Forum Discussion
Piotr_Lewandows
Altostratus
8 years agoStrange issue with SNAT stats, pinging self IP and Allow None
Hi,
I am running out of ideas why BIG-IP behaves as in cases described below, either it's my lack of knowledge, expected behavior or bug.
Tested on v11.2.0HF7 Active-Passive cluster.
Ca...
Pedro_Haoa
8 years agoRet. Employee
Hi,
Remember that there are multiple types of listeners, so the order of precedence is as follow:
- Connection table
- Packet filters
- Destination “listener” (i.e. Virtual Server)
- IP : port
- IP : * (all ports)
- NW : port
- NW : *
- * : port
- * : * (wildcard virtual server)
- Source “listener” (SNATs not in VS)
- Single IP
- Network
- All Addresses
- NATs
So first BIG-IP system check if there's an entry in the connection table. By default PF don't affect existing connections, but they can be changed to filter existing connections. Next we have the destination listeners or VSs, and then our source listeners (SNATs). Within both destination and source listeners, they can be configured more or less specific. Finally we process NATs.
I hope this helps.
Pedro
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects