For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

newf5learner's avatar
newf5learner
Icon for Nimbostratus rankNimbostratus
Aug 16, 2016

SNAT list - how to use it

Hi.. I have a standard VIP https://10.20.20.220 with ssl bridging and the server is listening on port 443.

 

I don't want to use SNAT Automap, but I want to use the just the plain SNAT feature where the client IP address is mapped to a IP address I define. FYI.. Self-IP on the F5s are 10.20.20.5, 10.20.20.6 (both are non-floating )

 

SNAT: Client IP : 10.30.30.1 SNAT IP : 10.20.20.221

 

I have set the SNAT option on the VIP as None, assuming that the one-to-one SNAT I have configured will kick in. But for some reason its failing. I'm not able to get the IIS page when I access the VIP.

 

Note: This is a F5 LTM virtual instance and I'm using a one ARMed mode of deployment.

 

Can someone suggest me if I'm missing something or is that SNAT doesn't work this way?

 

1 Reply

  • nathe's avatar
    nathe
    Icon for Cirrocumulus rankCirrocumulus

    SNAT should work like that. Can you confirm you have configured the SNAT list correctly? Translation should be the hide address and Origin/Address List should be the client IP address.

     

    assuming this is all correct, what happens if you run tcpdump on the bigip? Do you see connections going to the backend pool member using the snat address?

     

    Hope this helps,

     

    N