Dear community,
I’m trying to reverse engineer and configure F5 with SNAT enabled for local and distributed static analysis from nginx vendor sample config given:
http {
server {
...
...
location / {
...
...
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_buffering off;
proxy_cache off;
proxy_request_buffering off;
proxy_read_timeout 1w;
proxy_connect_timeout 300s;
}
}
}
For F5 we have deployed HTTP L7 fast profile with cookie and X-Forwarded-For iRule as per the diagram below and SNAT. This is the best we tested out and worked straight with the version of BIGIP we have.
F5 setup
This setup works fine when the static analyzer is running locally on the build server without requesting extra remote build resources via the proxy in the remote service discovery mesh located on the machine storing the static analysis solution. Here is our sample F5 configuration we are currently at.
ltm virtual VIP-SAST-HTTPS {
destination xxx%3404:https
ip-protocol tcp
mask 255.255.255.255
partition foo-tenant-dept-prd
persist {
/Common/HTTP-COOKIE {
default yes
}
ltm persistence cookie HTTP-COOKIE {
app-service none
defaults-from cookie
}
}
pool POOL-SAST-8045
profiles {
/Common/F5-FASTHTTP { }
}
ltm profile fasthttp F5-FASTHTTP {
app-service none
defaults-from fasthttp
}
}
rules {
X-FORWARD-FOR-TEST
when HTTP_REQUEST {
HTTP::header insert X-Forwarded-For [IP::remote_addr]
}
}
serverssl-use-sni disabled
source 0.0.0.0/0
source-address-translation {
type automap
}
translate-address enabled
translate-port enabled
vlans {
xxxsp_lb_vip01
}
vlans-enabled
vs-index 100
However, we’re seeing a problem with passing traffic through the SNAT ingress address when distributed analysis mode is enabled. In this mode, an RPC call from the build server via the proxy is launched first either cronjob or manually or systemd, telling the service mesh on the remote back-end servers where the remote build server is:
ssh server install-sast-rpccmd https://F5_VIP
Later when the analysis starts, the static analyzer is looking into the service mesh on the back-end servers where the free build servers servers are. Then static analyzer opens a master process on a random port on the build server and expects the SNAT ingress address to have the same port open and forwarded to the back-end pool members at the port configured on the backend servers - 8045 in this case.
Sample error message:
Mon Nov 27 16:49:48 2023 Slave 59897 host-sast1] Connecting to master at `SNAT_IP:53034'... (with TLS)
[Mon Nov 27 16:49:48 2023 Slave 27386 host-sast2 Connecting to master at `SNAT_IP:53034'... (with TLS)
msgpass_connect(SNAT_IP:53034) failed: Connection timed out
Connection times out as the port on the SNAT ingress controller is closed and not forwarded further the SNAT IP pool to the backe-end 1:1. Can you please advise how forwarding the source port via the SNAT unaltered can be achieved?
- e.g. having an iRule that traverses the SNAT ingress address and connects to the back-end port or something else? Example from GPT bot for which I need validation
when HTTP_REQUEST {
HTTP::header remove X-Custom-XFF
HTTP::header insert X-Custom-XFF "[IP::client_addr]:[TCP::client_port]"
set my_x_forwarded_for [HTTP::header "X-Forwarded-For"]
set client_ip [IP::client_addr]
set client_port [TCP::client_port]
if { $my_x_forwarded_for ne "" } {
# If X-Forwarded-For header is already set, append the client IP and port
set my_x_forwarded_for "$my_x_forwarded_for, $client_ip:$client_port"
} else {
# If X-Forwarded-For header is not set, set it with the client IP and port
set my_x_forwarded_for "$client_ip:$client_port"
}
# Set the X-Forwarded-For header with the modified value
HTTP::header replace "X-Forwarded-For" $my_x_forwarded_for
}
when HTTP_RESPONSE {
# Disable buffering and caching in the response
HTTP::disable
HTTP::buffering off
HTTP::cache disable
HTTP::request buffer disable
# Set the read timeout to 1 week (604800 seconds)
HTTP::read_timeout 604800
}
=====
when CLIENTSSL_HANDSHAKE {
# Enable SNAT automap
snat automap
}
- Bonus points for adding QoS low delay /high priority from back-ends to build-servers

