ibm-datapower

Datapower outbound ethernet interface


I am facing a problem with IBM Datapower XG45.7.0.0.0.

When I am connecting to an external service using DP, the source IP of DP is being picked up randomly among the 3 available eth interfaces. I know this has performance and stability benefits. However, this is causing great deal of pain in the firewall config. As a tactical solution, is there a way to ensure that the traffic is send from any one fixed eth interface?


Solution

  • Sure, normally you should make sure only one NIC has a default gateway (and that would in most cases be the NIC facing the Internet). The two other NIC's should only have static routes and set for the various subnets they should serve.

    If you don't have a need for different IP addresses for outbound (egress) traffic you might want to use only one NIC and set two additional Secondary IP addresses instead. That way you have three working IP address for ingress (inbound) traffic but only one IP will be used for egress.