Forum Discussion

AceDawg1's avatar
AceDawg1
Icon for Nimbostratus rankNimbostratus
Aug 17, 2017

Question on Routing when F5 is Default Gateway

I have a setup where the F5 serves as default gateway for 25 VLANs on the DMZ. The F5s default gateway is a Palo Alto 5000. The Palo has a route to 10.10.0.0/24 via 10.1.0.2 and is redistributing that route via OSPF. The F5 has a IP-forwarding virtual server configured.

 

PA (10.1.0.1/28) <--VLAN 1--> (10.1.0.2/28) F5 (10.10.0.1/24) <--VLAN 10--> Server (10.10.0.100/24)

 

Here's my conundrum:

 

  1. Pings from the PA to 10.1.0.2: successful
  2. Pings from the PA to 10.10.0.1: unsuccessful
  3. Pings from the PA to 10.10.0.100: successful
  4. Pings from the F5 (VLAN 10) to 10.1.0.1: unsuccessful
  5. Pings from the Server to 10.1.0.1: successful

All in all, the setup works but if I try to ping or traceroute from interface VLAN 10 on the F5 to anything left of the F5, I receive "Destination Host Unreachable".

 

Any ideas?

 

1 Reply

  • Hi,

     

    For security reasons, F5 does not allow packet to self IP from another VLAN than defined in Self.

     

    As F5 does not filter self IP sources in port lockdown, filter is only done on VLAN.