Forum Discussion
Symantec Email Gateway behind F5
I would like to use F5 in order to provide high availability across two Symantec Email Gateways. Symantec Email Gateways have to see the real Source IP in order to filter out emails based on IP reputation, that means i can't do a SNAT on F5 and hence gateway on Symantec should be F5. But i don't want Symantec's gateway to be F5. Is there any other way i could pass the real source IPs from F5 to Symantec Email Gateway? As far as i know Xforwarding will not work as Symantec does't support it.
- Snl
Cirrostratus
use dual arm or inline
- Stanislas_Piro2
Cumulonimbus
Hi,
Since F5 load balance SMTP, the answer is still the same...
X-Forwarded-For header is only compatible with HTTP(S) protocol.
In SMTP, Received header (inserted by each SMTP relay) is in the header of Data and not in SMTP conversation. so you have to listen all SMTP conversation to catch start of DATA, then insert Received Header.
Until F5 doesn't create SMTP irule events, it will be difficult to do this... maybe you can be the one who will success :-)
The other solution is to define the BIGIP as default gateway.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com