Forum Discussion
Stephane_Bernar
Nimbostratus
Jun 17, 2008Virtual Server /SNAT and Timeout
Hi,
i am running : BIG-IP 9.2.3 Build 34.8 and i have the following problem.
I have a VIP . 172.25.128.51 which uses the "tcp profile" which i have modified to extend the idle timeout to 1800 seconds as people were complaining that the application was timing out after 5 minutes [300 seconds which is the default number of seconds for the tcp profile]. This VIP is associated to a default pool which contains two servers.
This VIP used to have "Automap" selected for SNAT. But after reading this article https://support.f5.com/kb/en-us/solutions/public/7000/600/sol7606.html?sr=690509 i understand why the timeout of 5 mintues was still there [Note: An automap SNAT has a non-configurable idle timeout of 300 seconds.]
So what i did is: I created a SNAT pool with the IP address of the VIP [what the BIG-IP LTM does when you select automap in fact] changed the TCP Idle Timeout to 1800 seconds and associated that pool with that VIP
But the timeout is still 5 minutes or 300 seconds. What am i missing?
Regards
8 Replies
- dennypayne
Employee
Actually automap should use one of the LTM's self-ip's, not the vip address, but that doesn't really matter here. What you have done should work. I would try changing the SNAT pool to use a separate IP address and see what happens, if that makes a difference I would consider that a bug.
9.3.1 is the current maintenance release for the code branch you are using, I would definitely recommend upgrading off 9.2.3 in any case. I'll have a look at the release notes and see if there's anything related to this in there...
Denny - dennypayne
Employee
From the 9.3 release notes:
Timeout values for SNAT pool members (CR53064)
When adding a member to a SNAT pool, the system no longer removes the timeout values that are currently set for the other members of the SNAT pool. Now, the system leaves the timeout values as you set them for the pool members.
This could apply as well, depending on the PVA settings:
PVA and timeout values (CR69775, CR70547)
In previous releases, the FastL4 profile did not restrict a maximum timeout value; however, the Packet Velocity® ASIC (PVA) daemon could not handle timeout values over certain amounts. (The exact timeout value depends on the PVA version.) When the PVA timeout value was exceeded, idle connections could close prematurely. With this release, if the maximum timeout is exceeded, the system demotes the PVA to Assisted mode, which allows the system to control the timeout value.
And if you are using OneConnect this might apply:
Persistent HTTP connections and TMM (CR71998)
Now, the system correctly handles persistent HTTP connections on a OneConnect™ virtual server using secure network address translation (SNAT).
Anyway, definitely worth getting onto the 9.3 maintenance branch.
Denny - Stephane_Bernar
Nimbostratus
thank you for your reply. I did change the IP address and it didn't change anything. What's interesting is the following:
When i disable one of the nodes [web server] then all the requests from the BigIP are redirected to the only web server up and running.
In that case, the session is not timing out after 5 minutes but after 30 minutes as configured.
Any clues?
Regards - Stephane_Bernar
Nimbostratus
If you have the same issue or came accross the similar proble please help.
Regards - Deb_Allen_18Historic F5 AccountSounds like it might be this now:
Timeout values for SNAT pool members (CR53064)
When adding a member to a SNAT pool, the system no longer removes the timeout values that are currently set for the other members of the SNAT pool. Now, the system leaves the timeout values as you set them for the pool members.
What happens if you swap out pool members so the other one is disabled? 5 min or 30 min timeout?
/deb - Stephane_Bernar
Nimbostratus
On my SNAT_POOL, I have only one member [one of the LTM self IP] so i manot sure what you indicated is relevant. But i get a 30 minutes timeout if i shut down one the web server on the default pool used by the VIP [i am using source_Addr for the Default Persistence Profile ] - Stephane_Bernar
Nimbostratus
On my SNAT_POOL, I have only one member [one of the LTM self IP] so i manot sure what you indicated is relevant. But i get a 30 minutes timeout if i shut down one the web server on the default pool used by the VIP [i am using source_Addr for the Default Persistence Profile ] - Deb_Allen_18Historic F5 AccountWhen i disable one of the nodes [web server] then all the requests from the BigIP are redirected to the only web server up and running.
I meant what happens when you disable the other webserver?
/d
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
