Forum Discussion
Will F5 single arm setup work without SNAT?
Hi Ed, I was reading through the email that PS tech sent to my architect and in that he made following statements why this will not work, maybe you can shed more light based on that -
In a one armed solution some type of SNATing is required for laod balancing to work - either explicit SNAT pools or through AutoMap. You are right that if we don't use any type of SNATing, then the source IP is going to be visible on the end server. But, again if we are using a one armed solution, SNATing is a pre-requisite.
If we are using load balancing even with no SNATing, the outside client will not see the IP address of the server, on the return path, the IP address is re-written to be that of the VIP.
If we don't SNAT, the IP address of the source is not lost to the server, however, the server address is re-written on the way back to the client.
Unless we have the networking architecture to support this scenario - 2 arm network with server's gateway address pointing to F5 floating address, this will not work and you will get TCP RSTs.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
