what if they dont have an IP under same subnet. They are already in place in different networks. Is there any other way I can do?
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com