Forum Discussion
OttimoMassimo_1
Nimbostratus
May 13, 2013Using the same IP address for a VIP and a SNAT - yay or nay?
Hi,
We've run into a potential issue with response times from a VIP. Said VIP shares an IP address with a unique SNAT for outbound connections from a range of internal hosts. The VIP shares a ra...
What_Lies_Bene1
Cirrostratus
May 13, 2013I've SNATted traffic using the VS address as the source on a pretty large scale in the past without issues.
Regarding your design I suspect the issue may lie with the fact the IP is shared with a wildcard VS. The SNAT may assign a source port that is then used for the destination port by a client attempting to connect to the the VS, the F5 has no way of knowing or reserving ports in this scenario and I'm amazed it works at all. If the VS was restricted to a single port this wouldn't be an issue as the F5 would know what not to use for the SNAT.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
