Forum Discussion

Amit_Bhatnagar_'s avatar
Amit_Bhatnagar_
Icon for Nimbostratus rankNimbostratus
Aug 19, 2013
Solved

IPHTTPS with DirectAccess Not working with F5

I am helping a client implement DirectAccess 2012 using IPHTTPS as the Protocol. The setup is

 

ISP Firewall----Client Firewall------F5 (Big IP) ----DA Servers---Internal Network.

 

The ISP is doing 1-1 NAT for the Public IP Addresses to the Client’s Firewall to an internal range. Then the traffic is forwarded to the F5 and then DA. The setup works fine when using DA with a single Server configuration. I can connect and access internal resources but when I enable External Load Balancer with a standard SSL Forwarding to the DA, the setup never works. I am NOT terminating the SSL on F5.

 

The Servers are pointing to the internal IP of F5 as DG. Also, one thing that I am confused about is where to use the VIP which is created at the time of DA ELB Wizard. I have four Servers with 10.20.4.41, 42,43,44 and when I run the Load Balancing Wizard, it upgrades the 41 IP as VIP and I have to use 45 as the DIP but since F5 only requires the Self IP but no VIP. Where exactly do I use this IP which is on the same Network as the DA Server’s external Interface? I am using Performance L4 profile on the F5.

 

  • True Mac spoofing is not needed.

     

    I see two strange things. 1. Teredo interfaces are being enabled. Setup 2 interfaces behind edge device normally skips this step as Teredo only works with Public IPv4 addresses on the DA servers. 2. The pseudo network adapter is not getting an address assigned.

     

    What is the output of the powershell command "get-NetDnsTransitionConfiguration" ?

     

    Martijn

     

12 Replies