Carlos_123412
Oct 23, 2015Nimbostratus
Strange SNAT IP address behaviour
Hello everyone,
Recently we've discovered a weird behaviour on our BIG-IP system. We are currently running version 11.5.1 on an 8950 Active/Passive HA pair.
We have detected that a couple of servers, due to misconfiguration, are generating UDP traffic to port 1002 of an SNAT IP address which belongs to a SNAT Pool. Our BIG-IP is bouncing that traffic back to the network simply changing source an destination MAC address on the ethernet header.
You can see it on the following screenshots:
Is this an expected behaviour? Shouldn't F5 just drop this traffic?
As additional info: the VS to which this SNAT Pool belongs is configured for port 80 HTTP.
Thank you very much in advance for your answers.
Best regards, Carlos