Forum Discussion
Craig_17766
Nimbostratus
Aug 08, 2012HA Pair for Inside and DMZ?
HA Pair for Inside and DMZ?
We’re looking at using F5’s in our DR environment to replace old Cisco CSS’s, we’d like HA pair but the budget is not there for two HA Pairs one each for DMZ and Inside. Can we use a single F5 HA Pair for both DMZ and Inside?
Thanks,
Craig.
5 Replies
Sort By
- hoolio
Cirrostratus
Hi Craig, - Josh_41258
Nimbostratus
Craig - we host both DMZ and internal applications on a single pair. As Aaron stated, you can simply trunk multiple VLAN's to your BIG-IPs (one for your DMZ, one for your internal stuff, etc). - Hamish
Cirrocumulus
You can... But I wouldn't... Unless it's a Viprion and you're using separate vCMP guests for DMZ and internal. - You have firewalls between DMZ and internal for a reason. One of those is a single point of control. Having a single system 'bridge' the firewall like this can lead to security leaks. thinking if route domain is helpful in migitgating the security leak.
- Hamish
Cirrocumulus
It helps. But i still wouldnt bridge different levels of security like that. Bridging between zones of the same level i have done in the past. But dmz to internal is one i wouldnt do... Especially if a different team admin the firewall and bigip...
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects