Forum Discussion
Unable to access Server after load balancing
Hi,
My F5 is in routed mode.
client will hit on VIP 192.168.49.251
server IP adress is 192.168.205.119 and 120
I am doing HTTPs load balancing for servers. But after enabling the load balancing syste admin is not able to access the servers on the real IP address. Servers are having the gateway towrads F5 IP address.
Please let me know what needs to be enable in order to access the servers on real IP and as well as clients can access the HTTPS websites through the VIP.
5 Replies
- Matt_Dierick
Employee
Hi,
Use SNAT or add static route in servers in order to route to system admin network.
- Wasim_Hassan_13
Nimbostratus
thanks for the reply,
My F5 is having the default gateway towards the core switch, Users are also connected on the same switch in the different vlan and sys admin vlan is also located over there.
IF default route on the F5 is already the core switch where all users/sys admin VLAN is already connected will it helpful by adding a static route on the F5 towards core switch.
Also by add static route in Server towards sys admin VLAN will disturb them becase they will not able to access the app.
- Cory_50405
Noctilucent
Wasim,
Can you ping the server real IP addresses from your LTM? If so, can you apply a TCP monitor to the pool and see if any of the members go green? If none do, take a tcpdump on your LTM and see if you see any response from the LTM.
The reasons for this connection not working could be quite a few. These tests should help narrow down the possibilities.
- Wasim_Hassan_13
Nimbostratus
i can ping and the status is green for the Health for both the servers. The problem is with asymetric routing. sys admin (192.168.80.0 VLAN) having gateway of Core switch to reach the servers which is having F5 as a gateway. So request from sys admin are going through the core for physical IP (192.168.205.211) but reverse traffic is coming back through the F5. session break
If i will add the static route in physical servers it will distrub the return traffic for sys admin vlan and they will not able to access the web service.
Is there anyway that we can create irule so that i can access the servers on physical IP as well as able to access the webpage through the VIP.
- Cory_50405
Noctilucent
Your sys admin vlan default gateway can be on your core switch. If you enable SNAT on the virtual server as Matthieu suggested, then this should take care of your issue. Try enabling SNAT auto map on your virtual server and see if that fixes things.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com