Forum Discussion
Server port not accessible from F5
- Apr 27, 2017
Thanks all for your help, actually issue was on Firewall there was policy which allows only ping, http & ssh traffic.
My F5 management IP was 10.11.5.x/24 network, server was in 10.11.1.x/24 network so I was tracing on firewall using source IP F5 (10.11.5.x) destination server IP (10.11.1.x) I was getting no trace logs so I thought traffic was not blocked by firewall.
After more troubleshooting, I enabled tcpdump on server in (10.11.1.x) network, so I came to know F5 was doing NAT when forwarding its traffic. Like 10.11.5.x network was NATTed to 10.11.3.x network, this was not allowed on firewall. After enabling this network for 3010 port on firewall it worked.
Thanks all my concept was source and destination IP's never change util unless it is NATTED, still looking how F5 is NATTING its management IP from 10.11.5 to 10.11.3.
Thanks.
do u have routedomain configured or try telnet to the vip and ensure under same vip pool u allow the node with correct port also you can do tcpdump and see whether you are getting the response from server or not , there are few scenario were you might have firewall in between F5 and server then you need to ensure you have allowed the self ip's over firewall for communication towards server.
use below tcp dump - x.x.x.x is server ip
tcpdump -ni 0.0:nnnp host x.x.x.x -s0 -w /var/tmp/traffic.pcap -vvv
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com