Forum Discussion

Mike_Sullivan_2's avatar
Mike_Sullivan_2
Icon for Nimbostratus rankNimbostratus
Dec 15, 2009

Multiple 'Default' Gateways?

 

Greetings DevCentral!

 

 

I have a new Firewall cluster that I would like to phase into production. My LTM hangs off one of old cluster interface pairs (clustered like HSRP clusters but not HSRP) and everyone is happy. I have a new set with it's own cluster pair of IPs in the same vlan, it's just that the production LTM's don't use it.

 

 

I'd like to be able to selectively swing services through the new cluster but I'm not sure how I would implement it. There is a wildcard forwarding VS that takes care of all the services currently configured.

 

 

My thought was to create new default forwarding virtual servers and tune the mask to pair up with each host that would use it, but that obviously would be tedious at best.

 

 

Maybe an iRule? I'm not sure how that would be done. I can certainly nat from the new cluster, but I like our web folks to see the source IP.

 

 

Version 9.4.6.

 

 

Thanks for your insights,

 

Mike

3 Replies

  • Hi Mike,

     

     

    How many services (ip:port combos) are you eventually going to move to the LTM's? If you'd like the option to configure specific load balancing/persistence/protocol handling per service, it would be ideal to configure individual VIPs for each service. If you have a lot of services that you'd like to handle in a single VIP, then a network VIP would be more ideal.

     

     

    Can you provide more detail on what you're trying to migrate? Could you also provide a simplified network diagram with sample IP addresses?

     

     

    Thanks,

     

    Aaron
  • Hi Aaron,

     

     

    Thanks for your reply. I included a diagram, it should clarify just what I'm doing. In the interest of brevity, I left out the Link Controllers (where I'll created new pools) and how I planned to control the flow. This should clear it up.

     

     

    Thanks for looking.

     

     

    Mike

     

     

    PS There is a misspelled word 'engress' should be ingress.
  •  

     

    Well, good old auto lasthop totally takes care of this in my situation. It's a non-issue.

     

     

    Thanks for looking.

     

     

    Cheers,

     

    Mike