LTM Design - BIGIP on a Stick
Hi,
We are having some weird routing issues I'm hoping you all can help with our design.
We have two F5's (5000) in a redundant pair. Each of the F5's has one internal and one external link connecting to our CORE switches as a trunk.
We wanted to put local VLANs on the F5. We created one for external [VIPs] and two internal [WEB & APP]. The two internal VLANs are assigned to one trunk, the external VIP vlan assigned to the other. We created self and floating IPs for each VLAN.
We assigned the server IPs with their gateway as the floating IP. But we were unable to reach them.
We found this article: http://packetpushers.net/stateless-routing-f5-ltm/ and created a virtual forwarding server as they discuss. This allowed us to reach the servers and ping floating IPs.
Odd issue was, the servers could ping other networks. But all the applications on the servers were failing because they couldn't connect to any servers on TCP ports. I thought this was related to the selfIPs port lockdown and I went ahead and allowed all but no changes.
We had a static route on our core switch pointing at the F5 external floating IP. The traffic was getting to the F5 we saw in the TCPdump but we couldn't reach anything.
Ultimately, we had to create SVIs on our CORE switches for the servers to connect to other networks with more than ping connectivity. Weird thing is now I cant ping self IPs. And I feel the SVIs should not be needed in this design.
I hope I explained this well...and help be greatly appreciated.