Forum Discussion
Craig_17766
Aug 08, 2012Nimbostratus
HA Pair for Inside and DMZ?
HA Pair for Inside and DMZ?
We’re looking at using F5’s in our DR environment to replace old Cisco CSS’s, we’d like HA pair but the budget is not there for two HA Pairs one each for DMZ and Inside. Can we use a single F5 HA Pair for both DMZ and Inside?
Thanks,
Craig.
- hooleylistCirrostratusHi Craig,
- Josh_41258NimbostratusCraig - we host both DMZ and internal applications on a single pair. As Aaron stated, you can simply trunk multiple VLAN's to your BIG-IPs (one for your DMZ, one for your internal stuff, etc).
- HamishCirrocumulusYou can... But I wouldn't... Unless it's a Viprion and you're using separate vCMP guests for DMZ and internal.
- nitassEmployeeYou have firewalls between DMZ and internal for a reason. One of those is a single point of control. Having a single system 'bridge' the firewall like this can lead to security leaks. thinking if route domain is helpful in migitgating the security leak.
- HamishCirrocumulusIt helps. But i still wouldnt bridge different levels of security like that. Bridging between zones of the same level i have done in the past. But dmz to internal is one i wouldnt do... Especially if a different team admin the firewall and bigip...
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects