Forum Discussion
Selective SNAT in VPN
You could simplify the configuration and not use a lease pool. Have all client connect to one SNAT IP via a SNAT pool, applied to the VIP, instead of "AutoMap". --Local -> Address Translation --> SNAT Pool. That way you take out a layer of "complexity" knowing it is not a DHCP lease issue.
Network Configuration
--If you have a SELF IP for every Subnet needed for all of your applications/VIPs, then the clients will be able to route to where they need, as long as they have an IP that is one of the Self IP subnets you have configured. The F5 is a Layer 2("switch"), if it does not own the .1, where the routing will traverse the respective Self IP, versus the Default Route, if an IP is not matched.
iRule idea --
Try "when HTTP_RESPONSE_RELEASE" versus "when CLIENT_ACCEPTED"
- JurajMar 18, 2020Cirrus
I'm sorry, I'm a bit confused now. I'm configuring Network Access VPN for EDGE client. HTTP_RESPONSE_RELEASE doesn't get triggered either by the VPN client.
To be honest, I do not follow what you're trying to say.
This is my situation:
- I have Network Access VPN for Edge clients
- I do not have problems with DHCP, the clients get their IPs assigned properly once they connect to VPN; the IP is from 10.10.1.1-10.10.1.254, routable in our network, but not routable in the Internet
- everything works without any problems, if I apply AutoMap or SNAT-pool to the Network Resource.
My problem is that I want to SNAT only when they go to the Internet, i.e. their traffic leaves via a specific BIGIP interface
- Shaun_SimmonsMar 19, 2020Employee
I'll have to ask my colleagues for additional thoughts.
-My thoughts are the inbound and outbound is routed specifically to the SNAT. Knowing if traffic is routed to the internet is not in the same "stream", to know where to route. I'd think the user would have to use the BIGIP as a proxy to the Internet, since the gateway to the Internet is based on their local DHCP derived gateway and DNS. The Edge client creates a HTTPS tunnel to specific apps / links configured via APM.
- JurajMar 19, 2020Cirrus
My apologies, I do appreciate you're trying to help me, but with all due respect I have no idea what you're talking about. It doesn't make sense to me.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com