Forum Discussion
Harris_Hassan_3
Nimbostratus
May 09, 2008VPN connection behind F5 Link controller
Hi ,
Just wondering , has anyone done a VPN termination which terminates on a firewall behind an F5 link Controller. Having some issues establishing a tunnel despite NAT'ing the Firewall external interface via Virtual Server and SNAT.
Previously customer only had one ISP and it was connected directly to their Juniper SSG. Now that the SSG is behind the F5 with a private IP , can't seem to get the tunnel up and running.
Anything that i should try besides creating a Virtual server and SNAT'ing the fw external interface to a public IP.
Thanks
- dennypayne
Employee
The only way I've been able to get that to work is by allowing IP forwarding to the network behind the LC from one of the links so that a direct connection can be made to the VPN termination IP. That means that a) the backend network probably has to be publicly routeable and b) the VPN tunnel is confined to one link and won't be able to fail over to any other links. - Harris_Hassan_3
Nimbostratus
Got a TCPdump of the whole transaction. It seems the NAT is working on the F5 and is able to reach the Firewall internal interface. However , once packet is sent out to remote host , it stops at the F5 Private ip address. - Keith_Richards_
Nimbostratus
Yes, I have seen this working between Check Point Firewall-1 gateways - even works with path probing so the VPN can failover between ISPs. I think that you would be best sending IKE negotiation debug info to a Juniper forum and see if that shows up an issue. There isn't an inherent reason why an IPsec VPN can't work through Link Controllers. - kykong_107132
Nimbostratus
- Harris_Hassan_3
Nimbostratus
KY ... - Harris_Hassan_3
Nimbostratus
Double post , apologies - Harris_Hassan_3
Nimbostratus
Close to a solution now. Hopefully it's a permanent solution. - bruce_p_11387
Nimbostratus
Posted By kky on 05/12/2008 6:46 PM
- Beginner_92603
Nimbostratus
Can someone inform about the final configuration required to have IPSec Tunnel up and running with a firewall behind the Link Controller (using private IP) - Harris_Hassan_3
Nimbostratus
Posted By tkito on 10/20/2008 4:40 AM
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects