Forum Discussion
Edouard
Cirrus
Sep 06, 2019F5 AFM vs NG FW
Gents, I have a question for you. We have a F5 AFM/LTM facing the internet, and a new FW NG will be provisioned soon for end users. There is question whether or no the F5 should be next...
Sep 07, 2019
It kind of depends what kind of Next-Gen FW you are going to be using and what you are trying to achieve. What's your business case? I'm working a lot with both F5 and Check Point. In most cases I would position the F5 ADC behind the Check Point, because the Check Point comes with superb management capabilities (detailed logging etc...).
You could also check out SSL Orchestrator to create a decrypted zone to put the Next-Gen FW into. This way you can save resources on your Next-Gen FW, becasue it will only need to inspect already decrypted traffic.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects