Forum Discussion

Nagu_82025's avatar
Nagu_82025
Icon for Nimbostratus rankNimbostratus
Jan 30, 2019

Load balancing ipsec passthrough traffic

Hello I seen some questions regarding load balancing ipsec traffic through F5 LTM. The answer that were provided said it should work. The suggestion is to use a forwarding VS on the LTM. With forwarding VS can load balancing be done as well? Tried to configure a forwarding VS but no option to define a pool of resources. In our case we have

 

VPN clients ------internet------>Our firewall-----> F5 HA LTM -----------> two windows 2012 ipsec RAS server. should this be possible or would it only work with one 2012 ipsec RAS server? If so what sort of LTM VS should be setup and does it also need a forwarding VS with SNAT for return traffic?

 

1 Reply

  • Forwarding Virtual Servers are designed to implement routing solutions through the F5. This is why it does not allow pools. The minimum configuration for a VS that allows load balancing would be a Performance L4 VS. This allows all TCP traffic to be load balanced but can be configured to simply pass through all the data and not parse it.

     

    If you configure a performance L4 VS with a fastL4 profile and the HTTP profile set to None, I believe your issue will be solved.

     

    If you have any more questions, I am sure I can help.