F5 is upgrading its customer support chat feature on My.F5.com. Chat support will be unavailable from 6am-10am PST on 1/20/26. Refer to K000159584 for details.

Forum Discussion

wkucardinal_215's avatar
wkucardinal_215
Icon for Nimbostratus rankNimbostratus
Sep 24, 2015

Do you need to have separate GTMs for your DMZ and internal network?

The subject says it all: Do you need to have separate GTMs for your DMZ and internal network? It is best practice to have a separate DNS server in your public-facing DMZ network so that if it is compromised it does not affect your internal DNS environment. Is F5 GTM the same? Should you have a GTM environment for your internal network users and a separate GTM environment for your public-facing DNS queries in your DMZ?

 

It seems like a security risk to only have one GTM environment in your DMZ. It will have knowledge about how to resolve internal DNS queries, so outside traffic it seems could easily probe your internal network resolution.

 

No RepliesBe the first to reply