Re: F5 configuration help is needed

Kenneth Salchow <[email protected]> Mon, 21 Sep 2009 09:12:30 -0700
Newsgroups gmane.comp.programming.load-balancing.general
Message-ID <4B18A8F75A6384449755BC7784073E9360D0FD8551@exch11.olympus.f5net.com>
Tony--

Thanks for pointing out the default route option--it's one many people
forget about--just because the BIG-IP is not *really* the outbound router
doesn't mean it can't forward packets.  Even if the servers in question may
handle other services that don't go through the BIG-IP on the inbound, if
you add a wildcard VS on the BIG-IP, it will still allow those services to
work on the outbound--you just get an extra hop.

Anyway--good call Tony! :-)

KJ (Ken) Salchow, Jr. | Manager, Technical Marketing
D 651.423.1133
M 612.868.1258
P 206.272.5555
F 206.272.5555
www.f5.com



-----Original Message-----
From: [email protected] [mailto:[email protected]] On Behalf Of
Tony Bourke
Sent: Friday, September 18, 2009 6:20 PM
To: Load Balancing Mailing List
Subject: Re: [load balancing] F5 configuration help is needed

Hello Sezen,

Basically, we need to accomplish two things with this.  We need to 
ensure traffic hits the F5 on the way in, and traffic hits the F5 on the 
way out. 

As mentioned, there's the option of doing a SNAT, basically making all 
inbound web requests appear to the web servers to be coming from the F5 
itself.   Since the servers respond to the F5 directly, we ensure 
traffic hits the F5 on the way in and on the way out.

Also, you can make the F5 the default gateway for your servers.  That 
way, traffic hits the F5's VIP, gets forwarded to the server, the 
servers respond to the client, but use the F5 as the default gateway.  
This ensures traffic goes through the F5 on the way out.  The F5 uses 
its default gateway (your upstream router or firewall) and forwards the 
traffic onto the client.  The true source IP address of the client is 
preserved in this scenario (it is not in the SNAT scenario). 

Tony

sezen eren wrote:
> Hi all,
>
> I have an F5 installed in our system and I need to configure it.
>
> the servers behind F5 will be in same address range with the all 
> servers in the network, there will be no privite VLAN behind F5, 
> therefore I cannot implement NAT for the pool members, so I cannot 
> forward traffic to these hosts?
>
> Since there will be no private internal vlan, I guessI need to use 
> only external vlan and all traffic from outworld to F5 and from pool 
> members to F5 shall go to external vlan.
>
> one more thing F5 doesn't let me set a management IP in the range of 
> self IPs? I need to configure the management IP in same range becase I 
> have been given /25 IP range to use for everything traffic, management 
> bla bla :), how could I set this management IP within the self IPs range?
>
> I would appreciate if any of you can share configuration files of such 
> an structure?
>
> br
> //sezen
>
> ------------------------------------------------------------------------
>
> _______________________________________________
> lb-l mailing list
> [email protected]
> http://vegan.net/mailman/listinfo/lb-l
> Searchable Archive: http://vegan.net/lb/archive
> http://lbdigest.com Load Balancing Digest
> http://lbwiki.com Load Balancing Wiki
>   

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki

_______________________________________________
lb-l mailing list
[email protected]
http://vegan.net/mailman/listinfo/lb-l
Searchable Archive: http://vegan.net/lb/archive
http://lbdigest.com Load Balancing Digest
http://lbwiki.com Load Balancing Wiki
smime.p7s (application/x-pkcs7-signature, 3 KB) - not displayed