Forum Discussion
dragonflymr
Cirrostratus
Jun 12, 2015AFM and asymmetric routing
Hi,
I am looking for possible solution for this kind of scenario. I was checking available docs and can't find any real solution that could work and be manageable using AFM.
Two DC - DC1, ...
nitass
Employee
Jun 12, 2015I assume that what you posted proves that asymmetrical routing could be used and it will work - Am I right?
yes
Is it not kind of security hole?
yes, you can say that.
is there any documentation I can read about ID461582 [Network Firewall] AFM behavioral change for ACL rule match and/or IP intelligence lookup for TCP flows?
i do not see it.
- dragonflymrJun 12, 2015
Cirrostratus
Thanks, that can save the project I am working on, at least there is some hope :-) Regarding this ID461582 - is that some internal F5 secret knowledge or I can try to create ticket to find out? Piotr - nitassJun 12, 2015
Employee
>is that some internal F5 secret knowledge or I can try to create ticket to find out? i do not think it is secret knowledge. ID is used to track a know issue, behavior change or improvement. if behavior is not clear to you, you are free to open a support case to check. - dragonflymrJun 12, 2015
Cirrostratus
I probably will as this is very importnat aspect of the project. Anyway I found something like that in 11.6.0 Release notes: 461582AFM previously matched firewall and IP Intelligence rules against the first TCP packet of a new flow, even if that packet would later be dropped by LTM,for example a FIN or RST packet. AFM no longer matches these packets, and LTM continues to drop them. Is that the same subject but expressed using different sentence? Piotr - nitassJun 12, 2015
Employee
>Is that the same subject but expressed using different sentence? yes
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
