Forum Discussion
HarrisHome_3538
Nimbostratus
Oct 22, 2008TMM routes and Management Routes Question
Hi,
I am newbie to F5 Big-IP. I have some questions on TMM routes, mgmt routes & kernel routes. I had configured a management IP address (10.10.1.173/24) on eth0 and configured a management default route to the gateway (10.10.1.1). I had configured a NAT mapping for a nodes behind F5 to access the outside and created a TMM default route to route all traffics from the node to outside. Here is my configuration, the IP is not real.
mgmt 10.10.1.173 {
netmask 255.255.255.0
}
mgmt route default inet {
gateway
gateway 10.10.1.1
mtu 0
}
nat 192.168.9.42 to 10.10.2.42 {
enable
arp enable
unit 1
vlans none disable
}
route default inet {
gateway
vlan none
gateway 10.10.2.1
pool none
mtu 0
static
}
self 10.10.2.172 {
netmask 255.255.255.0
vlan WAN_VLAN
allow default
}
self 192.168.9.172 {
netmask 255.255.255.0
vlan LAN_VLAN
allow default
}
Kernel IP routing table
Destination Gateway Genmask Flags MSS Window irtt Iface
127.1.1.0 0.0.0.0 255.255.255.0 U 0 0 0 tmm0
127.2.0.0 0.0.0.0 255.255.255.0 U 0 0 0 eth0.1
10.10.2.0 0.0.0.0 255.255.255.0 U 0 0 0 WAN_VLAN
192.168.9.0 0.0.0.0 255.255.255.0 U 0 0 0 LAN_VLAN
127.0.0.0 - 255.0.0.0 ! - - - -
0.0.0.0 10.10.2.1 0.0.0.0 UG 0 0 0 WAN_VLAN
0.0.0.0 10.10.1.1 0.0.0.0 UG 0 0 0 eth0
After I added the TMM default route, I am unable to access the F5 by using the Management IP from outside network. It seems that the default route in Kernel IP routing table had been overwrite by the TMM routes. My question is can I access the F5 by using Management IP if the TMM default is exist?
Thanks a lot!
- dennypayne
Employee
Yes, you should still be able to access the management IP as long as that outside network is not routing you to a TMM address first. TMM won't forward management traffic. - HarrisHome_3538
Nimbostratus
Hi Denny, - Ian_Johnson_382
Nimbostratus
If you want the nodes behind the LTM to access the outside world you will need either create forwarding virtual server, or the better option would to create a SNAT to allow any internal host access the outside world.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects