Forum Discussion
F5 behind a router instead of a firewall, are there any risks??
Just to make sure: These are not the most recent recommendations by F5. As there are many firewalls on the market, that cannot handle as much sessions as the BIG-IP is able to do (when the sizing of firewall and BIG-IP is almost the same), today F5 recommends to place the BIG-IP directly to the outside, so beside the firewall. In combination with the AFM module the BIG-IP does nearly the same job as the firewall would do (no NG-Firewall).
In addition the most amount of traffic already is or will be in the future TLS. So also NG-Firewalls would have to terminate the TLS session. This doesn't make sense at all, because the firewalls I know do not have the capabilities in handling TLS traffic as the BIG-IP have - i.e. Cipher Suite Support, Protocol Support, Session Handling configuration, SNI and so on.
I know this article is from 2011, but if there are people out there, asking Google questions like this, they might be leeded to the wrong direction, because of a very old recommendation.
Greets, svs
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com