Forum Discussion

tcvander_93096's avatar
tcvander_93096
Icon for Nimbostratus rankNimbostratus
Jan 15, 2008

BigIP and PCI

I have a PCI requirement to separate traffic behind my F5 cluster by function AND a firewall. Meaning WEB servers can not talk to EMAIL servers without going through a firewall. My question is do pool members have to be on the same subnet as the F5? Meaning can I have a VLAN on the F5 that routes to a firewall where the pool members reside behind?

 

 

Attached is a diagram showing what I mean

 

  • hoolio's avatar
    hoolio
    Icon for Cirrostratus rankCirrostratus
    As long as you have routing configured on the BIG-IP, the firewall and the pool members, this should work fine. Ideally, you'd have redundant firewalls so you don't reduce the value of having redundant BIG-IPs.

     

     

    Aaron
  • Thank you for the response, yes there are redundant F5's and Firewall's, I was trying to keep the drawing simple. Where you state routing you mean static route's builit in the F5 and Firewall's, not a routing protocol running; correct?
  • hoolio's avatar
    hoolio
    Icon for Cirrostratus rankCirrostratus
    Static routes should work fine. If you have the advanced routing module licensed you could also use a routing protocol.

     

     

    Aaron