Forum Discussion

amine31_382319's avatar
amine31_382319
Icon for Nimbostratus rankNimbostratus
Jan 28, 2019

address MAC

two F5 connected with palo alto,the address of F5 active is X.Y.5.2 and the Standby f5 is X.Y.5.3 and the floating adresse is X.Y.5.1. when i do wireshark i have this information:

 

in the receive phase capture on FW DNS query i have: Ethernet II, Src: F5 network_(x:y:z:46:a6:04) Dst:palo alto_ (x:y:z:00:0d:30) Internet protocole version4, Src: X.Y.5.3, Dst:X.Y.194.21

 

in the transmit phase capture on FW -DNS query response: Ethernet II, Src: Dst:palo alto_ (x:y:z:00:0d:30) Dst:F5 network_(x:y:z:46:a5:84) Internet protocole version 4, Src:X.Y.194.21, Dst:X.Y.5.3,

 

the probleme is in src F5 and the dst F5 haven't the same adresse MAC??

 

6 Replies

  • Hello amine31!

     

    Can you attach the capture or post a screenshot of it?

     

    You could have MAC Masquerade enabled too...

     

    Cheers! Rafael

     

  • Hello amine31!

     

    I'm sorry, but it seems to me that you're looking at two different flows. On the upper part of the capture, I can see that frame 34 is the query and just below it, on frame 35 is the response to that same query.

     

    On the other part, you're showing frame 11 and it's response is right below on frame 12.

     

    Is this correct?

     

    Cheers! Rafael

     

  • hi rafabln

     

    the first is receive phase capture on FW DNS QUERY AND THE SECOND IS TRANSMIT PHASE IS NOT THE SAME, NORMALY THE FLOW pass by THE SAME EQUIPEMENT ACTIVE f5 who have @mac 05:84 but when he receive pass through F5 standby who has @ mac a6:04

     

  • Sorry amine31. I'm having a hard time understanding what you're trying to explain.

     

    Is this a virtual server? A GTM listener? Can you share the configuration of the VS or listener?

     

    Cheers! Rafael

     

  • Hi amine31,

     

    It was two different flows , Transmit UDP dst port 46704 and recieve UDP src port 59086 . it should be same .