Forum Discussion
Design with AFM in the DMZ-Environment
Hi
Has anybody some experience with the AFM-Module?
We have some discussions about the placement of the bigip when we would use the Advanced Firewall Modul.
In this case, bigip would have enabled: LTM, APM, ASM, AFM.
Do we need an additional stateful firewall in front of the bigip or can we place it directly in the internet, in front of the application servers?
What would make more sense?
Thanks
3 Replies
- What_Lies_Bene1
Cirrostratus
Any answer to this will be very dependent on your business, your existing infrastructure, security policy and so on. Can you provide some background please? - chamindak_11539
Nimbostratus
Hey, Basically a different vendor firewall sits in front of the F5s, just doing a cutover from a different vendor firewall onto AFM. Obviously upstream FW doesn't have contexts while the F5s have route-domains.
I've done some testing now and the conclusion is I need to use %[RD] syntax with source/destination IPs. Makes sense given they are essentially different VRFs.
Does any one know where AFM logs locally? I'm after a session/debug log that I can tail.
Thanks, Ck
- i would create a new question for your little unrelated to the originial question.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com