Forum Discussion
Kirk_Bauer_1018
Altostratus
Sep 07, 2007Selective SNAT rule, looking for suggestions
I wrote this rule for a customer who has 8 VLANs with real servers, and each pool may have servers from multiple VLANs. In addition sometimes the "client" comes from one of the VLANs as well, so I ne...
Deb_Allen_18
Jan 08, 2008Historic F5 Account
Also, I've elected to SNAT using the VIP address itself rather than use automap as that will give a better indication in the webserver logs whether the connection was related to an LTM monitor or whether the client was actually SNAT'ed.
Hi Nathan -
I like your "SNAT to local VS address" approach, will probably use that in future, but just thought I'd clarify one minor thing: If you are running a redundant pair, all monitors will be sourced from the non-floating selfIPs, while SNAT automap will only use the floating ones, so you already have some natural separation there...
Thanks for the contrib!
/deb
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
