Forum Discussion
member123_60341
Nimbostratus
Jul 06, 2009SNAT & Automap query
Hi,
We are having the network setup as attached.Web servers & App servers are getting load balanced.We are setting up Active/Active HA.Clients will access web servers using translated ip of Web virtual server ip 1.1.1.10.Web servers will access app servers using port 80.
1.When the web servers access application servers using VS IP 2.2.2.10 do you see any need for configuring SNAT?
2.If SNAT is required where do we need to configure(whether LTM 1 OR LTM2) ?
3.Do we need to configure SNAT pool - Auto map in Virtual server ?
Any help appreciated.
Rgds./Joe
3 Replies
- The_Bhattman
Nimbostratus
1. If the client and servers are on the same VLAN using the VS on the F5, then yes you will need to use SNAT so that the traffic synchronous.
2. You would have to configure it on both in case one has to take it over during failure.
3. If you use SNAT Automap on the VS then all your traffic will be SNAT, therefore the web server will lose the ability to log unique address for all. The best way, in my mind is to use an IRULE on the VS. Such that it it ONLY stats based on the client's IP address. This way you can limit the amount of snat you need.
I hope this helps,
CB - member123_60341
Nimbostratus
Thanks for your prompt reply.I am just a newbie to LTM.
I had a small clarification on point 3rd you suggested.
1.Can you elaborate on point 3rd regarding iRule.The traffic flow will be from Internet to Web server VIP, one of the real web server IP to App server VIP. Also, there will be communication from Web servers to the core network which is on a different subnet ( not shown in the diagram) In this case,
a.What is the iRule that we need to create based on the Network diagram
b.On which virtual server (WEB or APP) do we need to bind the iRule
c.In case if we need to use SNAT, do we need it for Web servers or for App servers or do we need it both web & App considering the the traffic flow explained above.
Rgds./Joe - JRahm
Admin
You shouldn't need snat for web -> app server traffic. You just need to make sure that the app servers and the firewalls have an appropriate route to return the traffic and that the web servers have an appropriate route to the app servers (default or otherwise).
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects