Forum Discussion
Send Client-IP to LDAP Server, not same subnet.
Hi Julio Medina,
you would need to implement Policy-Based-Routings (PBRs) to overwrite your routing infrastructure on the path between your LDAP servers and your F5. The mission of the PBR setup would be to forward every response from SRC_IP=YOUR_LDAP_SERVERS:389/636 to DST_IP=ANY:ANY always to your F5. After PBR is implemented you could remove SNAT on your Virtual Servers so that the LDAP Servers will see the original client IP again.
Note: PBRs are Routing-Tables overwrites, which can by used to capture traffic by providing a network based ACL and then forward any matching traffic to a given next-hop interface, MAC or IP. The difference to a regular Routing-Tables is that you can also use SRC_IPs, protocol and/or port information to choose the next-hop / gateway...
Cheers, Kai
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com