Forum Discussion
Fotios_30046
Nimbostratus
Sep 21, 2009Access Control Between VLANs On BigIP
We have a pair of 3400's in the following configuration:
-8 port trunk with 4 vlans
-vlan 1 is public connecting bigip to firewall
-vlan 2 is production web
-vlan 3 is development web
-vlan 4 is corporate web
-all servers use the bigip for default routing
-firewalls do not have interface inside web vlans
Is it possible to put access control between the web server vlans?
- hoolio
Cirrostratus
Hi, - Fotios_30046
Nimbostratus
Each web vlan has a wildcard virtual server setup. Does this null any security I want to put in place? - hoolio
Cirrostratus
Yep. Are there routers on each VLAN that you can specify in a pool? If so you could define them individually in pools and then change the forwarding VIPs to performance layer4 VIPs which reference the next hop router only for the allowed egress VLAN. Each ingress VLAN would only be able to route to the specific egress router. - Fotios_30046
Nimbostratus
Unfortunately, the bigip is the only router in the vlan. - hoolio
Cirrostratus
So which paths do you want to allow? - Fotios_30046
Nimbostratus
Vlan 1 sits between the bigip and the firewall. I have security here and control who can hit the web server vlans. I wanted to setup something up in between the web vlans. - hoolio
Cirrostratus
That's good, but the "internal" to internet connectivity was just one part of my last comment. Can you take a look at the rest and see if it might work for you? The general idea is that if you don't define one or more forwarding virtual servers, LTM won't route between the VLANs. - Fotios_30046
Nimbostratus
Sorry Aaron, I should have read your response slower. What you describe, internet to all three web, all three web to internet but no traffic between the web vlans is exactly what I would want. - Josh_41258
Nimbostratus
Aaron, - Josh_41258
Nimbostratus
OK, the thread that you linked answered my question (I think). I created a wildcard forwarding virtual bound to 0.0.0.0, and bound it to the specific internal VLAN.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects