Forum Discussion

BB1030_11211's avatar
BB1030_11211
Icon for Nimbostratus rankNimbostratus
May 23, 2013

Configuration requirements to ping internal vlan servers

Hi, I have an LTM configured in 2-arm routed mode, I need to be able to reach the real IP of the servers in the internal VLAN from the external networks, I already added routes in both the LTM and network switch/router, is there anything else neede to be able reach the real IP of the servers directly for troubleshooting purposes etc.? I appreciate it

 

5 Replies

  • have you had ip forwarding virtual server?

     

     

    sol7595: Overview of IP forwarding virtual servers

     

    http://support.f5.com/kb/en-us/solutions/public/7000/500/sol7595.html
  • Nitass, thanks for your response, I haven't done IP forwarding, does this mean that by default the LTM does not allow traffic to the internal VLAN real IPs of the servers?
  • does this mean that by default the LTM does not allow traffic to the internal VLAN real IPs of the servers?bigip is default-deny device. to allow traffic from one vlan to another, at least object listener has to be configured i.e. virtual server, snat, nat.
  • Thanks again, sorry one more question, how do I accomplish this with a snat/nat? I'm trying to avoid creating additional Virtual servers.
  • how do I accomplish this with a snat/nat? I'm trying to avoid creating additional Virtual servers.snat is source listner object. you may create snat list on external vlan, set origin to all ip address and translation to automap, snatpool or any ip address you want.

     

     

    sol9038: The order of precedence for local traffic object listeners

     

    http://support.f5.com/kb/en-us/solutions/public/9000/000/sol9038.html

     

     

    please be noted that snat list also apply to virtual server traffic which snat setting (under virtual server configuration) is set to none.