Forum Discussion

Christian_Manue's avatar
Christian_Manue
Icon for Nimbostratus rankNimbostratus
Apr 29, 2019

VIP forwarding with only F5 BIG ASM

Hello Community, In my client, we have a virtual edition of a F5 BIG ASM (without LTM) and we need to F5 route the nodes request to other networks. The nodes have a F5 as default gateway but, when they try to go out, the comunication dont pass the F5. My question is F5 with only F5 BIG ASM (without LTM) have the posibilty to have a VIP forwarding? With other appliance with LTM dont have these problem, these is the first time that i see these behavior.

 

The Hypervisor is Huawei Open Cloud and we use the KVM iso.

 

Thanks

 

Christian García

 

1 Reply

  • Hi

     

    you do not need to have LTM for FW traffic.

     

    You confirm the following point:

     

    • Create a wildcard VS 0.0.0.0:* (L4)
    • uncheck "Address Translation" and "Port Translation"
    • In your pool you have to set a node that will be the GW of F5 (1.2.3.4:*)
    • Don't forget to set snat automap

    Using TCPDUMP check that client request reach F5 on self IP (or floating IP if you have a cluster):

     

    tcpdump -nni 0.0 host client-ip and host self/floatingIP

     

    Regards