Forum Discussion
Greg_Ryan_33844
Aug 23, 2011Nimbostratus
Best practice for implementing f5's on internal and external vlans
I am looking for best practices as well as use cases to use 1 pair of f5's to load balance both external (dmz) and internal traffic. Currently I have 2 pairs, one for the dmz and one for internal traffic - both are on version 9.3.1 and upgrading has proven extremely difficult as there are many groups using them. What I have been contemplating is purchasing two 8900's for failover but using them to load balance traffic both on the dmz, and for internal traffic coming from the dmz machines. Is this best practice? Is there any downside to this? Any feedback would be greatly appreciated.
- JRahmAdminit really comes down to your company's security policy. Some require the physical separation of devices in different security zones. I've seen it both ways, and the LTM is more than capable to handle the collapsed dmz/internal infrastructure.
- HamishCirrocumulusIf you're going down the route of a single device, I'd recommend something like a virprion with vCMP... Best of both worlds :)
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects