Forum Discussion
dragonflymr
Cirrostratus
Nov 02, 2015ASM VE performance scalling
Hi,
I wonder if there is any good article about sizing VM for ASM/AFM deployment. Or maybe someone already did such deployment and can share some figures. What number of vCPU/RAM/Other resources...
dragonflymr
Cirrostratus
Nov 02, 2015Hi,
Thanks for hints. If I am not wrong limit for VE ends at 10Gb throughput? I am asking because right now under attack customer is reporting hardware BIG-IP as bottleneck (don't know yet what is HW). Wonder is alternative could be some LB pointing to ASM VE pool to create LB at the attack time in cost effective manner.
As far as I know ASM is most resource intensive module on BIG-IP.
Piotr
Hannes_Rapp
Nimbostratus
Nov 02, 201510Gbps is indeed the current maximum supported by VE. Your next question is thougher, it's for sure that you can deploy ASM on a separate BigIP, and route requests to it from another AFM/LTM box. What I do not know is if you can implement some sort of balancing from a single AFM/LTM appliance/cluster to multiple ASM boxes. Not even sure if it will help you remedy the effects of a DOS attack significantly.
Personally, I would leave out the balancing to multiple ASM appliances since the ASM module is quite costly and the desired solution is not guaranteed, but instead look into possibilities to take down the attack on the AFM/LTM box, and if the attack is huge (i.e the on-site appliance couldn't cope), manually activate the cloud-based DOS attack mitigation (i.e pay to subscribe service from F5 Silverline or Prolexic). Just some ideas.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects