Forum Discussion
gmac263_33890
Apr 12, 2012Nimbostratus
How to handle servers that do not need to be load balanced?
I have a customer that would like to use F5 BIG-IP 3600 load balancing device between the an Internet route-able segment and a server segment. He has some servers that he wants to load balance and he has other servers that he wants to be able to access directly from the internet without load balancing them. Can he do this even though the non-load balanced servers are on the same segment as the load balanced servers all behind the BIG-IP 3600? Is there any technical reason that he should create two segments, one behind the F5 load balancing device for load balanced servers and another segment not behind the F5 load balancing device for non-load balanced servers?
Thanks
GM
- hooleylistCirrostratusHi GM,
- HamishCirrocumulusFor my hosts I usually put them all into DMZ's by platform (Separate VLAN's for Windows/Linux/Unix) and some organisations like to segregate Prod/Non-Prod... Also I tend to segregate by level of auth. e.g. Public/Open servers. Servers that require Auth. It does mean a larger than normal number of DMZ's, but you can craft firewall rules by VLAN quite fictively that way (e.g. Windows servers need certain access back inwards where they require access to AD etc... Not that I advise using internal AD from the DMZ, but some organisations require it).
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects