Re: Client IP behind Load Balancer

From: Cédric Dardenne (cedric.nospam_dardenne_at_accenture.com)
Date: 11/15/04


Date: Mon, 15 Nov 2004 20:29:16 +0100

Hi again,

It seems that there is a firewall between our servers and the F5 BigIP and
for this reason, request had to be NATed.
So we will try to move servers into the same DMZ as the F5, and then your
configuration should work: no NAT and Bip-IP as default gateway.

Thanks,

Cédric

-- 
Programming today is a race between software engineers
striving to build bigger and better idiot-proof programs,
and the Universe trying to produce bigger and better idiots.
So far, the Universe is winning.
-- Rich Cook
Cédric Dardenne wrote:
> Hi Seth,
>
> Thanks for your answer.
> Unfortunately, I don't have access to F5 configuration or F5 itself...
> this is our hoster's one (and I have to admit I don't know a lot about
> it...).
>
> If requests are done through the public IP, then they go through the load
> balancer, and I only see the virtual private IP in the logs. If I make a
> request on the internal network directly to the real server's IP, then in
> the logs I see my real client IP, as I don't pass through the load
> balancer...
>
> Would it be possible for you to describe me your configuration, or to send
> me your config file? This would allow me to advise my hoster...
>
> I have been trying to read F5 documentation (:-S...), and saw the nPath
> routing configuration. Is this the one you are using? My hoster said that
> this would not be allowed by their firewall as the anwser doesn't come
> from the same host it was sent to... (is it true?)
>
> Thanks for your advises,
>
> Cedric
>
>
> srock wrote:
>> Hi,
>>
>> I have F5's in place and the client IP's are preserved in the logs as
>> expected. I have a few questions:
>>
>> 1. Are ALL of the requests in your logs coming from the bigip?
>> 2. Is the default gateway on your web servers set to the big IP?
>> 3. Can you post the contents of your bigip.conf file?
>> 4. Can you post the results of: b global show
>>
>> thanks,
>>
>> Seth
>>
>>
>>
>> "Cédric Dardenne" <cedric.nospam_dardenne@accenture.com> wrote in message
>> news:%23STJGDZyEHA.2212@TK2MSFTNGP15.phx.gbl...
>>> Hi all,
>>>
>>> We have a website running under II5 (W2k SP4). To analyze logs, we use
>>> WebTrends Pro. However our servers are behind a physical load balancer
>>> (F5). Thus, in IIS logs, we now only see the load balancer's virtual IP
>>> address instead of the real client IP...
>>>
>>> I guess I might not be the first facing this issue... Would you have any
>>> solution?
>>>
>>> Thanks a lot,
>>>
>>> Cedric
>>>
>>> --
>>> Programming today is a race between software engineers
>>> striving to build bigger and better idiot-proof programs,
>>> and the Universe trying to produce bigger and better idiots.
>>> So far, the Universe is winning.
>>> -- Rich Cook


Relevant Pages

  • Re: Balance load
    ... webserversand I would like to sent user's request to ... one of the three server depending on a load on the server. ... will in the long run see to a quite even load on the servers. ...
    (alt.os.linux)
  • Re: profile issues.
    ... I've run into this issue when an application cannot/does not close correctly and when windows tries to load the profile it cannot load, so it loads this temp profile. ... Look in the event logs and see what event id there are when the user logs in and this will help us troubleshoot it. ... 2000 servers but they are application servers. ...
    (microsoft.public.windows.server.active_directory)
  • Re: FTP Client With File Encryption For Remote Backup?
    ... POST or GET request to port 80 to a web site under the authors ... glancing at logs wouldn't ... from publishing its source code, and why PGP was so stalwart in the ... I especially liked the bit where he had the source code ...
    (alt.computer.security)
  • Re: Bad news about Tor
    ... A "privacy service" would be ideal. ... Attack truly anonymous methods like Tor even though it ... keeps logs and lies about it, but got caught using them to track people ... Servers in the US are a lot safer that servers in most other places, ...
    (alt.privacy)
  • RE: Upgrading W2K3 Server to MSXML SP2
    ... "Trent USTA" wrote: ... > between the IIS request to SQL and the response back to IIS. ... > I've been tasked with upgrading the web servers to SP2. ...
    (microsoft.public.inetserver.asp.db)