Forum Discussion

Marcus_10406's avatar
Marcus_10406
Icon for Nimbostratus rankNimbostratus
Nov 02, 2016

SNAT traffic between Ingress interfaces

I noticed sth interesting on F5 LTM:

 

I'm using version 11.5.4, I have 2 VS VLANs configured on the LTM

 

10.1.1.0/24 (selfIP 10.1.1.254) 10.2.2.0/24 (selfIP 10.2.2.254)

 

also a server VLAN (egress) 192.168.10.1 (selfIP 192.168.10.254) default route configured as 0.0.0.0 0.0.0.0 --> 10.1.1.1 I created a VS with IP 10.2.2.10 with 2 servers in the pool: 10.125.10.10 and 10.125.10.11

 

so these 2 backend servers are not on any VLAN's directly configured on the LTM. Hence I have to do SNAT. then sth caught my eyes:

 

when I do auto map, the source IP will be NAT'ed to be egress interface selfIP 192.168.10.254 and then go out by default gateway to reach the backend server. then the TCP connection breaks.

 

I have to SNAT the VS to a specific IP on the VLAN 10.1.1.0/24, then the source IP will be SNAT to that IP and TCP session established.

 

so it seems to me the ingress interfaces cannot pass traffic to each other directly. Anyone has the same experience and insight on this too?