done_23947
May 05, 2015Nimbostratus
iRule help w/ no snat for public DMZ
I've been using a irule for several yrs and believe it works as intended. I don't change or snat public DMZ networks (neiu_dmz_subnets). I need to add another DMZ public network (ATT_DMZ) that I don't want to snat (keep the system's public IP address). First matchclass "neiu_dmz_subnets" our current public DMZ's working but second matchclass "ATT_DMZ" not working, changing IP address. Why? should I just add a "snat none"?
} elseif { [matchclass [IP::client_addr] equals neiu_dmz_subnets]} {
Data Grp 66.99.13.0/24 forward pool ISP_routers member 64.107.163.129 } elseif { [matchclass [IP::client_addr] equals ATT_DMZ]} { Data Grp 12.239.13.193-255 forward pool ISP_routers member 12.239.13.129 } else { snat automap return }