Forum Discussion
Chris_Phillips
Nimbostratus
Oct 03, 2006voyeuristic pool monitoring
Hi all,
Unless i'm very much mistaken there is no way at all within the LTM's to make them snat their monitor traffic. As such whilst we can happily use a snatpool or such on a virtual serve...
Deb_Allen_18
Oct 04, 2006Historic F5 Account
Hi Chris -
I'll just chime in to answer your question as to why we don't have the ability to SNAT monitor traffic:
Monitor traffic is sourced from the non-floating self-IP for each unit in a redundant pair, since each unit will be performing its own independent health checks. (If a monitor instead used a floating address as a sourceIP, the standby box would never get a response, so all the nodes would be marked DOWN until after that unit became Active -- obviously not an ideal situation on failover for all nodes to be marked DOWN on the newly active unit.)
SNATs, on the other hand, are typically configured to use floating self-IPs (or SNAT-defined shared address) to maintain consistency on failover, so you would need to have a firewall rule allowing all 3 addresses to access the nodes.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects