Forum Discussion
JRahm
Aug 06, 2015Admin
- since everything appears to be L3 segmented with routes pointing in the "right" direction, I don't think snat is necessary.
- If you are routing anything inbound, yes. If you are just serving traffic via specific application virtual servers, no. The outbound virtual will manage return traffic.
- Complex because of DMZ, but fairly simple wrt the BIG-IP itself. Note that in DMZs, I always make a habit of disabling auto-lasthop so I am 100% sure I have explicitly allowed traffic to flow instead of BIG-IP getting traffic back to where it came from with or without the routes necessary to do it.