Forum Discussion

Blackl3g_58846's avatar
Blackl3g_58846
Icon for Nimbostratus rankNimbostratus
Jun 02, 2015

Virtual GTM Health Monitors through Cisco ASA to public IP address

Hi guys,

 

I have a proof of concept lab set-up where I have two stand-alone Virtual GTM/LTM's and my aim is to load-balance using the GTM's (active/active) to a LTM Virtual server.

 

On the back the back-end I have three VM's listening on port 80 and a Virtual server set up to hit the pool using round-robin and that all works fine as expected.

 

I have also provisioned the GTM modules on the same VE's and have configured two Data Centres each with the GTM servers configured along will all the necessary Virtual servers/Pools using the same public IP address on each GTM. All the DNS configuration has been set up so when I hit a URL it sends the DNS query to the GTM's which are NAT'd through a Cisco ASA and the GTM's respond back with the correct public IP address of the website which is also NAT'd through the Cisco ASA to the LTM Virtual server.

 

The problem that I have is that the GTM's can't use the gateway ICMP monitor or a HTTP monitor from behind the Cisco ASA (inside) to the Public IP Address on the (Outside) the is by design. So the million dollar question is how can I monitor the pool members on the Public IP address?

 

Also should this work without the monitors in place as I seem to hit the Virtual server using the public DNS?

 

Thanks in advance

 

Matt

 

2 Replies

  • So the GTM/LTM is located on the outside of the ASA and the pool members on the inside of the ASA. May I ask when you can't monitor through the ASA?

     

    You could NAT the health monitor requests on the ASA so memberPublicIP > ASA-NAT > MemberPrivateIP Or if this is a Lab - how about having another VE on the inside of the ASA then use iQuery between the GTM on the outside and the inside LTM. This would be encrypted so may elevate any security concerns

     

  • Hi not the case, the GTM/LTM is behind the ASA but the IP that the GTM is trying to monitor is an Outside Public IP address of the ASA. This Public IP address of the ASA is the NAT'd address that a client would use from the internet to access the web service through the LTM.

     

    Because by design you can't ping ab Cisco ASA outside interface address from the Inside interface address, how can I configure the GTM to Monitor the GTM Virtual server on the public address?