Forum Discussion
cxcal_18687
Nimbostratus
Dec 05, 2007SNAT conflict with MoveIT software
We are using Big-IP v4.5 and we failed our MoveIT migration this pass weekend because when we have SNAT enabled and 2 nodes behind the VIP the MoveIT software will lock out all of the users when I one fails to login correctly after 5 attempts. We found that this is due to the SNAT address that is being used. Auditing the client source IP address is needed for troubleshooting.
Bottom line, traffic comes in but does not make it back out to the clients.
Any way around this issue?
1 Reply
- hoolio
Cirrostratus
I would assume the app is blocking by source IP when a client fails five attempts. IP-based logic doesn't work so well when some/all of your clients are connecting from behind a proxy. You could configure the BIG-IP to insert the original client IP address in a custom header. But you would need to instruct the app to parse that header instead of the source IP on the TCP packets. I'm guessing you don't have that ability.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects