VS setup in AWS with public IP (EIP)
I've been following F5's official BIG-IP_Virtual_Edition_Setup_Guide_for_Amazon_EC2.pdf to stand up LTM VE instance in AWS. My setup is simple with 3 VPC subnets - Mgmt, Private, Public. Public subnet has default route to internet gateway specified. On F5 default gateway for external interface is the ip of internet gateway.
I have configured basic HTTP VIP in auto-map mode and have selected one of the internal IP's allocated to external interface ENI as VIP IP. My pool member is the server in private subnet. It all looks green and works internally in AWS.
I'd like my VIP to be accessible from the internet and I assigned EIP to external interface. When I am sending traffic to it, I can see it hits the VIP VS, but instead of being returned back to the client, is rejected after a long timeout - in the tcpdump below I can see countless SYN's:
124.169.XX.XX - is customer's IP
10.0.3.154 - is VIP self-ip
Can you please assist with what I am doing wrong here and why no reply is returned to a remote client?