Forum Discussion
Virtual Server Cannot Access External Pool Members
- Mar 13, 2017
Are you able to reach these Google external IP from f5(ping, telnet,wget)? What is the status of pool member on f5?
Are you able to reach these Google external IP from f5(ping, telnet,wget)? What is the status of pool member on f5?
- Company_B_88989Mar 13, 2017Nimbostratus
All of the health checks are green for the pool members. I can also cURL to any of the pool members form the F5 TMSH.
- Stephane_Viau_1Mar 13, 2017Nimbostratus
Which stats are you looking at?
Also, can you tell us what your NAT settings are for this Virtual Server?
- gsharriMar 13, 2017Altostratus
Try setting the VS source address translation to automap and see if it works. If so then there is a routing problem affecting the return traffic.
- Company_B_88989Mar 13, 2017Nimbostratus
VS source address translation is set to automap.
I do not have NAT or SNAT configured for this VS since it is for internal use only. I know this is considered a sideband connection, so I'm not sure what is missing.
We use our edge firewall to handle SNAT translation for the other virtual servers and we do have an ACL rule that allows this ip to connect externally.
- Stephane_Viau_1Mar 13, 2017Nimbostratus
You should look at both VS stats and Pool stats, but otherwise I think you might need to use tcpdump to figure out what's happening.
When you use curl from the Big-IP command line, are you sure that you are using the same source IP as when using automap on your VS?
- Company_B_88989Mar 14, 2017Nimbostratus
When you use curl from the Big-IP command line, are you sure that you are using the same source IP as when using automap on your VS?
This may be the part I am not understanding. We do not have any SNAT translations set up and the source IP for the Google VS is 0.0.0.0/0
- Stephane_Viau_1Mar 14, 2017Nimbostratus
You said you were using Automap for your VS's source address translation. Automap will let the Big-IP decide which IP to use for address translation. So if your Big-IP has multiple Self IPs, which is fairly common, it is possible that your curl command from the command line works because because it could use a different source IP than the one selected by the Big-IP's Automap feature on your VS.
I think tcpdump is your best friend in this scenario.
- Company_B_88989Mar 14, 2017Nimbostratus
Thanks, I will try the tcpdump
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com