Forum Discussion

Tamer_Ezzat_235's avatar
Tamer_Ezzat_235
Icon for Nimbostratus rankNimbostratus
Jan 10, 2018

Anti-Spam behind F5 LTm

Hi all,

 

I have a quick question please

 

Can I allow traffic from Anti-Spam node with all ports (inbound & outbound) through F5 LTM ?

 

Traffic flow as follow:-

 

Anti-Spam node > LTM > Firewall > Internet

 

Thanks in advnace

 

20 Replies

    • Tamer_Ezzat_235's avatar
      Tamer_Ezzat_235
      Icon for Nimbostratus rankNimbostratus

      Thanks Kolom

       

      However I need to allow the Anti-Spam node to initiate a connection to the internet on port 3888 is that option applicable ?

       

      what I understood from this link that forwarding Virtual server is based on the destination port on the internal node while what I am asking for is how can I allow connection from internal node to internet on destination ports like 3888, 9993 ect., ?

       

      Did you get my point

       

      Thanks

       

    • kolom's avatar
      kolom
      Icon for Altostratus rankAltostratus

      Hello , check "Emulating stateless IP routing with BIG-IP LTM forwarding virtual servers" part.

       

      You can configure a wildcard VS with all ports ,specific protocol ( TCP , UDP ) , and specifying a source address of your node .

       

      In this case , you'll be using F5 as Antispam's default GW.

       

    • Tamer_Ezzat_235's avatar
      Tamer_Ezzat_235
      Icon for Nimbostratus rankNimbostratus

      Hello,

       

      in my case F5 will not be as Antispam's default GW what is the solution in this case ? SNAT Automap ?

       

    • Tamer_Ezzat_235's avatar
      Tamer_Ezzat_235
      Icon for Nimbostratus rankNimbostratus

      Thanks Kolom

       

      However I need to allow the Anti-Spam node to initiate a connection to the internet on port 3888 is that option applicable ?

       

      what I understood from this link that forwarding Virtual server is based on the destination port on the internal node while what I am asking for is how can I allow connection from internal node to internet on destination ports like 3888, 9993 ect., ?

       

      Did you get my point

       

      Thanks

       

    • kolom_265617's avatar
      kolom_265617
      Icon for Cirrostratus rankCirrostratus

      Hello , check "Emulating stateless IP routing with BIG-IP LTM forwarding virtual servers" part.

       

      You can configure a wildcard VS with all ports ,specific protocol ( TCP , UDP ) , and specifying a source address of your node .

       

      In this case , you'll be using F5 as Antispam's default GW.

       

    • Tamer_Ezzat_235's avatar
      Tamer_Ezzat_235
      Icon for Nimbostratus rankNimbostratus

      Hello,

       

      in my case F5 will not be as Antispam's default GW what is the solution in this case ? SNAT Automap ?