Forum Discussion
F5 LTM setup with Cisco FWSMs
Hi,
I am going to setup F5 LTMs in our environment for server load balancing. I have a question about the placement of F5 LTMs. We want to use our existing Data Centre Gateway Switch to connect to F5. These data center switches have Firewall module in place which acts as a gateway for the servers in the data center.
Now with F5 (not acting as firewall) what is the best placement of the device, should we place F5s behind the firewall so all traffic first pass through the Firewall module and then hit the F5 external interface. The F5 internal interface will have VLANs configured for the servers connected to it. These servers will point to F5 as gateway. Is this the correct approach?
Is there any design document that can help in setting up such requirements? What is the best practice. Any help would be appreciated?
Thanks,
Fawad Alam
- Josh_41258NimbostratusThere are several ways to accomplish this. We have a similar setup, although we utilize SNAT. Therefore, the gateways of the servers are -not- the BIG-IP, they are the firewall/switch/SVI interfaces for that particular VLAN that the servers reside on. The BIG-IPs are directly connected to our core infrastructure which handles all Layer 3 - one trunk for the "external" side of the BIG-IP (this is where our VIPs reside), and one trunk carrying multiple VLANs for the "internal" side of the BIG-IP (this is where our servers reside).
- Sly_85819NimbostratusYes there are many ways to do that as mentioned by Josh. I would prefer the approach mentioned by you if you have the flexibility of changing server IP or building a new setup. Have all server point to LTM as a gateway and then have FWSM as gateway for LTM.
- Fawad_29089NimbostratusThanks guy! Is there any link you can forward to me where I can see guideline!
- Josh_41258NimbostratusI'm not sure if there are any guides or not, but I would suggest that you talk to your SE or account manager to help you carve out a design that fits into your existing network.
- HamishCirrocumulusUsing FWSMs id recommend placing your vlans behind the bigip so that you just have two vlans one your fwsm... Then if you want to firewall your vlans from each other use network virtual servers to push inter vlan traffic via the firewall instead of direct.
- lkchenNimbostratusI think we did get help from SE when we originally setup our F5 with FWSM. 'cause I don't know how they would've figured out how to do what they've done.
- TechgeeegNimbostratusHi Fawad,
- HamishCirrocumulusNot sure I envy you with this one.
- lkchenNimbostratusThe standby BigiP unit got disconnected, to move its fiber connection.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com