Forum Discussion
OttimoMassimo_1
Nimbostratus
May 13, 2013Using the same IP address for a VIP and a SNAT - yay or nay?
Hi,
We've run into a potential issue with response times from a VIP. Said VIP shares an IP address with a unique SNAT for outbound connections from a range of internal hosts. The VIP shares a ra...
What_Lies_Bene1
Cirrostratus
May 14, 2013OK, the extra information you've provided mostly indicates that sharing the address is not the cause of your issue, however, let me respond to a few things;
1) The originating segment doesn't matter; if the SNAT IP consumes port 16000 for an outbound translation that port cannot be used to serve a different inbound connection to the same IP address. Port 16000 for that IP address has already been used, how, why or where is not relevant.
2) Apologies but I missed the fact the inbound VS was NOT wildcard and was getting confused with the outbound one.
3) Regarding the Linux OS, this is a red herring. Any settings found there are for the HMS and management functions and interface. LTM/TMM does not use these settings; it has multiple protocol stacks that operate independently of the HMS. So yes, it's possible a lower port number could be used for an SNAT and that setting is completely ignored for anything other than management related traffic.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
