For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

Fotios_30046's avatar
Fotios_30046
Icon for Nimbostratus rankNimbostratus
Sep 21, 2009

Access Control Between VLANs On BigIP

We have a pair of 3400's in the following configuration:

 

 

-8 port trunk with 4 vlans

 

-vlan 1 is public connecting bigip to firewall

 

-vlan 2 is production web

 

-vlan 3 is development web

 

-vlan 4 is corporate web

 

-all servers use the bigip for default routing

 

-firewalls do not have interface inside web vlans

 

 

Is it possible to put access control between the web server vlans?

11 Replies

  • hoolio's avatar
    hoolio
    Icon for Cirrostratus rankCirrostratus
    Hi Josh,

     

     

    If you create a forwarding virtual server, LTM will use the routing table to handle the request. If you add a route that you want to use for traffic originating from one VLAN, there isn't a way to prevent LTM from forwarding traffic from all VLANs.

     

     

     

    I see that you recommended creating a pool for each VLAN containing the router as a pool member and then create a performance layer 4 VIP. I am confused on how to create this VIP, and what address it should use?

     

     

     

     

    You would use 0.0.0.0:0 as the VIP IP:port and add the router for the outbound VLAN to a pool. The type of VIP would be Performance Layer4 which uses a FastL4 profile.

     

     

    Hope this is clearer.

     

     

    Aaron