Forum Discussion
Nathan_67739
Nimbostratus
Jan 15, 2010Forcing "routed" traffic back to gateway
We currently have a LTM 3600 (running 10.0.1), set up in a router-on-a-stick model (vlan based network with backend servers and VIPs logically, but not physically, behind the LTM).
We a...
Hamish
Cirrocumulus
Jan 18, 2010Posted By Nathan on 01/16/2010 4:44 PM
Something else just occurred to me. We have a 'default forwarding' virtual server, set up as a 'Forwarding (IP)' type virtual server with a 0.0.0.0 addr and mask. Could this be done differently to tell the LTM "don't forward between subnets, only between the subnet and the gateway"?
Yes.
You set the destination for the default network VS as a pool. And the poolmember(s) just happen to be the gateway. I do this where a single F5 is used for a number of DMZ's between the firewall and the DMZ's themselves. In this way any traffic between subnets is forwarded via the gateway (Firewall), and not direct.
I normally set the allowed VLAN's as well just to make sure that traffic inbound on some interfaces is treated slightly differently (eg. traffic TO the subnets doesn't want to match the default VS so the allowed VLAN's is set to just the subnets behind the F5)
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects