Forum Discussion
Transparent Forward Proxy iApp
Paulius Thank you sir. The original forward proxy iApp did not require SWG. Actually I think it was built before SWG was even a product. We used it from version 11 to version 13. Only version 14+ seems to have broken it, so it was a method at least at one point in time. Oddly I cannot find any references to it DevCentral even though it was written by F5.
I setup the explicit proxy as mentioned in Steve's thread. It does respond but now we're receving a 503 error. I saw a reply to Steve's thread which suggested adding the route domain in the profile if a 503 is received, but that did not fix it.
9 230.341665 X.X.116.153 X.X.115.133 HTTP 357 IN s1/tmm3 : CONNECT externalsystem.com:443 HTTP/1.0
10 230.341744 X.X.115.133 X.X.116.153 TCP 211 OUT s1/tmm3 : 443 → 58998 [ACK] Seq=1 Ack=132 Win=65024 Len=0 TSval=1446237578 TSecr=1680799487
11 241.621895 X.X.115.133 X.X.116.153 TCP 283 OUT s1/tmm3 : 443 → 58998 [PSH, ACK] Seq=1 Ack=132 Win=65024 Len=72 TSval=1446248858 TSecr=1680799487 [TCP segment of a reassembled PDU]
12 241.621903 X.X.115.133 X.X.116.153 HTTP 211 OUT s1/tmm3 : HTTP/1.0 503 Service Unavailable
Seems like it may not be making the full trip to the external system, and I did not see any DNS requests in the packet capture.
Michael_Goetz If you are not seeing the F5 perform any DNS requests for the forward proxy the DNS Resolver might not be configured correctly and that might be why this is failing. I never had any luck configuring a wildcard DNS Resolver but I was able to configure individual DNS Resolvers entries for each domain we were dealing with and that fixed our issues with DNS queries.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com