Forum Discussion
SNAT for outbound, problem with firewall
Hello,
I have requirement for outbound internet access from my servers, I have different vlans X, Y, Z, When I set the SNAT is not working until I set a firewall rule to send traffic from the vlan X to ANY ANY, then the server in vlan X can access the internet, the problem with that is that server in VLAN X can access also Server in VLAN Y. How I can set rules to servers in vlans can access the internet without compromising my security.
Thank RR
P.d Excuse my english
2 Replies
- HHeredia_36237
Nimbostratus
would be useful to have a diagram. However, if you're setting the SNAT you can select which vlan you want to apply it.
Normally you enable SNAT on the vlan which it receives traffic and then it takes the IP of the outgoing vlan. You may have this configuration to ALL VLANs.
cheers, hheredia
- rrey_156291
Nimbostratus
Hello HHeredia,
I configure right SNAT or I guess, the problem is for a computer in vlan 10 to access internet I need to create a rule in the F5 firewall to access the intenet example:
source vlan 10, destination: ip: any port: any..
the problem with this rule is that after I applied the rule the server in vlan 10 effectively can access the internet but also every vlan that I have creating a security hole for me.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com