Forum Discussion

golfislife13_33's avatar
golfislife13_33
Icon for Nimbostratus rankNimbostratus
Dec 15, 2009

SNAT/Floating IPs/Masquerade MACs

I am in the middle of replacing a single F5 LTM installation with a dual LTM1600 set up in HA mode.

 

 

I would like my servers to use the router as a default gateway but respond directly back to the F5 units for all incoming requests that come thru the F5's. I've done this before but dont''t remember the exact set up. I think I need floating IP's on both the External and Internal interfaces which I have. I also assume I need to use masquerade MACs since this is an Active/Passive configuration. Do I need a SNAT pool? If so, on which interface? I don't remember having one in a previous installation.

 

 

Thank you!!

 

 

  • You've got it pretty much right: a self and floating IP for each vlan the BigIP pair is connected to. For your virtual servers, use SNAT (you'll have to here or your flows will break unless you do npath - and don't do npath). You can use a snat pool or automap if port exhaustion isn't an issue.

     

     

    Regarding MAC masq, it's a best practice, so definitely do that if you can.

     

     

    -Matt
  • Thanks for the verification. The one thing I was forgetting was setting the SNAP Pool to Auto Map.

     

     

    All seems to be working!! Now for some failover testing.....

     

     

    Thanks!!