Forum Discussion

Paulastya_Aich_'s avatar
Paulastya_Aich_
Icon for Nimbostratus rankNimbostratus
Dec 02, 2016
Solved

Port translation not happening

We have configured a VIP to listen on port 443 and the associated pool members listening on port 7443.

 

Now when we are trying open the VIP IP from our browser we are getting Page cannot be displayed error.But we are able open the web page directly if we put the server IP with port 7443.

 

We have checked the routing and also enabled the Port and address translation option.

 

What could be issue.

 

  • Have you installed SSL certificate on Server Side? Yes. 1). Select Server side certificate as "serverssl-insecure-compatible"

     

    2). Select SNAT Automap 3). Capture TCPDUMP

     

    Please let me know if it is working

     

3 Replies

  • Did you also enable SNAT automap or SNAT pools? Have you supplied both the client- and serverssl profiles if you are planning to do SSL bridging? What does a tcpdump on the BIG-IP show?

     tcpdump -nni 0.0:nnn port 7443
    
  • Have you installed SSL certificate on Server Side? Yes. 1). Select Server side certificate as "serverssl-insecure-compatible"

     

    2). Select SNAT Automap 3). Capture TCPDUMP

     

    Please let me know if it is working

     

    • Paulastya_Aich_'s avatar
      Paulastya_Aich_
      Icon for Nimbostratus rankNimbostratus

      We are not using any ssl offloading in f5. snat is set to automap. In the tcpdump at F5, we are getting reset packet from the realservers after completeing the 3way handshaking. The reset is coming in response of fin/ack from the snat ip to the server.