Forum Discussion

John_380411's avatar
John_380411
Icon for Nimbostratus rankNimbostratus
Feb 25, 2019

APM SSL VPN - Internet Access Issue

We currently have an F5 configured using the APM/LTM with an SSL VPN for corporate users.

 

To get internet access, the users currently use a proxy which is defined in the network access profile, split-tunneling isn't used and is not an option. We want to move away from the proxy and use a FW with URL filtering for internet access. However, the users also have VOIP software for phone calls so there is no SNAT on the NA profile. Removing the proxy configuration breaks the internet access as the source IP is the internal DMZ range which is blocked on the DMZ FW. There is a default gateway on the F5 for external networks via the DMZ FW, however as it is not Natted it gets blocked.

 

Is there any way to get the source IP natted for internet access via the external interface on the F5?

 

1 Reply

  • Hi John

     

    Have you tried using forwarding layered vips for this?

     

    I guess it depends on whether you can make the different destination determinations as to whether this could work