Forum Discussion

adambaack_13393's avatar
adambaack_13393
Icon for Nimbostratus rankNimbostratus
Apr 22, 2015

External/Internal Exchange VIPs with different VLANs.

Trying to figure out how to do this. I've done basic F5 Exchange iApps but only where everything was on the same subnet and no VLANs to mess around with. Have a F5 I've taken over and they want Exchange load balanced internally and externally. It's connected via a trunk to the network and has all of the VLANs listed under Network\VLANs. Under Network\Self IPs\ there is just one Floating Self IP on VLAN 34 with the appropriate subnet.

 

So what they're wanting for the external users: Internet>Firewall DMZ>F5 DMZ VIP>Internal LAN>Exchange CAS

 

Internal users: User LAN>F5 Internal VIP>Exchange CAS

 

F5 DMZ IP: 10.10.10.4 F5 DMZ Subnet/VLAN: 10.10.10.0 / VLAN 10

 

F5 Internal IP: 10.10.34.4 F5 Internal Subnet/VLAN: 10.10.34.0 / VLAN 34

 

Exchange CAS are both on 10.10.34.10 & 10.10.34.11

 

I've installed the 1.5 Exchange 2013 iApp and it seems to work internally but externally it is not working. Assuming the firewall rules are setup correctly am I missing something? I have an idea that it's something with the VLANs but don't know how to fix it.

 

Also, under Network\Routes it's blank.. not sure if I need anything there. For the iApps I chose mainly all the defaults. Nothing fancy. For the External iApp I said the servers were on different subnets and Internal iApp I said that the servers were on the same subnet.

 

Thanks.

 

1 Reply

  • If you look at the stats for the DMZ VIP, are you seeing traffic hitting it? If so, are you seeing return traffic...?

     

    If you are not then you have a routing problem north of the F5 and so you can start troubleshooting their, if you are seeing traffic hitting the VIP, can you follow the traffic to the application pools. Do you see return traffic from the app servers?

     

    A combination of LTM on box Statstics and TCPDumps will probably point you in the right direction.