Forum Discussion

dbowles65_19789's avatar
dbowles65_19789
Icon for Altostratus rankAltostratus
Mar 18, 2016
Solved

My first iRule

Hi, I'm hoping, and pretty sure this is a simple one, but I am not sure exactly how to accomplish the following: Our customer wants their real servers/nodes to be able to reach their own VIP and get load balanced. The nodes are in routed mode pointing to the F5 as their gateway in the ‘internal’ VLAN and the virtual servers live in the external VLAN. The gateway for the F5 is a Cisco firewall DMZ interface (same VLAN as external). The firewall will allow this hair pin connection but the traffic is not even reaching the firewall, I suspect because the forwarding virtual server is not forwarding traffic that is destined to itself. I researched DevCentral and found an iRule to use SNAT/Automap when the client and server are on the same VLAN but in this case the client and server are not on the same VLAN so I’m not convinced this will work. Also, I’ve never successfully created an iRule so I’m reaching out for any guidance. Is there a checkbox I can check or a simple iRule I can create to allow just these nodes in routed mode to hit the virtual server they load balance for? All other traffic sourcing from outside the F5 works fine.

 

Thanks,

 

4 Replies