For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

mraful_64014's avatar
mraful_64014
Icon for Nimbostratus rankNimbostratus
May 07, 2013

distributed applications

The application is distributed and lacks any centralized monitoring of management of the application itself. The traffic flow is from Apache to Tomcat and Tomcat to any other server that has a needed web service

 

user -->LTM-> apache in dmz --> LTM -> JBoss/Tomcat --> another web service

 

--> even another service

 

--> yet another service

 

 

If you ran iApp/AVR on the second LTM you would see statisitcs for the JBoss/Tomcat but nothing else. I was thinking it could be reconfigured like this where all the other servers with a web service could have a VIP on the external side without SNAT, since the servers are all on the same subnet. Tomcat would communicate with the various web services via the VIP on the back end allowing a full monitoring via AVR. ( I don't know how much would be gained by also running web acceleration here.)

 

user -->LTM-> apache in dmz --> LTM --> JBoss/Tomcat

 

--> another web service

 

--> even another service

 

--> yet another service

 

Here, I would put virtual servers for the web services on the internal side and use the existing SNAT pool for Tomcat to talk to those servers, or create virtual servers on the external side without snat (since they would be on the same subnet) and let Tomcat talk to the virtual servers on the external side. Also, would there be much performance boost to running the web acceleration on the second LTM for all of those REST calls and JSON responses from the services?

 

 

Thanks!

 

No RepliesBe the first to reply