Forum Discussion
Diference between inline or one arm
Inline and one arm don't really change LTM behavior as we are full proxying TCP connections.
What is needed times to times is to be able to preserve source IP address to backend server. in such case you may need to deactivate SNAT (source NAT), then two architecture modes are available :
- keep a proxy behavior with a VIP and make sure the come back traffic is routed to big-ip
- implement a bridged mode with two arms.
Otherwise if you don't need that, and you can SNAT all you applicative traffic, the LTM will behave the same with one or two arms.
Some people like two arms for traffic segmentation at the firewall level, you can pretty much identify easily traffic going to the big-ip, from traffic going to the backend as you will be in different subnets. But even in this case, you could be physically on one arm, but logically on two with vlan tagging.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com