Forum Discussion
nathe
Cirrocumulus
Jan 06, 2010Source Address Translation irule
Afternoon,
Our Load Balancer appliances are on a DMZ off our Firewall and we are load balancing http traffic to an internal server on a different LAN to the F5s. Traffic comes into the F5s and is then re-directed to a pool member back through the firewall. The problem we are having is all to do with Source addresses. The original Source address is a public one and this is maintained on re-route, so when it then gets re-routed via the firewall to the LAN where the pool member resides the firewall blocks this for two reasons, no rule to allow the internet client to an internal IP address and IP spoofing.
Can I configure the F5 Virtual Server to translate the Source when re-routing to the actual node? Perhaps even translate it to the VS IP address itself. Perhaps using an iRule?
Thanks in advance
- The_Bhattman
Nimbostratus
Hi Nathan, - naladar_65658
Altostratus
I agree with Bhattman, a diagram would be nice. Have you tried turning on SNAT Automap on the VIP? - nathe
Cirrocumulus
Thanks both for getting back to me so promptly. I tried the SNAT option and this has worked. Source address is now translated to Virtual Server IP address and everything is happy.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects