Forum Discussion
Server port not accessible from F5
- Apr 27, 2017
Thanks all for your help, actually issue was on Firewall there was policy which allows only ping, http & ssh traffic.
My F5 management IP was 10.11.5.x/24 network, server was in 10.11.1.x/24 network so I was tracing on firewall using source IP F5 (10.11.5.x) destination server IP (10.11.1.x) I was getting no trace logs so I thought traffic was not blocked by firewall.
After more troubleshooting, I enabled tcpdump on server in (10.11.1.x) network, so I came to know F5 was doing NAT when forwarding its traffic. Like 10.11.5.x network was NATTed to 10.11.3.x network, this was not allowed on firewall. After enabling this network for 3010 port on firewall it worked.
Thanks all my concept was source and destination IP's never change util unless it is NATTED, still looking how F5 is NATTING its management IP from 10.11.5 to 10.11.3.
Thanks.
Ensure the server is listening on port 3010. Also ensure automap is set or correct SNAT pool if you are going from the BIGIP F5, to the front-end of the F5, and back through. This would be the case if you are trying to telnet to the VIP. Automap and firewall verification shouldn't take long. If that does not resolve the issues, a tcpdump should fix it right up.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com