Forum Discussion
Do you need to have separate GTMs for your DMZ and internal network?
The subject says it all: Do you need to have separate GTMs for your DMZ and internal network? It is best practice to have a separate DNS server in your public-facing DMZ network so that if it is compromised it does not affect your internal DNS environment. Is F5 GTM the same? Should you have a GTM environment for your internal network users and a separate GTM environment for your public-facing DNS queries in your DMZ?
It seems like a security risk to only have one GTM environment in your DMZ. It will have knowledge about how to resolve internal DNS queries, so outside traffic it seems could easily probe your internal network resolution.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com