Forum Discussion
SSL VPN - Access to internal resources without SNAT
I have a single-arm F5 (one VLAN for both external and internal IP address ranges). The internal, private IP addresses are assigned to VPN clients. The security team needs to build firewall rules around those private DHCP addresses, so SNAT isn't an option.
The default route on the F5 points to the public IP address of the shared VLAN.
When I configure the Network Access with Proxy ARP, internal resources see the client IP as showing up as the public local (non-float) self-IP address.
When I disable Proxy ARP, the internal resources see the DHCP address, but I'm unable to connect to them; no ARP entries on the router with client MAC/IP addresses. External resources are reachable (Split tunnel).
Anybody have suggestions on what to try next?
- BigD_300005Cirrostratus
Have you looked into using F5's ACLs into doing what the security team is trying to do with a firewall? Then do your policy based off user name instead of IP addresses.
Otherwise this might work: https://support.f5.com/csp/article/K4816
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com