Forum Discussion
F5 2200s in the DMZ and LAN Security / PCI compliance question
Hello, I have a requirement for load balancing and WAF in my DMZ environment and also for load balancing only in my LAN environment. The environments must be secure and compliant with the PCIDSS. My question is, if I use the same F5 appliance for the load balancing/WAF in the DMZ, and the load balancing in the LAN, using different ports on the F5, how would I be able to prove to my PCI auditor that there is no possibility of the LAN traffic being visible or captured in some way in the DMZ should a compromise occur. Any thoughts on this please.
4 Replies
- Emad
Cirrostratus
I think you should be creating RouteDomains. Route Domains will isolate your DMZ from LAN. one RouteDomain for DMZ and second for LAN.
- Emad
Cirrostratus
I think you should be creating RouteDomains. Route Domains will isolate your DMZ from LAN. one RouteDomain for DMZ and second for LAN.
- GraemeZwart_185
Nimbostratus
Hi Johny Walker, thank you, and is the creating of route domains a feature that is available on the 2200s model?
- Emad
Cirrostratus
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com