Forum Discussion

Shiraz's avatar
Shiraz
Icon for Altostratus rankAltostratus
Nov 20, 2017

Configuring ASM policy twice for the same application accessed via two different F5 devices

Dears,

 

We have two F5 pairs in different zones. The Pool member of the first F5 VS is the VS of send F5.

 

Client --> 1st F5 VS --> 2nd F5 VS --> Real Servers

 

Both the Virtual servers needs to be protected by ASM. The reason behind having ASM on the 2nd F5 VS is that its been accessed by other users which do not come via 1st F5.

 

I hope I am clear with my question.

 

I would like to know whether there will be any issues in having ASM for the same application twice??

 

Regards,

 

Mohammed

 

  • there will be no ASM issues, but please remember about IP addressing. Second asm will see packet only from one IP address (previous F5), so XFF header should help you.

     

    p.s I have never seen such an infrastructure like you wrote :-) Why do you need two asm for one app ?