Forum Discussion

hung_105573's avatar
hung_105573
Icon for Nimbostratus rankNimbostratus
Jul 19, 2012

Problem NAT

Hi ALL

 

 

 

I'm facing problem the NAT on F5 ( LTM)

 

 

My network :

 

 

Server-----FW-------- ------Line internet2

 

F5(LTM) ------line internet 1

 

 

50(Users)------FW--------- ------line internet 3

 

 

 

- I haved config Virtual servers to publish some servers to internet

 

 

-Default GW Pool

 

- I have config to users to access the internet

 

 

LTM--Virtual servers:

 

 

-Destination:0.0.0.0/0.0.0.0

 

-Type: Performance Layer4

 

-Vlan : internal

 

-SNAT Pool:automap

 

 

 

But I have problem the users access to internet , it work some times (about 20 min) then so users can not access internet , it times at pc of users can not ping 8.8.8.8 , but on F5 then ping 8.8.8.8 ok and F5 can not NAT source users

 

 

so I guess on F5 have problem NAT

 

 

Could you PLS help me !

 

Many thanks

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

2 Replies

  • it work some times (about 20 min) then so users can not access internet , it times at pc of users can not ping 8.8.8.8 , but on F5 then ping 8.8.8.8 ok and F5 can not NAT source userswhen problem happens, can you try to run tcpdump on f5 to see what is going on?

     

     

    to screen

     

    tcpdump -nni 0.0 host 8.8.8.8 and icmp

     

     

    to file

     

    tcpdump -nni 0.0:nnn -s0 -w /var/tmp/output.pcap host 8.8.8.8 and icmp
  • Hi Hung,

     

    In you wildcard VS which is the performance layer 4 VS in the Advance config have you selected "for all traffic" instead of "tcp" or "udp" I think you still have it set to TCP or UDP. change it and it should start working perfectly fine. Also for the NAT its not going to work as per your expectations as you have the wild card server. You have to have some iRules and SNAT's & VS pair created to make it work.

     

    It is really strange but NAT the simplest thing in the network world works very differently with F5. They seriously have to look into it.

     

     

    Regards,