Module 2 - Processing Traffic - Vfinal
Module 2 - Processing Traffic - Vfinal
© F5 Networks, Inc.
3
Nodes
Represented by an IP address
© F5 Networks, Inc.
4
Pool Members
Represented by an
IP address and a port
172.20.10.1 172.20.10.2 172.20.10.3 172.20.10.4
Pools
Virtual Servers
Represented by an
IP address and a port
Listener
10.2.2.100:80 10.2.2.100:443
HTTPS: 443
BIG-IP LTM is a
default deny device
© F5 Networks, Inc.
8
18.200.150.10 http://www.f5.com
10.2.2.100:80 10.2.2.100:443
Request packet
Source IP: 18.200.150.10:4003
Member: 172.20.10.1:80
Destination IP: 172.20.10.1:80
18.200.150.10
Request packet #2
Source IP: 18.200.150.10:4003
Destination IP: 10.2.2.100:80
10.2.2.100:80 10.2.2.100:443
Request packet #2
Source IP: 18.200.150.10:4003
Member: 172.20.10.2:80
Destination IP: 172.20.10.2:80
18.200.150.10
10.2.2.100:80 10.2.2.100:443
Request packet #3
Source IP: 18.200.150.10:4003
Member: 172.20.10.4:80
Destination IP: 172.20.10.4:80
Port Translation
18.200.150.10
Request packet
Source IP: 18.200.150.10:4003
Destination IP: 10.2.2.100:80
10.2.2.100:80 10.2.2.100:443
Request packet
Source IP: 18.200.150.10:4003
Member: 172.20.10.3:8080
Destination IP: 172.20.10.3:8080
18.200.150.10
Request packet
Source IP: 18.200.150.10:4003 Response packet
Destination IP: 10.2.2.100:80 Source IP: 10.2.2.100:80
Destination IP: 18.200.150.10:4003
10.2.2.100:80 10.2.2.100:443
Response packet
Source IP: 172.20.10.1:80
Destination IP: 18.200.150.10:4003
18.200.150.10
If BIG-IP LTM changes an IP address,
the response must return through BIG-IP LTM
Request packet Response packet
Source IP: 18.200.150.10:4003 Source IP: 172.20.10.1:80
Destination IP: 10.2.2.100:80 Destination IP: 18.200.150.10:4003
10.2.2.100:80 10.2.2.100:443
Request packet
Source IP: 18.200.150.10:4003 172.20.10.240
172.20.10.241
Destination IP: 172.20.10.1:80
Solution #1: Response packet
Configure the default gateway or Source IP: 172.20.10.1:80
static routing on every pool member Destination IP: 18.200.150.10:4003
DG: 172.20.10.241
Solution #2:
172.20.10.1 172.20.10.2
Use 172.20.10.3
Secure Network Address 172.20.10.4
Translation (SNAT)
172.20.10.1:80 172.20.10.2:80 172.20.10.3:8080 172.20.10.4:80
172.20.10.2:443 172.20.10.3:443 172.20.10.4:443
© F5 Networks, Inc.
14
18.200.150.10
10.2.2.100:80 10.2.2.100:443
172.20.10.240
172.20.10.241
DG: 172.20.10.240
172.20.10.241
Using SNAT
18.200.150.10
Use SNAT when modifying the
Module: NATs and SNATs pool members is not an option
10.2.2.100:80 10.2.2.100:443
Request packet
Source IP: 172.20.10.240:80 Self IP: 172.20.10.240
172.20.10.241
Destination IP: 172.20.10.2:80 Member: 172.20.10.2:80
Broadcast for 172.20.10.240
Response packet
Source IP: 172.20.10.2:80
Destination IP: 172.20.10.240:80
DG: 172.20.10.241
18.200.150.10
10.2.2.100:80 10.2.2.100:443
TMOS:
Traffic Management Operating System
© F5 Networks, Inc.
17
© F5 Networks, Inc.
18
© F5 Networks, Inc.
19
Configuring a Pool
© F5 Networks, Inc.
20
© F5 Networks, Inc.
21
Resources section
© F5 Networks, Inc.
22
© F5 Networks, Inc.
23
© F5 Networks, Inc.
24
Statistics
© F5 Networks, Inc.
25
Logging
© F5 Networks, Inc.
26
Module Review
© F5 Networks, Inc.
27
© F5 Networks, Inc.
F5 Worldwide Field Enablement
Learn More, Sell More, Sell Faster