Forum Discussion
ASM Virtual server vlan configuration.
Hello All,
We are planning to deploy ASM to monitor application traffic. Application servers are in internal VLAN. No app server in DMZ. Only option I think is VIP(virtual server) to be created in internal vlan and map app servers to VIP so that both are in same VLAN. Hence, External user uses public IP which is NAT to F5 VIP(internal VLAN) and from F5 VIP to internal APP server. But risk here is we can not allow externals to access internal VLAN directly. If F5 VIP(internal VLAN) compromised it will risk entire internal network.
- we have other applications in DMZ VLAN for which we don't face any issue. But for this particular application servers in DMZ is not an option.
Is this understanding correct or am I missing anything here? Please help.
- Richard_Karon
Employee
what is your preferred configuration?
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com