Forum Discussion
Using the same IP address for a VIP and a SNAT - yay or nay?
Hi,
We've run into a potential issue with response times from a VIP. Said VIP shares an IP address with a unique SNAT for outbound connections from a range of internal hosts. The VIP shares a range of pools, etc. with several other VIPs. We are not seeing the same "lag" in download speeds fom the other VIPs.
One quick way to rule out the shared IP of the VIP and SNAT would be to re-IP either. However, before we go down this route I'd like to ask if anybody has encountered a similar issue in the past and if this is a design no-no from an F5 perspective?
I should also mention, the SNAT is not a standard SNAT with an IP and pool members. Instead we have identified the next hop within our network. So, the configuration looks something like this:
1.
virtual snat-wcard {
snatpool LTM-public-IP
pool nexthop-gw
destination any:any
mask 0.0.0.0
vlans internal-pool-VLAN enable
}
2. The public SNAT IP is as follows:
snatpool LTM-public-IP {
members 192.168.1.2
}
2. The next hop gateway (up-stream routing device) is as follows:
pool nexthop-gw {
monitor all gateway_icmp
members 192.168.1.1:any {}
}
3. internal-pool-VLAN - vlan100 - 10.1.1.0/24
12 Replies
- What_Lies_Bene1
Cirrostratus
Indeed. Packet capture deep analysis time. Thanks for letting us know. - Craig_17766
Nimbostratus
Not sure if it helps and since the sharing of the address may not be the issue, we recently had a similar issue with lag turned out to be an issue with the nagle algorithm. We are now using the tcp-wan-optimized profile on the virtual with the issue thus disabling the nagle feature.
I am by no way an F5 expert so please go easy on me if I’m taking rubbish :)
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
