Forum Discussion
Inter-Vlan Security
I have a very simple scen
Vlan A: Server vlan with BIGIP as default gateway
Vlan B: Server vlan with BIGIP as default gateway
Vlan C: Interconection vlan between Firewall an BIGIP. Firewall is default gateway for BIGIP
My custoner want that all traffic to and from server vlans (including inter-vlan traffic) go to firewall for security control. Can i do it with IP Fordwarding virtual servers?. How i must configure them?.
I don't want configure route domains or iRules for this if is possible.
Regards.
- The_Bhattman
Nimbostratus
Hi Ernesto, - Ernesto_27816
Nimbostratus
Hi Bhattman, - The_Bhattman
Nimbostratus
Hi Ernesto, - Ernesto_27816
Nimbostratus
Hi Bhattman, - Hamish
Cirrocumulus
Posted By Ernesto on 03/18/2012 05:59 AMOne network VS of type forwarding. Destination VlanA. Enabled on VLAN C only.
One network VS of type forwarding. Destination VlanB. Enabled on VLAN C only.
And then
One network VS of type STANDARD. Destination default (0.0.0.0/0). The default pool has one pool member, the firewall IP address on port 0. Enabled on VLAN A and VLAN B.
Traffic from VLAN A or B hits VS 0.0.0.0. It's forwarded to the pool member (Firewall). The firewall checks the traffic. Assuming it's allowed, the firewall forwards the packet BACK to the BigIP (Using the firewall routing table) via the floating IP address.
This traffic from the firewall hits VS(A) or VS(B) depending on destination (Because they are enabled only on VLAN C). It's forwarded direct to the attached VLAN.
H
- The_Bhattman
Nimbostratus
If you have a PIX Firewall versions prior to 7.2(1) you cannot send packets in and out from the same interface. However, starting in version 7.2(1) you can do this via command "same-security-traffic permit intra-interface" - Ernesto_27816
Nimbostratus
HI both,
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com