Forum Discussion

DanielPlasencia's avatar
DanielPlasencia
Icon for Altostratus rankAltostratus
Apr 06, 2020

SIP TCP 5061 packets dropped by IP Forwarding Virtual Server

Hello

 

 

I have a HA F5 LTM Solution running v14.1.2.3

 

I have an internal vlan (192.168.10.8 as Floating IP) and external vlan (192.168.13.5 as Floating IP)

 

I also have an IP Forwarding Virtual Server that allows all 192.168.10.x servers to send packets through the F5 without making any NAT configuration. So servers in 192.168.10.0/24 network can send all protocol packets through the f5 to reach external networks. For example, 192.168.10.50 server sends a packet to 10.16.75.50 server. First, it reaches 192.168.10.8 (F5 internal vlan), then the packet is sent to a firewall (192.168.13.2 which is in the same vlan as external vlan in f5), then the firewall reaches 10.16.75.50 by static route or because it is one of its local networks.

 

The problem comes when this packets are from SIP protocol (TCP 5061 SIP REGISTER), I see that the f5 drops this packets even though the IP Forwarding Virtual Server should allow them because it allows TCP packets and all ports are permitted. Do I need to create something different from my IP Forwarding virtual server? ps: When I run tcpdump in F5, I see SIP traffic coming to internal vlan interface but nothing egresses by the external vlan interface