i have 3 nodes have this subnet 10.1.200.0/24, and the interface of the f5 have self IP 10.1.200.1/24 this is the gateway of these nodes. i have VIP 192.168.1.10/24, externally can the users reach the VIP without putting self_IP on the external interface? on Layer2 does the VIP have a mac address? and the Self_IP should be same subnet as the VIP?
Hi Elio,
Short answers to your questions:
- Can users reach the VIP without a Self IP on the external VLAN? Technically yes. The BIG-IP answers ARP for the virtual address on the VLANs where the virtual server is enabled, even without a Self IP there. Return traffic can use Auto Last Hop, which sends responses back to the MAC address the request came from. That said, I’d recommend configuring a Self IP on the external VLAN anyway: you’ll need it for a default route to your upstream gateway, for floating IPs if you move to HA, and it makes troubleshooting much more predictable.
- Does the VIP have a MAC address? Yes. When ARP is enabled on the virtual address, the BIG-IP replies to ARP requests for the VIP using the MAC address of the VLAN/interface.
- Does the Self IP need to be in the same subnet as the VIP? No. If the VIP is in the same subnet as the external Self IP, it’s resolved via ARP. If it’s in a different subnet, the upstream router just needs a route to the VIP pointing to the BIG-IP’s external Self IP as the next hop.
Also, since your nodes use the BIG-IP (10.1.200.1) as their default gateway, you don’t need SNAT for return traffic.
More info on Auto Last Hop:
Overview of the Auto Last Hop setting
Note: I used AI to help with the translation.
Best regards,
Quiroman81
Hi Quiroman81,
Thank you so much for this valuable information.
Best regards,
Elio