F5 is upgrading its customer support chat feature on My.F5.com. Chat support will be unavailable from 6am-10am PST on 1/20/26. Refer to K000159584 for details.

Forum Discussion

Rabbit23_116296's avatar
Rabbit23_116296
Icon for Nimbostratus rankNimbostratus
Jan 07, 2014

Using LTM as a forwarder for internet originated traffic (reverse proxy)

I have a scenario where a BIG IP appliance is bound to the corporate network, say 10.10.10.0/24. It is performing APM tasks like NTLM authentication and SAML single sign on. This appliance is next to our corporate services and I don't want to change this as 90% of the traffic will be initiated from the internal network.

 

We have a perimeter environment that we use, basically a DMZ, where I have an existing LTM appliance pair, say 10.199.10.0/24. There are SNATs from the internet to virtual server IPs on that network. On this LTM I already have virtual servers that communicate with 10.10.10.0/24 nodes over TCP 443. So really what I would like to do is change one of these virtual servers to an IP forwarder to forward to my APM enabled virtual servers on 10.10.10.0/24.

 

Is this something that is possible?

 

6 Replies

  • Hi,

     

    Do you want to keep the functionality of a virtual server ? Because you can do multiple things here, I'll list 2 of them only (better ones for me)

     

    1. Make a ip forwarder virtual server (you'll loose the http traffic vision)
    2. Keep your virtual server and set the APM IP as a pool member
  • Thanks I have tried both options so far with no luck, the APM IP is 10.10.10.222

     

    On the LTM in the DMZ I've tried option 1 and then set up a simple iRule and attached it to the forwarder:

     

    when CLIENT_ACCEPTED {node 10.10.10.222}

     

    Trying option 2 with it being a "Standard" virtual server with the APM IP address as a pool member does not work either (even if I attach a simple HTTPS monitor which indicates the member is reachable)

     

  • Did you apply SNAT, or does your APM know how to route back the traffic through your LTM ?

     

  • There's no SNAT but yes as you say I probably need networks to configure a route back to the APM's floating IP?

     

  • You need to apply SNAT or to define a route back to your floating IP.

     

    I think your APM is sending the traffic back to your router then to your firewall without passing through the LTM.

     

    That's why it doesn't work for you.