Forum Discussion
Warren_A__97345
Nimbostratus
Nov 24, 2009Traffic Routing with out a Snat ?
Greetings everyone.
I am setting up a pair of HA F5s for my datacenter and I have a problem with IP preservation and I was hoping someone could shed some light on this topic for me.
...
hoolio
Cirrostratus
Nov 24, 2009Hi Warren,
Try checking SOL7229 for details on configuring a forwarding virtual server for admin access. You could enable SNAT on that and restrict who can connect to the forwarding VIP by VLAN or by IP/subnet using iRules or packet filters.
SOL7229: Methods of gaining administrative access to nodes through the BIG-IP system
https://support.f5.com/kb/en-us/solutions/public/7000/200/sol7229.html
Also, in terms of support, you might still be able to install 9.3.1 if your service check date is after the 9.3.1 release date even without an active support contract. You could open a case with F5 Support to see if upgrading to 9.3.1 is an option.
As for the self IP question, you should only need one floating self IP per VLAN (unless you have a lot of SNAT traffic and are seeing/concerned about port exhaustion--which shouldn't be a problem in your scenario if you're not using SNAT for most connections).
Aaron
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects