Forum Discussion

レザ's avatar
レザ
Icon for Cirrus rankCirrus
Jun 07, 2023

Disable Inter-VLAN Routing?

Hello I was searching for my problem when I came across this topic, but unfortunately, there was no complete answer to this question. Therefore, I wanted to know how to prevent bigip from bypassing...
  • Paulius's avatar
    Paulius
    Jun 07, 2023

    レザ As long as the servers sit in a different VLAN it would be up to your routing to not allow them to reach each other. Example, if you have VLANs 1-5 and the F5 and the firewall sit in each VLAN with the F5 being in 1 arm mode then each server should have the firewall as their gateway. As long as the switch seperating each VLAN doesn't performing any routing then those servers should not be able to reach each other without going through the firewall. They could technically reference the F5 as their gateway but if the F5 doesn't not have a forwarding virtual server configured with SNAT enabled on that virtual server they will not be able to communicate with each other without using the firewall.