Forum Discussion
Trying to create an internal IP virtual server pointed to a load balanced pool for an API call
Hi Ronnie,
- Verify F5 can reach the servers {Ping}
- If the servers don't have F5 IP as default gateway, enable SNAT(snat-pool or automap) on your virtual server.
HTH
- Ronnie_MunozNov 27, 2018
Nimbostratus
- Confirmed the servers are pingable/reachable from the F5. They are passing their health check and the pool is up and ready for traffic.
- Auto Map SNAT enabled, that is our default virtual server config build.
- ebenNov 27, 2018
Nimbostratus
Share the output of the following;
tcpdump -nni 0.0:nnnp host and port
tmsh list ltm virtual
- ebenNov 27, 2018
Nimbostratus
-
If the server vlan is not setup on the device(F5), do "tmsh show net route lookup ", get the F5 egress ip address from the output of the cmd and create and add the egress ip add to a snat-pool, apply the snat pool to the virtual server and try again.
-
Set your vs to listen on port 80 and enable port-translation. and also try accessing.
-
How do you access the backend server service (URL)?
-
What version of TMOS are you running?
-
- Ronnie_MunozNov 27, 2018
Nimbostratus
- Server vlan is set up on the F5. These two pool members are being used in other pools and completely accessible for other traffic.
- I set the virtual server to port 80 and enabled port-translation, no change, still not accessible.
- Visiting the server address directly gives me a 403, so server error, something is there and listening, just not when I try through the F5 virtual server address.
- ebenNov 27, 2018
Nimbostratus
- What exactly do you get as response when you try to access the VS?
- Correct this if not accurate as I do not have specifics of your ip addressing, CleintSide-> 10.234.xxx.xxx.50856 > 192.168.xxx.xxx.9000 ServerSide-> 192.168.xxx.xxx.50927 > 10.228.128.76.9000 ?
- Ronnie_MunozNov 27, 2018
Nimbostratus
1.Browser error "This page can't be displayed" 2.That path appears to be correct. 10.228.128.76 is one of the two servers in the pool, other being 10.228.128.77.
- ebenNov 28, 2018
Nimbostratus
- If my previous comment was accurate, why is the F5 using 192.168.xxx.xxx:50927 connecting to the backend server 10.228.128.76:9000 if it has a the server vlan configured?
2.This could be a PMTU issue, as you are getting too many DF bit set in the tcpdump. Open a support case for this.
Regards
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
