Forum Discussion
Strange issue with SNAT stats, pinging self IP and Allow None
Hi,
Remember that there are multiple types of listeners, so the order of precedence is as follow:
- Connection table
- Packet filters
- Destination “listener” (i.e. Virtual Server)
- IP : port
- IP : * (all ports)
- NW : port
- NW : *
- * : port
- * : * (wildcard virtual server)
- Source “listener” (SNATs not in VS)
- Single IP
- Network
- All Addresses
- NATs
So first BIG-IP system check if there's an entry in the connection table. By default PF don't affect existing connections, but they can be changed to filter existing connections. Next we have the destination listeners or VSs, and then our source listeners (SNATs). Within both destination and source listeners, they can be configured more or less specific. Finally we process NATs.
I hope this helps.
Pedro
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com