one of the applications, there are four backend servers, but currently the traffic is being directed to only one pool member but want to distribute or utilize all backend servers.
The current configuration is as follows:
• Persistence profile: Enabled with Hash
• WAF SNAT: None
• LB SNAT : Automap
• LB pool method: round robin
• X-Forwarded-For: Enabled on WAF
• X-Forwarded-For: Also enabled on the LB
However, despite the above configuration, the traffic is sticking to a single pool member. The client requirement is to distribute the traffic across all four backend servers.
with the information you gave us, it is difficult to say why there is an uneven distribution of the load-balancing. Looks correct.
The BIG-IP should see the real client IP as the source, since there is not NAT on the WAF.
For the egress traffic the BIG-IP for sure has a route via the WAF.
In such setup the XFF header should be irrelevant for the load-balancing decission. Since it’s a client header it’s anyway not good for load-balancing, since it may be manipulated.
Round-robin is only used once for the initial load-balancing decision, afterwards the persistence method is used.
Can you share the virtual server config and the persistence profile with us?
Did you try looking at the persistence table on the F5 for that virtual server?
Did you take a tcpdump for that virtual server, to make sure the virtual sees the real client IP?
I have noticed that the round robin load balance algorithm has preference for one of the pool members. The least connections algorithm should provide the the best distribution of traffic across the pool members.
When persistence is used. The balance of the traffic will be weighted by the sessions with the longest duration. Only the first data-gram of session is load balanced. All the future data-grams are persist to the pool member that was selected by the load balancing algorithm. The pool members with the most sessions are the servers with the longest running sessions.