We have a wideip in our environment for VPN users and its Topology based. But the configuration is slightly different. The users DNS server subnet is not defined in region.user file because the wideip era0.fidelity.com uses geoip based DNS events (meaning it houses an internal database of internet addresses f5 got from an arin.net provider or the like) not subnet based like an intranet based GTM would.
Now the issue is we see users in India region, is hitting Merimac VPN servers whereas as per topology they should hit only India servers. Also The capacity limit on India VPN server is fine and can take traffic .
Below is the setup:
gtm wideip era0.fisc.fidelity.com { ipv6-no-error-response enabled persistence enabled pool-lb-mode topology pools { era0.fidelity.com-Ind { order 4 } era0.fidelity.com-all { } era0.fidelity.com-dcc { order 2 } era0.fidelity.com-mko { order 1 } era0.fidelity.com-rtp { order 3 } } ttl-persistence 60 }
Topology records:
Topology Records: 0.0.0.0/0era0.fidelity.com-all250 RemoteAccess-NorthernEuropeera0.fidelity.com-mko500 RemoteAccess-SouthAmericaera0.fidelity.com-mko500 RemoteAccess-SouthernEuropeera0.fidelity.com-mko500 RemoteAccess-Australiaera0.fidelity.com-mko500 RemoteAccess-NorthCentral-USera0.fidelity.com-mko500 RemoteAccess-NorthEast-USera0.fidelity.com-mko500 RemoteAccess-SouthernAsiaera0.fidelity.com-dcc500 RemoteAccess-Africaera0.fidelity.com-dcc500 RemoteAccess-Alaska-Hawaiiera0.fidelity.com-dcc500 RemoteAccess-SouthWest-USera0.fidelity.com-dcc500 RemoteAccess-SouthCentral-USera0.fidelity.com-dcc500 RemoteAccess-SouthernNorthAmerica-NonUSera0.fidelity.com-rtp500 RemoteAccess-NorthernNorthAmerica-NonUSera0.fidelity.com-rtp500 RemoteAccess-NorthernAsiaera0.fidelity.com-rtp500 RemoteAccess-NorthWest-USera0.fidelity.com-rtp500 RemoteAccess-SouthEast-USera0.fidelity.com-rtp500 ERA-Indiaera0.fidelity.com-Ind500