cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
350
Views
0
Helpful
1
Replies

Insert Client IP address to packet?

tevfik
Level 1
Level 1

Hi,

In our infrastructure, we had to hide the client ip address, to ensure the response traffic comes back to the CSS 11503 LB due to the network deployment. However we need to know which client ip address is orginating the request. Is there a way to have the CSS 11503 LB insert the client ip address to the packet? I think this might be possible for HTTP as a client-ip header, but there are non-HTTP appliciatons that need this.

Thanks

1 Reply 1

Gilles Dufour
Cisco Employee
Cisco Employee

this is the well-known drawback of using client nat.

If you need to know the original client ip for statistics, you should try to collect the stats before the CSS.

Otherwise, you will have to avoid client-nat and use policy routing in your network to guarantee that the response goes back to the CSS.

There is no way to insert the client-ip info in a non-HTTP protocol.

Moreover, the CSS can only insert the ip address in HTTPS requests and only if you have the SSL module.

A solution that may looks very easy [like client-nat] may sometimes come with important drawbacks [no info about original client ip].

Gilles.