In a previous article, I provided a guide on using F5’s Access Policy Manager (APM) and Secure Web Gateway (SWG) to provide forward web proxy services. While that guide was for organizations that are looking to provide secure internet access for their internal users, URL filtering as well as securing against both inbound and outbound malware, this guide will use only F5’s Local Traffic Manager to allow internal clients external internet access.
This week I was working with F5’s very talented professional services team and we were presented with a requirement to allow workstation agents internet access to known secure sites to provide logs and analytics. Of course, this capability can be used to meet a number of other use cases, this was a real-world use case I wanted to share. So with that, let’s get to it!
Creating a DNS Resolver
Navigate to Network > DNS Resolvers > click Create
Name: DemoDNSResolver
Leave all other settings at their defaults and click Finished
Navigate to Local Traffic > Virtual Servers > click Create
Name: explicit_proxy_vs
Type: Standard
Destination Address/Mask: 10.1.20.254
Note: This must be an IP address the internal clients can reach.
Service Port: 8080
Protocol: TCP
Note: This use case was for TCP traffic directed at known hosts on the internet. If you require other protocols or all, select the correct option for your use case from the drop-down menu.
In order to catch and forward all traffic to the BIG-IP’s default gateway, we will create a virtual server to accept traffic from our explicit proxy virtual server created in the previous steps.
Navigate to Local Traffic > Virtual Servers > Virtual Server List > click Create
If it is not, for troubleshooting purposes only configure to the virtual servers to accept traffic on All VLANs and Tunnels as well as useful tools such as curl and tcpdump.
You have now successfully configured your F5 BIG-IP to act as an explicit forward web proxy using LTM only. As stated above, this use case is not meant to fulfill all forward proxy use cases. If URL filtering and malware protection are required, APM and SWG integration should be considered. Until next time!
We have a explicit F5 forward proxy server where I am able to access all external sites and it works fine however I can’t reach any my internal sites , It said "DNS lookup failed " .
from BIG-IP I can resolve these sites but not working in browser., In DNS resolver list I have called the internal DNS server which can resolve all the DNS entries internal and external.
@Sergi0 : the Explicit Proxy Virtual Server convert proxy connection with CONNECT method to TCP connection. CONNECT method is usually for HTTPS connection when the proxy must not inspect the content.
This connection is injected into an internal network to be forwarded to the destination.
Then the HTTPS virtual server with destination 0.0.0.0/0 listen on this internal network to enabled SSL Forward Proxy.
As Stanislas mentioned, the network tunnel will maintain the HTTP CONNECT tunnel for SSL traffic using the tcp-forward profile. I just searched for documentation around this and I honestly don’t see a ton. I will keep searching and share if I find anything.
Its not working when I configured in Partition. I do not see traffic on Wild CARD VS configured in Partition. I am not sure if above solution supports in F5 Partition.
@Ajit, do you have an external self IP configured that allows access to the external internet or whatever you are using as a DNS resolver? You can also run ip route get <server ip address> to determine which IP address is being used to communicate with the DNS resolver.
Honestly this is the first time I am seeing any of these comments so if it is related to internal websites, you should probably be bypassing any type of proxy for internal addresses. If not, let me know and we can figure out how to resolve it.
No, these are Amazon VPC endpoints that I am trying to resolve. If I set the same DNS server that I use in the DNS resolver in nslookup command then it resolves without any issues. However, the same DNS server is unable to resolve via the proxy solution. Am I missing something.
, can you validate that when you do a tcpdump, you see queries sent and received on the IP you have configured in your DNS resolver? I too was getting DNS failures in my browser when I just set this up again in my own environment which let me to believe I did not have a route configured for my queries and external connections to use. I have a very basic configuration and when I did an “ip get route 8.8.8.8” it was attempting to use my mgmt IP. That of course is not going to work so I configured a default route for my BIG-IP to use a gateway that had access to the outside world. Using ip route get and tcpdump, can you validate your connections are being attempted using your external self IP? If you do not have an external self IP configured, that needs to be done first. I will be updating this article to reflect these troubleshooting steps as well. Let me know.
[root@ip-10-1-1-4:Active:Standalone] log # ip route get 8.8.8.8
8.8.8.8 via 10.1.10.1 dev External src 10.1.10.240
All the configuration & routing looks perfect however, the dns resolvers are not resolving the hostnames.
I think the issue is that I had first set the forward zone name as “TestDNS” initially, later realized that it is incorrect. I then changed the forward zone name as “dot” however in-spite of the correction made the DNS resolver refuses to resolve the FQDN’s whatsoever. I think it has some bug / misbehavior after the correction. When I built the same setup on another LB with the exact steps (no mistakes in any step) then it worked perfectly.
, I cannot be sure about your configuration without seeing it but I can tell you I have deployed this using v13, v14, and v15. I have customers currently running this on v13 and v14. The biggest issue my customers faced was understanding how and what self IP was being used to perform the resolution. They each experienced the same issue you did regarding the inability to resolve but after validating the external self IP being used, it began functioning as expected. Some created default routes to use the external self IP. I am sorry you are unable to get this functioning. I would definitely recommend opening a ticket with F5 support to determine why resolution is not occurring.
This also entails https traffic. There is no additional configuration for this specific use case. With that, if we are terminating SSL for inspection or authentication purposes then yes there would be additional configuration items.