Forum Discussion

Josh_41258's avatar
Josh_41258
Icon for Nimbostratus rankNimbostratus
Sep 05, 2013

Routed VS SNAT Deployment

Typically, we always use SNAT in our environment. I have a scenario now where I need to retain source IPs from clients thus disabling SNAT.

 

Here is what I have configured thus far:

 

1) Created a new VS with a type of "Forwarding IP," a destination network of 0.0.0.0, and a mask of 0.0.0.0. The VS is bound to all ports. It also has a fastL4 profile assigned to it, and is bound to all VLANs and all protocols.

 

2) Defined a default route on the BIG-IP to a gateway that can reach all of our internal applicable networks.

 

3) Configured the server's default gateway as the floating self-IP on the corresponding VLAN.

 

From the server, I can reach all external networks. However, I can not access the server FROM a remote network. I can however ping it, but all TCP connections fail (SSH, etc).

 

What configuration am I missing here? My goal is to be able to access the server (which has the LTM defined as it's gateway) from any network via it's assigned IP address and not a VS.

 

Is this possible?

 

Thanks for any help!

 

18 Replies