Forum Discussion

Souravpcs_14061's avatar
Souravpcs_14061
Icon for Nimbostratus rankNimbostratus
Mar 13, 2014

SNAT Issue

Hi Guys,

 

I have an issue in translating the Client Source address to internal node IP Subnet in the F5. Could you please provide some clear idea on how snat works.

 

Regards

 

3 Replies

  • There are multiple ways of translating IP's. If all you want is to translate incoming client source IP's on a particular virtual server I'd recommend using a SNAT pool.

     

    To use a SNAT pool on a virtual server:

     

    1. Go to the virtual server config page.
    2. Change Source Address Translation from "None" to automap, or a custom SNAT Pool that you've create yourself.

    Note that if you create a SNAT pool yourself it should contain at least one IP in the subnet facing the member servers.

     

    /Patrik

     

  • Hi!

     

    Try enabling SNAT automap first and see if that works.

     

    I have never setup load balancing for Lync myself but I've heard that it can be a bit tricky. Some Microsoft services are using kerberos SSO as authentication and then they might not accept that you NAT the incoming packets unless you have allowed the server to authenticate sessions for users (something like a proxy). I believe you have to configure an "SPN record" in the domain controller in that case.

     

    /Patrik

     

  • Have you tried iApps?

     

    Here's one for Lync 2010 and 2013: https://devcentral.f5.com/wiki/iapp.Microsoft-Lync-Server-2010-Updated-iApp.ashx

     

    /Patrik