Forum Discussion
First time setup
Hi Team-
Need your advice/assistance as Im new to F5 and have very limited knowledge on setting up the appliance. We recently purchased licenses for F5BIG-VE BT 200 and was able to setup on VMware 6.5. Yet to configure network adapters and other cool stuff so that i can protect web servers. My setup scenario is
Clients --> Internet --> Cisco ASA firewall --> F5 LTM (in DMZ) --> Web server (LAN)
Since we cannot afford multiple F5, we will use single F5 instance in DMZ (no failover pair). My question, is it possible to setup F5 LTM like mentioned in above topology? Is it possible to offload SSL traffic and use F5 device as proxy server? I dont want to put web server in DMZ except F5 appliance that is my goal here.
F5 licenses Carrier Grade NAT LTM ASM Global Traffic (DNS) Access Policy (APM) Application Visibility and Reporting (AVR) Advanced Firewall (AFM) iRules Language Extensions (iRulesLX)
Your inputs are much appreciated.
sincerely, sm
- youssef1
Cumulonimbus
Hi,
your approach is correct regarding your architecture.
My question is the following, your web app that you will expose to internet is public? if not you can use APM to implement a security policy (authentication, endpoint inspection, ...).
Second point, if you site is public and you dont set APM (authentificaiton), you can increase security by implementing an ASM security policy to avoid attack, ...
Regarding ssl Offload I advise you to set this settings. It will allow you to secure ssl/tls part (HSTS, Disable Renegotiation, use secure cypher, ...).
let me know if I can help you on some points.
Regards
- KevinA_246454
Cirrostratus
Hi SM18
Setting up multiple network adapters is fairly straight forward on your ve appliance, you 1st need to decide your deployment architecture the diagram you have is a good start, depending if you want to go the one arm route or external -> internal interface that will depend how much network adapters you need, I think by default the ova template comes with 3 adapters one for HA, one for external and for internal and additional management. if you go one arm you can get away with one interface for your load balancing using snat. If you require documentation on how to setup the adapters or even the ssl offloading the F5 VE LAB package that is available from the f5 downloads is a perfect place to start.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com