Courseiva

F5-CTS-LTM BIG-IP Local Traffic Manager Practice Question

Exhibit

ltm virtual vs_app { destination 10.0.0.5:80 pool pool_app profiles { http { insert-xforwarded-for enabled } } }

Refer to the exhibit. The web server logs show the source IP is the BIG-IP Self IP. Why is this happening despite the X-Forwarded-For configuration?

⚠ Common exam trap

Candidates often assume that 'Insert X-Forwarded-For' automatically hides the SNAT IP, failing to realize that the header and the source IP translation are two completely independent BIG-IP configuration settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SNAT is enabled on the virtual server, causing source translation.

The 'Insert X-Forwarded-For' setting only adds an HTTP header; it does not change the source IP address of the TCP packet. If the backend server sees the BIG-IP Self IP, it is because SNAT (Secure Network Address Translation) is active and is translating the client's source IP to the BIG-IP's address. The X-Forwarded-For header is present, but the server must be configured to read it.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The HTTP profile is misconfigured and needs an iRule to function.

    Why it's wrong here

    The HTTP profile configuration is correct for X-Forwarded-For insertion. No iRule is required to perform this function, as the native profile feature is optimized for this exact task. The issue lies within the backend server's log configuration, not an iRule, which would only add unnecessary processing overhead.

  • ✓

    SNAT is enabled on the virtual server, causing source translation.

    Why this is correct

    SNAT overrides the original client source IP with the BIG-IP's address at the network layer. Even with an X-Forwarded-For header present, the network-level source IP seen by the web server will be the BIG-IP's IP unless SNAT is disabled or the backend server is configured for XFF.

  • ✗

    The virtual server is missing a Client SSL profile.

    Why it's wrong here

    A Client SSL profile is for decrypting SSL traffic. It has no impact on the source IP translation behavior. If the traffic is plain HTTP on port 80 as shown in the exhibit, the presence or absence of a Client SSL profile is irrelevant to the reported source IP issue.

  • ✗

    The pool members are in a different subnet than the virtual server.

    Why it's wrong here

    Subnet placement does not force SNAT or determine the visibility of the source IP. The BIG-IP handles routing regardless of the subnet configuration. The source IP visibility is purely a function of whether SNAT is enabled or if the backend server's default gateway is the BIG-IP.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

About these practice questions

One of 119 original F5-CTS-LTM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official F5 exam blueprint

This F5-CTS-LTM practice question is part of Courseiva's free F5 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the F5-CTS-LTM exam.