Forum Discussion

xMadi's avatar
xMadi
Icon for Nimbostratus rankNimbostratus
Mar 14, 2017

Issue with direct connections to server behind F5

Hello all,

 

We are having some weird issues with some of our servers and maybe someone else had the same issue. The way we have setup is following:

 

Firewall ----- DMZ external vlan --- F5 --- DMZ internal vlan ---- Server

 

So the server is having a default gateway pointing to F5 and F5 has wildcard virtual server for any request coming in on internal vlan to point to IP on the Firewall. The one strange thing is that the Firewall has also interface in the DMZ internal vlan with IP so when requests coming in directly to server they are bypassing the F5 but going back they are going through F5. So there is assymetric routing when connecting directly to server - the wildcard virtual server has the TCP profile to enable assymetric flow.

 

So the issue is. We are having the F5 as a Virtual Edition on one of our ESXi hosts. When the server (node) is on the same host (same ESXi) - direct connections to server are really slow, pages are loading for 5 minutes+. However when we connect to virtual server which has a pool with this server on it, the speed is much better, the page loads within 10-15 seconds. This all goes away when we move the server to a different host in the network.

 

Does anyone have any ideas why this could happen ?

 

Thanks