Forum Discussion
Using LTM as a forwarder for internet originated traffic (reverse proxy)
I have a scenario where a BIG IP appliance is bound to the corporate network, say 10.10.10.0/24. It is performing APM tasks like NTLM authentication and SAML single sign on. This appliance is next to our corporate services and I don't want to change this as 90% of the traffic will be initiated from the internal network.
We have a perimeter environment that we use, basically a DMZ, where I have an existing LTM appliance pair, say 10.199.10.0/24. There are SNATs from the internet to virtual server IPs on that network. On this LTM I already have virtual servers that communicate with 10.10.10.0/24 nodes over TCP 443. So really what I would like to do is change one of these virtual servers to an IP forwarder to forward to my APM enabled virtual servers on 10.10.10.0/24.
Is this something that is possible?
6 Replies
- Thomas_Gobet
Nimbostratus
Hi,
Do you want to keep the functionality of a virtual server ? Because you can do multiple things here, I'll list 2 of them only (better ones for me)
- Make a ip forwarder virtual server (you'll loose the http traffic vision)
- Keep your virtual server and set the APM IP as a pool member
- Rabbit23_116296
Nimbostratus
Thanks I have tried both options so far with no luck, the APM IP is 10.10.10.222
On the LTM in the DMZ I've tried option 1 and then set up a simple iRule and attached it to the forwarder:
when CLIENT_ACCEPTED {node 10.10.10.222}
Trying option 2 with it being a "Standard" virtual server with the APM IP address as a pool member does not work either (even if I attach a simple HTTPS monitor which indicates the member is reachable)
- Thomas_Gobet
Nimbostratus
Did you apply SNAT, or does your APM know how to route back the traffic through your LTM ?
- Rabbit23_116296
Nimbostratus
There's no SNAT but yes as you say I probably need networks to configure a route back to the APM's floating IP?
- Rabbit23_116296
Nimbostratus
correction meant the LTM's floating IP
- Thomas_Gobet
Nimbostratus
You need to apply SNAT or to define a route back to your floating IP.
I think your APM is sending the traffic back to your router then to your firewall without passing through the LTM.
That's why it doesn't work for you.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com