Forum Discussion

Elvis's avatar
Elvis
Icon for Nimbostratus rankNimbostratus
Nov 25, 2019

F5 What are the best practices defaultGateWay or not ?

Architecture

 

WAN (www.mydomain.com/app) <-----> Cisco ASA Nat ----> F5 Load Balancer (BigIP 2600) <------> Http Server <----> Tomcat App Server

 

 

Previously I had a Cisco ACE as Balancer which in turn was defaultGateWay of the Http Server....

 

 

 

What do you recommend in the new architecture using F5 Load Balancer for a Web application, is my F5 in the DMZ?

 

A. The f5 assumes the role of defaultGateWay (it was tested and is not working, it does not return the return requests).

 

B. Place the ASA as defaultGateWay so that traffic routing is achieved

  • Hamish's avatar
    Hamish
    Icon for Cirrocumulus rankCirrocumulus

    Normally I'd run as defaultGateway. The options if your'e not doing that are SNAT (Which is more difficult to debug at the network level) or policy routing (Requires config on the endpoints)