Forum Discussion
SNAT pass Destination IP back to Client
I have a web services running on port 443. The incoming traffic from "Client server -> F5 -> Back-end Servers" is working fine, but the outbound response to the Client Server is not working. So we have learned that the Client Server required the same IP address from whichever F5 route to the Back-end server must response back to the Client Server instead of the VIP. We sort of circumvent it by creating a host file on each back-end server that map to the VIP DNS.
Has anybody done an iRule that could solve this problem?
1 Reply
The text format of the comments is just painful to watch, so I'll put this in an answer.
Sorry, but I don't know if I got your scenario. Is it like this?
- Client server contacts the VIP,
- The F5 chooses a pool member (does it have to use any SNAT when connecting to the member?).
- The pool member receives the response and then sends it back to the client server via the F5.
- You now want the F5 to replace the source address of the return packet with that of the selected member?
/Patrik
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com