Forum Discussion
Virtual forwarding server versus routing table
Hello there:
I'm pretty new to the F5 system, recently purchased the F5 10259v. Now I am stuck with the routing, especially when I try to do the intra-vlan routing and route all vlans back to my headquarter company through Cisco ASA (VPN). I was told to setup the virtual forwarding servers, I did set them up, but none of them work!!! And I don't know what I shall do with it. In my case, it seems only routing table can help me a bit. For example I am able to route one vlan back to my remote network. When I search this forum for the right answer, I don't see much people mentioned about the routing table when talking about the VS. I get confused. If we have the routing table why bother to use the VS??
Thanks
35 Replies
- The_Bhattman
Nimbostratus
Did you try to enable the VS fowarding on all VLANs?
- Felix888_164906
Nimbostratus
oh yes, I enable the VS all the time. I also tried to setup VS as source 0.0.0.0/0 to 0.0.0.0/0. It doesn't work though.
- The_Bhattman
Nimbostratus
What do packet captures reveal?
- Felix888_164906
Nimbostratus
I have a host tried sitting in the vlan 7 try to ping the server in the company. Below is the tcpdump captured in the LTM: [root@ltm1:Active:Standalone] config tcpdump -ni 0.0 host 192.168.130.98 tcpdump: verbose output suppressed, use -v or -vv for full protocol decode listening on 0.0, link-type EN10MB (Ethernet), capture size 96 bytes 18:12:03.004386 IP 10.0.7.250 > 192.168.130.98: ICMP echo request, id 512, seq 32787, length 40 18:12:08.504241 IP 10.0.7.250 > 192.168.130.98: ICMP echo request, id 512, seq 33043, length 40 18:12:14.004117 IP 10.0.7.250 > 192.168.130.98: ICMP echo request, id 512, seq 33299, length 40 18:12:19.504020 IP 10.0.7.250 > 192.168.130.98: ICMP echo request, id 512, seq 33555, length 40
- Felix888_164906
Nimbostratus
On the ASA side I cannot see any attempted packet destined for 192.168.130.98.
- Felix888_164906
Nimbostratus
It seems VS does no impact at all to my routing work. Luckily I can still connect to vlan 2 to access to the devices at the remote. If I remove the routing entry, and only setup the VS, I can connect to nothing...
- The_Bhattman
Nimbostratus
And your route towards 192.168.130.98 is through the ASA? If so you have a route 192.168.0.0/16 pointing the ASA interface?
- Felix888_164906
Nimbostratus
Yes, this was configured in the static routing table:
- Felix888_164906
Nimbostratus
Yes, this was configured in the static routing table: destination: 192.168.0.0/16Gateway IP 10.0.2.2there is also the routing table (VPN) in ASA:route 192.168.0.0/16 to the headquater through lan interface 10.0.2.2If the packet can reach the ASA LAN interface, it will be routed to the remote server via VPN.Internal routing back to F5 at LAN interface of ASA:route LAN 10.0.0.0 255.255.240.0 10.0.2.1 1
- The_Bhattman
Nimbostratus
According to the diagram, the ASA is 10.20.0.2 not 10.0.2.2
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com