Forum Discussion
dragonflymr
Cirrostratus
Jun 12, 2015AFM and asymmetric routing
Hi,
I am looking for possible solution for this kind of scenario. I was checking available docs and can't find any real solution that could work and be manageable using AFM.
Two DC - DC1, ...
nitass_89166
Noctilucent
Jun 12, 2015I assume that what you posted proves that asymmetrical routing could be used and it will work - Am I right?
yes
Is it not kind of security hole?
yes, you can say that.
is there any documentation I can read about ID461582 [Network Firewall] AFM behavioral change for ACL rule match and/or IP intelligence lookup for TCP flows?
i do not see it.
dragonflymr
Cirrostratus
Jun 12, 2015I probably will as this is very importnat aspect of the project.
Anyway I found something like that in 11.6.0 Release notes:
461582AFM previously matched firewall and IP Intelligence rules against the first TCP packet of a new flow, even if that packet would later be dropped by LTM,for example a FIN or RST packet. AFM no longer matches these packets, and LTM continues to drop them.
Is that the same subject but expressed using different sentence?
Piotr
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
