Forum Discussion
Deployment of F5 APM - SSL VPN,
hi all,
We go to deploy F5 apm for a SSL VPN in our environment, we need experts advice to design the deployment. We are presently using Microsoft UAG and our current setup is below
Public -> Checkpoint -> UAG(in DMZ with 2 arm - 1 lan and 1 for dmz)
Pls help us.
You may refer to the link for the details regarding ACL for Network Access.
http://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-network-access-11-5-0/2.html
12 Replies
- kunjan
Nimbostratus
You can follow the same topology with 2-arm (DMZ and LAN). Is there anything specific you are looking for?
- Mariappan_S_156
Nimbostratus
Thanks for reply. Our vendor has advises us to put firewall between F5 device and LAN connectivity and all the traffic between F5 to LAN should travel through mention firewall. Can F5 box do the firewall protection for LAN connectivity? What is your advice? Need a firewall or can achieve firewall protection with F5 itself.
- kunjan_118660
Cumulonimbus
You can follow the same topology with 2-arm (DMZ and LAN). Is there anything specific you are looking for?
- Mariappan_S_156
Nimbostratus
Thanks for reply. Our vendor has advises us to put firewall between F5 device and LAN connectivity and all the traffic between F5 to LAN should travel through mention firewall. Can F5 box do the firewall protection for LAN connectivity? What is your advice? Need a firewall or can achieve firewall protection with F5 itself.
- kunjan
Nimbostratus
The use of firewall on the LAN side will help to control the VPN user traffic, provided you require to have granular control on the VPN traffic.
- Mariappan_S_156
Nimbostratus
I accept, But pls confirm, how possible the same granular control through ACL in F5 APM. If we can then we skip the additional firewall purchase.
- kunjan_118660
Cumulonimbus
The use of firewall on the LAN side will help to control the VPN user traffic, provided you require to have granular control on the VPN traffic.
- Mariappan_S_156
Nimbostratus
I accept, But pls confirm, how possible the same granular control through ACL in F5 APM. If we can then we skip the additional firewall purchase.
- kunjan_118660
Cumulonimbus
You may refer to the link for the details regarding ACL for Network Access.
http://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-network-access-11-5-0/2.html
- Mariappan_S_156
Nimbostratus
thanks for useful information..
- kunjan
Nimbostratus
You may refer to the link for the details regarding ACL for Network Access.
http://support.f5.com/kb/en-us/products/big-ip_apm/manuals/product/apm-network-access-11-5-0/2.html
- Mariappan_S_156
Nimbostratus
thanks for useful information..
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com