Forum Discussion
Aaron1121_669
Nimbostratus
Feb 05, 2009Implemenation Advice
I'm new to the forums here, and I wanted to see if I could get some advice on an implementation. I’ve worked a lot with the Cisco LD’s, CSM’s, and ASA’s, as well as Radware Applications directors, but my F5 experience is somewhat limited.
I’ve been put on a project to consolidate some old load balancing equipment, to use two new redundant F5 devices.
Here is the logical layout of what I’ve got:
Internet
|
CheckPoint Cluster
|
-----------------------------------------------------------------
| | | |
DMZ1 DMZ2 DMZ3 Internal
Old F5 520 (1) Old F5 520 (2) Radware Appdir Network
One IP/ Int Config One IP/ Int Config L2 Mode
I have setup L2 trunking so that everything is accessable from the new F5's, and I've almost got the failover setup.
From what I've seen, we really have three options for deployment. Can you guys let me know your thoughts on the options, and maybe any of the pro's and con's that I missed? One of the things I am worried about is that we are trying to use smaller F5 boxes, so we are looking at options that reduce traffic through them.
We currently use the firewall as the default gateway on all the hosts. Our backups take place accross the network, and I'm a little concerned about running all that traffic through the F5's.
Option 1-
Trunk out all three DMZ vlans to the F5 cluster. Setup each DMZ in a one IP config. This would be similiar to the way it is setup now. It also keeps the default gateway on the servers setup as the firewall, so most of the traffic does not have to traverse the F5.
Any major drawbacks? It also may require an I-Rule to deal with some of the routing implications??.......
Option 2-
Trunk out all three DMZ vlans to the F5 cluster. Use N-Path Routing for each DMZ. Return traffic would use the firewall, same as now......
Option 3- Trunk out all three DMZ vlans to the F5 cluster. Insert a new network in each of the DMZ's. Setup the F5 cluster with logical internal and external network connections for each DMZ. Setup the hosts default gateway as the F5.
This is the textbook way to do it, but I'm a little concerned about the overall throughput, and the amount architecture changes.
I really appreciate your input and your thoughts. I know that each of these methods would probably work, but each has it's own implications. I rather know some of them up front, before I get halfway throught he project and find a "gottcha".
Thanks in advance for your comments!
- dennypayne
Employee
Hi, - L4L7_53191
Nimbostratus
Two other (random) notes here...you mention 520s, which are older appliances, but you also mention implementing new systems...could you clarify what version we're dealing with? - Aaron1121_669
Nimbostratus
Thanks for the advice! I really appreciate it.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects