For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

JotaCePena_1783's avatar
JotaCePena_1783
Icon for Nimbostratus rankNimbostratus
Sep 28, 2016

VS with automap does not work but with snat_pool work fine

We have a VS with automap configuration, this VS worked fine until yesterday, after that, the VS does not work fine anymore. The only change in configuration was use a snat_pool instead automap.

 

VS is balancing port 80 and pool redirect traffic to many different ports. Pool has 6 backend server. Service Monitor is TCP_HalfOpen

 

6 Replies

  • Normally, issues like this would be because of the underlying network configuration. I would recommend checking to make sure you have the right connectivity between the SNAT IP addresses and the pool members. Are the self-IP address that are utilized for traffic flow and the IP addresses in the snat pool in the same network ?

     

  • Rhys_Peters_770's avatar
    Rhys_Peters_770
    Historic F5 Account

    I am assuming that the IP range of the SNAT pool is not within the same subnet range as the exit VLAN (ie when you use Automap it will select the self IP address of the exiting VLAN)

     

    If this is the case it sounds like there is no route back to the SNAT pool. I would verify the network configuration to ensure there is a route back to the SNAT pool via the exit VLAN.

     

    • IainThomson85_1's avatar
      IainThomson85_1
      Icon for Cumulonimbus rankCumulonimbus

      I would look exactly where Rhys and Odaah have suggested.

       

      If there is a fundamental routing issue (I.e. not on the same VLAN)... Alternatively if you've got an inline firewall/server firewall blocking the new IP address you've chosen.

       

  • What does "does not work fine anymore" mean exactly? Didn't it work at all anymore or were you experiencing intermittent errors?

     

  • If you are using a SNAT POOL then you must have configured it with one or more translation addresses. Request you to confirm in case that has been done.

     

  • Actually only some pool members answered the requirements for a few minutes, then did not respond either. In f5 there are other VS that run smoothly.

     

    The SNAT POOL has set a IP address for translation.