Forum Discussion
f5s across web and app tiers / across firewalls
we are using f5's with GTM across two sites for web tier (for Oracle Weblogic apps).
we need to provide load balancing for the app tier as well which is inside the inner firewall.
is this a valid config in terms of security ? ie the f5s wil be cabled both to dmz and inner vlans with diffent ports / rules.
thanks for help - want to avoid buying more load balancers !
Mark
5 Replies
- nitass
Employee
is this a valid config in terms of security ? ie the f5s wil be cabled both to dmz and inner vlans with diffent ports / rules.it is configurable. you may separate web tier and app tier in different route domain. anyway, in term of security perspective, i think using two separate load balancers is better.
just my 2 cents. - What_Lies_Bene1
Cirrostratus
Fair points Nitass. If I can suggest another alternative. Just use the 'web' load balancers to balance to the 'app' servers. It doesn't matter that there is a firewall in the path between the load balancers and app servers. You might need to SNAT but that's about the only downside.
I would avoid cabling to two different DMZs and Route Domains myself. - Joseph_Ortiz_73
Nimbostratus
Steve - How do you accomplish using the 'web' load balancers to balance to the 'app' servers? We're using f5 in one-arm configurations, but our environment is getting more complex and I'm having trouble wrapping my head around these different configurations. Thanks. - What_Lies_Bene1
Cirrostratus
Just create a VS on the server-side VLAN the web servers are part of, with the app servers as Pool Members. You'll need to SNAT to ensure the traffic back from the app servers goes back to the F5's. I appreciate it can be difficult to 'get it' and 'hold it all in your head' sometimes. If I get time I'll post a diagram over the weekend. - What_Lies_Bene1
Cirrostratus
OK, here's a quick and dirty diagram. Just remember to factor the monitors direct from the F5 in the firewall rules and SNAT on the second VIP (assuming there is a L3 device between the F5 server-side and the firewalls).
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com