Forum Discussion
jenmick1_43986
Nimbostratus
Apr 29, 2011Dual Firewalled Enviroments - 1 LB
Hello. We are looking for assistance with a simple way to route & load balance traffic in a setup that we haven't configured before. We have two separate firewalls for the environments behind our LTM/...
Michael_Yates
Nimbostratus
Apr 29, 2011Hi jenmick1,
Q: We are attempting to load balance traffic sourcing from two separate firewalls and need to ensure that traffic is sent back through the proper firewall.
A: Shouldn’t the rest of your network configuration (non-BigIP) be taking care of your network routes and routing table for you? If the BigIP does not know the route it should utilize its default route.
Q: SNAT cannot be used in these environments as the developers need to see true source IPs.
A: Can you configure X-Forward in the HTTP Profile so that the True Client IP Address is placed in the header and the downstream application can retrieve it?
Q: The servers need to be able to connect to the correct firewall when they are the source.
A: If your servers are the source then they become a client and are passed through the BigIP if the traffic destination is not on a subnet that is owned by the BigIP. The traffic from the server should be allowed to pass through unaffected, but other devices might cause this not to work (firewall configurations).
I can't offer any insight into your Route Domain issue, perhaps on someone else can give you some suggestions.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects