Forum Discussion
Enterprise Security best practices with F5 WAF
if all user access to the app goes through bot defense in dmz f5 awaf, then no need to put the filter again in server zone.
in my personal opinion, bigip/waf is application-layer oriented device, not network layer oriented device.
it behaves more like application servers, so it's more properly installed in the server zone.
and btw, bigip device supports vlan, vxlan, and vrf-like segmented routing via route domain features.
so actually 1 device can covers all zones if you set proper vlan/vxlan/vrf configurations.
some people might "persuade" buyers to buy separate devices for each zone though 🙂
Thanks for your response.
In our case F5 WAF is in the DMZ and the applications are in the private subnets behind DMZ.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com